Ad End 1 February 2024
Ad Ends 13 January 2025
Ad End 26 February 2025
ad End 25 April 2025
Ad Ends 20 January 2025
Ad expire at 5 August 2024
banner Expire 25 April 2025
What's new
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
casino
swipe store
adv exp at 23 August 2024
Carding.pw carding forum
BidenCash Shop
Kfc CLub

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,544
Reaction score
916
Points
212
Awards
2
  • trusted user
  • Rich User
The approach organizations should take to develop and maintain an effective DevSecOps culture were highlighted by Patrick Debois, director of market strategy at Snyk during a session at the Infosecurity Magazine Online Summit EMEA 2021.

Debois firstly emphasized the importance of an organization’s culture in determining the DevSecOps strategy that should be employed. “The CEO and culture of your company will set the tone on the areas upon which your DevSecOps transformation will address,” he commented. Depending on the context, this may involve greater focus on automation, metrics, empowerment or command and control.

He then outlined the different ‘topologies’ available, which relate to the nature of the relationship between dev and ops teams, with varying degrees of closeness. The type that will work best in a given organization is dependent on the culture that has been developed, he said. These can manifest in five ways:

  1. Dev and ops collaboration
  2. Fully shared ops responsibilities
  3. DevOps with expiry date
  4. DevOps Evangelist
  5. Container-driven collaboration
Debois went on to describe three team interaction modes that need to be considered:

  1. Collaboration: the day-to-day human collaboration
  2. X-as-a-service: the self-servicing automation that a developer can use
  3. Facilitating: a facilitation by the teams to help guide the collaboration
He added: “If you’re constructing how your teams overlap, you also have to look at how they will collaborate.”

Ultimately, in the view of Debois, building and gaining trust between the respective teams is what is most essential. He highlighted four key facets related to this:

  1. Sincerity
  2. Reliability
  3. Competence
  4. Care
Debois noted that competence is not enough on its own. “That’s why I see DevSecOps as the trust building up between both parties,” commented Debois.

Finally, the four areas of DevSecOps were defined as the following:

  1. Secure stack: what is being delivered and is that secure? e.g. code dependencies
  2. Secure delivery: how it’s being delivered and is that secure? e.g. is the integrity of the download secure
  3. Security governance: Where the team hooks into the processes of the security team
  4. Security empowerment: How the team interacts with security, ultimately to acquire security knowledge.
These are all interlinked, and there is an equal focus placed upon each. Debois concluded: “You have to level up in a spiral way on all of these areas.”
 
Ad End 1 February 2024
Top