New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Putting the “sec” in DevSecOps: An overall reduction of risk

New York Tech Editorial Team by New York Tech Editorial Team
November 29, 2021
in Cybersecurity
0
Putting the “sec” in DevSecOps: An overall reduction of risk
Share on FacebookShare on Twitter

In this Help Net Security interview, Cindy Blake, Senior Security Evangelist at GitLab, talks about the importance of integrating security in DevSecOps and how to overcome the complexity of such integration.

security DevSecOps

Security in DevOps is often being neglected. Why do you think this is the case?

According to GitLab’s 2021 Global DevSecOps Survey, over three-quarters of respondents continue to think developers find too few bugs too late in the software development life cycle (SDLC). The complexity of integrating security is one of the biggest challenges facing DevOps today. This is because iterative development workflows can make security a release bottleneck, so it is neglected altogether. In addition, most organizations don’t have enough security practitioners to test all of their code. As a result, security is often addressed last — or even completely left out — of the DevOps flow.

As is the case for most businesses, the pace of innovation needs to be greater than or equal to competitors to outpace them and, ultimately, succeed. The faster that features can be released and enjoyed by users, the sooner businesses can generate revenue from that code — and the reality is that security must be a part of that to be successful.

The good news is many organizations have shifted security left, or at least started on their journey, in an effort to improve development velocity while also managing security risks — in fact, the survey also found that 35.9% develop software using DevSecOps, (where security is integrated into development) as compared to only 27% in 2020. While security has been traditionally neglected, organizations are beginning to value the importance of security in their DevOps processes. The newest challenge is complexity of that integration when using incumbent tools.

Is there a way to overcome the complexity of integrating security in DevSecOps?

When making the case for DevSecOps, or any new technology strategy, IT leaders need to be convinced that adopting new tools or processes will be worthwhile in the long run. Shifting to DevSecOps requires an investment in time and resources that can sometimes take years. This is a real challenge that prevents organizations from putting the “sec” in their DevSecOps processes sooner.

The best way to bring security into the development process is by using a tool that allows developers to stay in the same platform or interface they’re already using to commit, scan, and ship code to production. This makes the security process automatic and seamless every time there is a code update. In addition, it is critical that organizations start small. You don’t need to completely change your infrastructure to move things forward. Starting small with one team or one project is often the most successful way to implement change. Having an integrated platform approach can then help you scale more quickly.

How can DevSecOps benefit businesses?

In today’s evolving threat landscape, and especially with the uptick in software supply chain cyberattacks we’ve seen, it’s not enough to just find and fix security vulnerabilities earlier in the software development life cycle.

Proper DevSecOps will ultimately improve simplicity, provide earlier visibility, and give greater control over the security of the end-to-end SDLC. Building security into the entire DevOps pipeline is key for agility, advancement, and protection, and ultimately will save businesses time, money, and resources when done right.

How important is DevSecOps for the CI/CD pipeline?

DevSecOps integrates security controls and best practices into the DevOps workflow through CI/CD pipelines. These pipelines are akin to an assembly line for the software factory. As more teams try to shift left, automated security testing within the pipelines streamlines adoption and scalability while improving consistency.

Teams that adopt a DevSecOps strategy will not only develop better, faster software, but will also improve business outcomes, identify bugs, and catch vulnerabilities before they ever reach users.

You say built-in security will be a prerequisite. Can you explain why?

Built-in security has become a prerequisite to not only automate a comprehensive security scanning process, but also automate the policies and actions taken when exceptions are found. Consistently applying policies to your CI/CD pipelines ensures better security and regulatory compliance – without added work. As more and more organizations are understanding both the efficiencies and improved security of DevSecOps, this strategy will continue to increase in 2022.

The benefits of strong DevSecOps are clear — and the “sec” in DevSecOps will be more important than ever before as organizations realize the benefits with fewer vulnerabilities, faster deployments, less time spent in corrective actions, and an overall reduction of risk.

Credit: Source link

Previous Post

US venture capital valuation trends in seven charts

Next Post

Fintech Firm Slice Raises $220 Million, Hits “Unicorn” Status

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Fintech Firm Slice Raises $220 Million, Hits “Unicorn” Status

Fintech Firm Slice Raises $220 Million, Hits "Unicorn" Status

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media