New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Putting the “sec” in DevSecOps: An overall reduction of risk

New York Tech Editorial Team by New York Tech Editorial Team
November 29, 2021
in Cybersecurity
0
Putting the “sec” in DevSecOps: An overall reduction of risk
Share on FacebookShare on Twitter

In this Help Net Security interview, Cindy Blake, Senior Security Evangelist at GitLab, talks about the importance of integrating security in DevSecOps and how to overcome the complexity of such integration.

security DevSecOps

Security in DevOps is often being neglected. Why do you think this is the case?

According to GitLab’s 2021 Global DevSecOps Survey, over three-quarters of respondents continue to think developers find too few bugs too late in the software development life cycle (SDLC). The complexity of integrating security is one of the biggest challenges facing DevOps today. This is because iterative development workflows can make security a release bottleneck, so it is neglected altogether. In addition, most organizations don’t have enough security practitioners to test all of their code. As a result, security is often addressed last — or even completely left out — of the DevOps flow.

As is the case for most businesses, the pace of innovation needs to be greater than or equal to competitors to outpace them and, ultimately, succeed. The faster that features can be released and enjoyed by users, the sooner businesses can generate revenue from that code — and the reality is that security must be a part of that to be successful.

The good news is many organizations have shifted security left, or at least started on their journey, in an effort to improve development velocity while also managing security risks — in fact, the survey also found that 35.9% develop software using DevSecOps, (where security is integrated into development) as compared to only 27% in 2020. While security has been traditionally neglected, organizations are beginning to value the importance of security in their DevOps processes. The newest challenge is complexity of that integration when using incumbent tools.

Is there a way to overcome the complexity of integrating security in DevSecOps?

When making the case for DevSecOps, or any new technology strategy, IT leaders need to be convinced that adopting new tools or processes will be worthwhile in the long run. Shifting to DevSecOps requires an investment in time and resources that can sometimes take years. This is a real challenge that prevents organizations from putting the “sec” in their DevSecOps processes sooner.

The best way to bring security into the development process is by using a tool that allows developers to stay in the same platform or interface they’re already using to commit, scan, and ship code to production. This makes the security process automatic and seamless every time there is a code update. In addition, it is critical that organizations start small. You don’t need to completely change your infrastructure to move things forward. Starting small with one team or one project is often the most successful way to implement change. Having an integrated platform approach can then help you scale more quickly.

How can DevSecOps benefit businesses?

In today’s evolving threat landscape, and especially with the uptick in software supply chain cyberattacks we’ve seen, it’s not enough to just find and fix security vulnerabilities earlier in the software development life cycle.

Proper DevSecOps will ultimately improve simplicity, provide earlier visibility, and give greater control over the security of the end-to-end SDLC. Building security into the entire DevOps pipeline is key for agility, advancement, and protection, and ultimately will save businesses time, money, and resources when done right.

How important is DevSecOps for the CI/CD pipeline?

DevSecOps integrates security controls and best practices into the DevOps workflow through CI/CD pipelines. These pipelines are akin to an assembly line for the software factory. As more teams try to shift left, automated security testing within the pipelines streamlines adoption and scalability while improving consistency.

Teams that adopt a DevSecOps strategy will not only develop better, faster software, but will also improve business outcomes, identify bugs, and catch vulnerabilities before they ever reach users.

You say built-in security will be a prerequisite. Can you explain why?

Built-in security has become a prerequisite to not only automate a comprehensive security scanning process, but also automate the policies and actions taken when exceptions are found. Consistently applying policies to your CI/CD pipelines ensures better security and regulatory compliance – without added work. As more and more organizations are understanding both the efficiencies and improved security of DevSecOps, this strategy will continue to increase in 2022.

The benefits of strong DevSecOps are clear — and the “sec” in DevSecOps will be more important than ever before as organizations realize the benefits with fewer vulnerabilities, faster deployments, less time spent in corrective actions, and an overall reduction of risk.

Credit: Source link

Previous Post

US venture capital valuation trends in seven charts

Next Post

Fintech Firm Slice Raises $220 Million, Hits “Unicorn” Status

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Fintech Firm Slice Raises $220 Million, Hits “Unicorn” Status

Fintech Firm Slice Raises $220 Million, Hits "Unicorn" Status

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025
Magnus Almqvist, new CEO of Exberry

Exberry Appoints Magnus Almqvist as CEO to Drive Next Phase of Strategic Growth

March 5, 2025
Expert Family Law Firms in New York: Your Essential Guide to Legal Help

Expert Family Law Firms in New York: Your Essential Guide to Legal Help

March 3, 2025

Recommended

Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media