{"id":13582,"date":"2018-07-26T09:46:36","date_gmt":"2018-07-26T08:46:36","guid":{"rendered":"http:\/\/www.devopsonline.co.uk\/?p=13582"},"modified":"2018-07-26T09:59:07","modified_gmt":"2018-07-26T08:59:07","slug":"security-in-the-world-of-devops","status":"publish","type":"post","link":"https:\/\/devopsnews.online\/security-in-the-world-of-devops\/","title":{"rendered":"Security in the world of DevOps"},"content":{"rendered":"

DevOps can ensure compliance by incorporating automated policy enforcement into the development process, but how does security fit into DevOps without hindering software development?<\/p>\n

Security deals with many protocols that are baked into the development process rather than added as a \u201clayer on top\u201d. Today, professionals harness the power of agile methodologies\u00a0\u2013 together as a team\u00a0\u2013 instead of a shortcut to deliver insecure code.<\/p>\n

Back in 2016, professionals were always questioned about security over DevOps environments\u00a0\u2013 especially vulnerabilities being questioned on DOCKER for measures that should be taken, snapshots, public images, unsecured communication, inconsistent updates, and patches etc.<\/p>\n

The philosophy of DevSecOps<\/h2>\n

Now, teams are creating a \u2018Security as Code\u2019 culture with on-going development. This comes with concepts of security testing, infrastructure testing, and is not limited to traditional automation or are QA specific.<\/p>\n

The philosophy of DevSecOps integrating security practices within the DevOps process has given testers a more formal way to deploy secure DevOps systems.<\/p>\n

With this movement, DevOps itself is focused on creating new solutions for complex software development processes within an agile framework.<\/p>\n

DevSecOps is a natural and necessary response to the bottleneck effect of older security models on the modern continuous delivery pipeline. The goal is to bridge traditional gaps between IT and security while ensuring fast, safe delivery of code. Silo thinking is replaced by increased communication and shares the responsibility of security tasks during all phases of the delivery process.<\/p>\n

DevSecOps has streamlined the process, now not only focusing on \u2014\u201cspeed of delivery\u201d but also on \u201csecure code”.<\/p>\n

The benefits of SecOps<\/h2>\n

Security is tested early and more often as you execute regression aka security regression in iterations as this will have to be completed within the sprint or delivery cycle. Critical security issues are dealt with as they become apparent, not after a threat or compromise has occurred.<\/p>\n

Professionals that focus on security operations (SecOps) reap the below benefits:<\/p>\n