Putting security into DevOps

How secure code fits within the larger picture

Published September 2016

We believe DevOps is one of the most disruptive trends ever to hit software development, and will drive organisational changes over the next decade. But it is equally disruptive for application security, in a good way. DevOps enables developers to weave security testing, validation, and monitoring into both application development and deployment.

To illustrate how this affects application security, this research paper will dive into what DevOps is, and then explain how delivering secure code fits within the larger picture. But to understand why most software development organisations are adopting this trend — often over strenuous objections — you need to understand why it’s so attractive, and the problems it is helping organisations solve.