
Re-examining the Efficiency of DevSecOps
CIO Review APAC | Tuesday, November 08, 2022

Development, security, and operations collaborating together will promote efficiency for software production. However, there is a need for a few reassessments.
FREMONT, CA: One of the primary goals of utilizing a DevSecOps approach to software development is to get security on board quickly rather than later in the cycle. However, whether they translate into increased security is yet to be understood. Development and deployment speed combined with security are some of the expected benefits of DevSecOps, despite requiring different types of teams to adapt to each other, if not compromise. The question arises if those compromises include easing up on security to deliver software.
Companies should focus on tools and automation to help security engineering move at the same velocity and deliver visibility. Moreover, security engineering has advanced beyond using various platforms to define how security should be implemented. Automation for security helps to realise the true potential of DevSecOps. There is a need for a security engineer to assist the DevOps team to truly unleash DevSecOps.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Receiving the DevSecOps elements to align takes focus and understanding, particularly if teams are accustomed to operating independently of each other. Security or operations will not operate for the business unit in which the development is happening.
Shifts in DevSecOps Culture
The mentioned challenge leads teams to concentrate on other tasks, especially making codebases less of a priority. Although development teams initially encountered issues, the DevSecOps culture has shifted to imbibe more security testing.
More mutual understanding is important as it would be expensive to introduce fixes in production after an issue arises. Most security tools are designed around incidents that have happened before. This is because they have gaps in awareness of new types of attacks. Most zero-day vulnerabilities in breaches are unaware, or it is the human factor.
Security should be thoroughly embedded in DevSecOps teams to be on the development track, raising questions along the way. DevSecOps is often combined with CI/CD for customers with pressure to introduce features immediately, which can conflict with another strategy aspect. Security people want to slow down the processes and ensure that what customers get will not risk them.
Importance of Prioritisation
Understanding the real potential risk severity bridges the gap between those ideologies and prioritises how organisations respond. Businesses cannot merely respond to everything but need a rubric allowing for autonomy for DevOps.
The immediacy to automate everything in IT and security will remain a desirable factor in how DevSecOps functions. Companies are not spending the time to manually understand what they are doing before automating. For instance, developers will create automation for operational tasks for the pipeline, but operations are likely not to understand the codebase, possibly creating confusion. Simultaneously, deploying security tools in the pipeline with other teams not understanding the codebase also leads to confusion and vulnerabilities.
Operations and security often fall under the IT field, and businesses frequently focus on other business goals. For a true DevSecOps team to achieve the required understanding level, they should form a team and work for that business unit to achieve similar goals.
More in News