Security is everyone's responsibility. The 2016 State of DevOps Report (PDF) research shows that high-performing teams spend 50 percent less time remediating security issues than low-performing teams.

By better integrating information security (InfoSec) objectives into daily work, teams can achieve higher levels of software delivery performance and build more secure systems. This idea is also known as shifting left, because concerns, whole foods magnesium security concerns, are addressed earlier in the software development lifecycle (that is, left in a left-to-right schedule diagram).

In software development, there are at least these four activities: design, develop, test, and release. In a traditional software development cycle, testing happens after development is complete.

This typically means that a team discovers significant problems, including architectural flaws, that are expensive to fix. After defects are discovered, developers must then find the contributing factors and how to fix them. The time required to find the defect, develop a solution, and fully test the fix are unpredictable.

This can push out delivery dates. Continuous delivery borrows from lean thinking the concept of building quality into the product throughout the process. Edwards Deming says in his Fourteen Points for the Transformation of Management, "Cease dependence on inspection to achieve quality. Eliminate the need for inspection on a mass basis by building quality into the product in the first place.

Research from DevOps Research and Assessment (DORA) (PDF) shows that teams can achieve better outcomes by making security a part of everyone's daily work instead of testing for security concerns at the end of the process.

This means integrating security testing and controls into the daily work of development, QA, and operations. Ideally, much of this work can be automated and put into your deployment pipeline. Shifting the security review process "left" or earlier in the software development lifecycle requires several changes from traditional information security methods, but is not a significant deviation from traditional software development methods on quality inspection.

The InfoSec team should get involved in the design phase for all projects. When a project design begins, a security review can be added as a gating factor for releasing the design to the development stage. This review process might represent a fundamental change in the development process.

This change might require developer training. It might also require you to increase the staff of the InfoSec team, and provide organizational support for the change. While including InfoSec might represent a change in your organization, including new stakeholders in design is not a new concept and should be embraced when considering the benefits.

Providing developers with preapproved libraries and tools that include input from the InfoSec team can help standardize developer code. Using standard code makes it easier for the InfoSec team to review the code. Standard code allows automated testing to check that developer are using preapproved libraries. This can also help scale the input and influence from InfoSec, because that team is typically understaffed compared to developers and testers.

Building security tests into the automated testing process means that code can be continuously tested at scale without requiring a manual review. Automated testing can identify common security vulnerabilities, and it can be applied uniformly as a part of a continuous integration or build process.

Automated testing does require you to design and develop automated security tests, both initially and as an on-going effort as new security tests are identified. This is another opportunity to scale the input from the InfoSec team. Based on the stated ways to improve outlined above, you can measure security in the following ways. These capabilities were discovered by the DORA State of DevOps research program, an independent, (Desflurae)- rigorous investigation into the practices and capabilities that drive high performance.

To learn more, read our DevOps resources.



