Modern App Development
and Enterprise DevOps Series
6 Tips to Integrate Security
into Your DevOps Practices
6 tips to integrate security into your DevOps practices 2
Summary
DevOps proven practices illustrate how collaboration between developer and operations teams
leads to aster sotware delivery. Now, the issue acing digital leaders is the security and compliancy
o their code, workfows, and inrastructure. The logical next step: integrate your security team
with the existing DevOps team—breaking down another organizational silo. The most challenging
part o DevSecOps adoption is to make security complement existing business processes, culture,
and people. How can technical leaders develop cross-unction collaboration and unite developer,
security, and operations teams around the culture o security as a shared responsibility?
The tips inside include how to:
Develop a security-rst company culture
to drive DevSecOps adoption
Proactively secure your code, workfows, inrastructure,
and sotware supply chain against vulnerabilities
Provide your teams with shared tooling and best practices
to enable end-to-end visibility and traceability
Leverage improved insights and policy automation
to realize continuous compliancy
The most challenging part of DevSecOps adoption
is to make security complement existing business
processes, culture, and people
6 tips to integrate security into your DevOps practices 3
Table of contents
6 tips to integrate security into your DevOps practices
TIP 1 Build a security-frst culture across the business 5
Integrate security in the early stages of the 9
TIP 2
development lifecycle
TIP 3 Monitor and observe continuously with purpose 15
TIP 4 Embrace everything-as-code 23
TIP 5 Realize compliancy with policy automation 31
TIP 6 Secure and visualize your software supply chain 35
Closing thoughts 38
How Microsoft and Sogeti can help 40