John Rofrano
Feb 26, 2023

--

DevSecOps is a reminder that security needs to be built into everything we do. We need to create applications that are "secure by design". You don't add security later as was done with most legacy systems. So IMHO, there is no need to add "Sec" in the middle of "DevOps" except to remind us that security must be in the mix.

It is a real practice that everyone should be following but I still call it DevOps because there are a lot of things between developing software and operating it and we can't keep adding more letters for each one.

DevSecOps is an acknowledgement that security teams have not been involved in the software development lifecycle and they need to "shift-left" and get involved or be left out.

--

--

John Rofrano
John Rofrano

No responses yet