{"id":4424,"date":"2021-09-29T06:44:00","date_gmt":"2021-09-29T06:44:00","guid":{"rendered":"https:\/\/wibmo.com\/devsecops-a-necessity-in-the-current-landscape\/"},"modified":"2024-08-07T09:30:05","modified_gmt":"2024-08-07T09:30:05","slug":"devsecops-a-necessity-in-the-current-landscape","status":"publish","type":"post","link":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/","title":{"rendered":"DevSecOps \u2014 A necessity in the current landscape"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4424\" class=\"elementor elementor-4424\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2f1cb4f6 e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"2f1cb4f6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-362e59b0 elementor-widget elementor-widget-text-editor\" data-id=\"362e59b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p id=\"26bc\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\">Let\u2019s start with the basics here. Traditionally, we followed Software Development Life Cycle, in short SDLC, a structured approach to develop quality software that meets customer requirements. With a rapid evolution in lifestyle, we moved to the Agile method which is one of the variants of SDLC to develop software in an iterative and fast way. While the agile methodology aims to develop a software or a component of software quicker, there is a need to deploy that component at equal speed in production set up to make it available to the user community. This development process along with the deployment process is together referred to as DevOps. Essentially, DevOps refers to the continuous integration of a software component and its continuous deployment. Now, thinking of security from the early stage of the development cycle instead of retrospectively fitting at the end of the cycle, transcends DevOps to DevSecOps. Here, we are shifting Security at the early stage of the cycle, i.e., shifting to the left of the cycle, which is referred to as Shift Left.<\/p>\n<p id=\"f76b\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\">To establish an analogy, may not be exact but a crude analogy to understand better, let\u2019s look at some of the household work like cooking. I cook in my free time at home. After cooking, I request my wife to serve the food to family members. Here, the cooking process is Development, serving process is Operations, together with cooking and serving process is DevOps. Now, it\u2019s important to understand in this example what is DevSecOps. While cooking, I am concerned about the hygiene of the food from the beginning, else, retrospectively fitting hygiene is very difficult. Therefore, the cooking and serving process along with maintaining hygiene in the entire process is DevSecOps.<\/p>\n<p id=\"db69\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\">In a rapidly moving world where technology is easing the way we do business and lead life, there is a rapid increase in threats to the technology landscape by fraudsters or individuals with malicious intent. Therefore, it\u2019s imperative that security is looked at from the very early stage of the development cycle and all possible threat vectors are identified and appropriate controls or safeguards are built into the software to protect the software and therefore protect its user community and ultimately customers. Let\u2019s look at some of the benefits of DevSecOps.<\/p>\n<p id=\"6a48\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Continuous integration (CI)<\/strong>&nbsp;\u2014 merges code changes to ensure the most recent version is available to developers.<\/p>\n<p id=\"b38a\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Continuous delivery and continuous deployment (CD)<\/strong>&nbsp;\u2014 automate the process of releasing updates to increase efficiency.<\/p>\n<p id=\"ae2d\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Microservices \u2014&nbsp;<\/strong>builds an application as a set of smaller services.<\/p>\n<p id=\"c1ce\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Infrastructure as code (IaC) \u2014&nbsp;<\/strong>designing, implementing, and managing app infrastructure needs through code<strong class=\"wj lv\">.<\/strong><\/p>\n<p id=\"7954\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Common weaknesses enumeration (CWE)<\/strong>&nbsp;\u2014 improves the quality of code and increases the level of security during the CI and CD phases.<\/p>\n<p id=\"7f58\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Threat modeling&nbsp;<\/strong>\u2014 implements security testing during the development pipeline to save time and cost in the future.<\/p>\n<p id=\"ba5b\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Automated security testing<\/strong>&nbsp;\u2014 test for vulnerabilities in new builds on regular basis.<\/p>\n<p id=\"ede5\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Incident management<\/strong>&nbsp;\u2014 creates a standard framework for responding to security incidents.<\/p>\n<p id=\"dc3a\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Fast delivery&nbsp;<\/strong>\u2014 achieve ensure fast delivery of application by embedding automated security controls and tests early in the development cycle.<\/p>\n<p id=\"6bbc\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Enriched efficiency<\/strong>&nbsp;\u2014 higher efficiency by scanning code for vulnerabilities as it&#8217;s written.<\/p>\n<p id=\"6847\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Automotive<\/strong>: reduce lengthy cycle times while still meeting software compliance standards.<\/p>\n<p id=\"8d8e\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Digital Transformation<\/strong>: enable digital transformation efforts while maintaining the privacy and security of sensitive data per regulations such as GDPR.<\/p>\n<p id=\"41c7\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Code analysis<\/strong>&nbsp;\u2014 deliver code in small chunks so vulnerabilities can be identified quickly.<\/p>\n<p id=\"ac3e\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Compliance monitoring<\/strong>&nbsp;\u2014 be ready for an audit at any time that means being in a constant state of compliance, including gathering evidence of&nbsp;<a class=\"af xf\" href=\"https:\/\/www.sumologic.com\/security\/platform-security\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">GDPR compliance<\/a>,&nbsp;<a class=\"af xf\" href=\"https:\/\/www.sumologic.com\/brief\/pci-dss-compliance-requirement-10\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">PCI compliance<\/a>, etc.<\/p>\n<p id=\"4fac\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Threat investigation<\/strong>&nbsp;\u2014 identify potential emerging threats with each code update and be able to respond quickly.<\/p>\n<p id=\"f169\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Vulnerability assessment<\/strong>&nbsp;\u2014 identify new vulnerabilities with code analysis and accordingly analyze how quickly they are being responded to and patched.<\/p>\n<p id=\"2ec6\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Security training<\/strong>&nbsp;\u2014 train software and IT engineers with guidelines for set routines.<\/p>\n<figure class=\"aff afg afh afi afj sj sd se paragraph-image\">\n<div class=\"sk sl dl sm bg sn\" tabindex=\"0\" role=\"button\">\n<div class=\"sd se aix\"><picture><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1240\/format:webp\/1*JeibiFVy-26RLv9t2RT3yg.png 1240w\" type=\"image\/webp\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 620px\"><source srcset=\"https:\/\/miro.medium.com\/v2\/resize:fit:640\/1*JeibiFVy-26RLv9t2RT3yg.png 640w, https:\/\/miro.medium.com\/v2\/resize:fit:720\/1*JeibiFVy-26RLv9t2RT3yg.png 720w, https:\/\/miro.medium.com\/v2\/resize:fit:750\/1*JeibiFVy-26RLv9t2RT3yg.png 750w, https:\/\/miro.medium.com\/v2\/resize:fit:786\/1*JeibiFVy-26RLv9t2RT3yg.png 786w, https:\/\/miro.medium.com\/v2\/resize:fit:828\/1*JeibiFVy-26RLv9t2RT3yg.png 828w, https:\/\/miro.medium.com\/v2\/resize:fit:1100\/1*JeibiFVy-26RLv9t2RT3yg.png 1100w, https:\/\/miro.medium.com\/v2\/resize:fit:1240\/1*JeibiFVy-26RLv9t2RT3yg.png 1240w\" sizes=\"(min-resolution: 4dppx) and (max-width: 700px) 50vw, (-webkit-min-device-pixel-ratio: 4) and (max-width: 700px) 50vw, (min-resolution: 3dppx) and (max-width: 700px) 67vw, (-webkit-min-device-pixel-ratio: 3) and (max-width: 700px) 65vw, (min-resolution: 2.5dppx) and (max-width: 700px) 80vw, (-webkit-min-device-pixel-ratio: 2.5) and (max-width: 700px) 80vw, (min-resolution: 2dppx) and (max-width: 700px) 100vw, (-webkit-min-device-pixel-ratio: 2) and (max-width: 700px) 100vw, 620px\" data-testid=\"og\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bg so sp c\" role=\"presentation\" src=\"https:\/\/miro.medium.com\/v2\/resize:fit:1240\/1*JeibiFVy-26RLv9t2RT3yg.png\" alt=\"\" width=\"620\" height=\"384\"><\/picture><\/div>\n<\/div>\n<figcaption class=\"aiy ew aiz sd se aja ajb be b bf z dn\" data-selectable-paragraph=\"\">Source:&nbsp;<a class=\"af xf\" href=\"https:\/\/accelera.com.au\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">https:\/\/accelera.com.au\/<\/a><\/figcaption>\n<\/figure>\n<p id=\"c643\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\">To conclude, DevSecOps is a cultural shift which means security is a shared responsibility, and everyone participating in SDLC has to a play very vital role in building security into the DevOps workflow.<\/p>\n<p id=\"6938\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><strong class=\"wj lv\">Author:<\/strong><\/p>\n<p id=\"0f2a\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><a class=\"af xf\" href=\"https:\/\/www.linkedin.com\/in\/ravibhushan\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">Ravi Bhushan<\/a>, Head- GRC and&nbsp;<a class=\"af xf\" href=\"https:\/\/www.linkedin.com\/in\/ritesh-prasad20\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">Ritesh Prasad<\/a>, Manager DevOps+SRE<\/p>\n<p id=\"7693\" class=\"pw-post-body-paragraph wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe fv bj\" data-selectable-paragraph=\"\"><a class=\"af xf\" href=\"https:\/\/www.wibmo.com\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">Wibmo<\/a>&nbsp;A PayU\/Naspers FinTech Company<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0eb99d8 e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"0eb99d8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b1b23be wpr-post-info-align-center elementor-widget elementor-widget-wpr-post-info\" data-id=\"b1b23be\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wpr-post-info.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<ul class=\"wpr-post-info wpr-post-info-vertical\"><li class=\"wpr-post-info-taxonomy\"><a href=\"https:\/\/wibmo.com\/blogs\/tag\/compliance\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Compliance<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/devops\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>DevOps<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/infosec\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Infosec<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/risk-management-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Risk Management<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/security-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Security<\/a><\/li><\/ul>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Let\u2019s start with the basics here. Traditionally, we followed Software Development Life Cycle, in short SDLC, a structured approach to develop quality software that meets customer requirements. With a rapid evolution in lifestyle, we moved to the Agile method which is one of the variants of SDLC to develop software in an iterative and fast way. While the agile methodology aims to develop a software or a component of software quicker, there is a need to deploy that component at equal speed in production set up to make it available to the user community. This development process along with the deployment process is together referred to as DevOps. Essentially, DevOps refers to the continuous integration of a software component and its continuous deployment. Now, thinking of security from the early stage of the development cycle instead of retrospectively fitting at the end of the cycle, transcends DevOps to DevSecOps. Here, we are shifting Security at the early stage of the cycle, i.e., shifting to the left of the cycle, which is referred to as Shift Left. To establish an analogy, may not be exact but a crude analogy to understand better, let\u2019s look at some of the household work like cooking. I cook in my free time at home. After cooking, I request my wife to serve the food to family members. Here, the cooking process is Development, serving process is Operations, together with cooking and serving process is DevOps. Now, it\u2019s important to understand in this example what is DevSecOps. While cooking, I am concerned about the hygiene of the food from the beginning, else, retrospectively fitting hygiene is very difficult. Therefore, the cooking and serving process along with maintaining hygiene in the entire process is DevSecOps. In a rapidly moving world where technology is easing the way we do business and lead life, there is a rapid increase in threats to the technology landscape by fraudsters or individuals with malicious intent. Therefore, it\u2019s imperative that security is looked at from the very early stage of the development cycle and all possible threat vectors are identified and appropriate controls or safeguards are built into the software to protect the software and therefore protect its user community and ultimately customers. Let\u2019s look at some of the benefits of DevSecOps. Continuous integration (CI)&nbsp;\u2014 merges code changes to ensure the most recent version is available to developers. Continuous delivery and continuous deployment (CD)&nbsp;\u2014 automate the process of releasing updates to increase efficiency. Microservices \u2014&nbsp;builds an application as a set of smaller services. Infrastructure as code (IaC) \u2014&nbsp;designing, implementing, and managing app infrastructure needs through code. Common weaknesses enumeration (CWE)&nbsp;\u2014 improves the quality of code and increases the level of security during the CI and CD phases. Threat modeling&nbsp;\u2014 implements security testing during the development pipeline to save time and cost in the future. Automated security testing&nbsp;\u2014 test for vulnerabilities in new builds on regular basis. Incident management&nbsp;\u2014 creates a standard framework for responding to security incidents. Fast delivery&nbsp;\u2014 achieve ensure fast delivery of application by embedding automated security controls and tests early in the development cycle. Enriched efficiency&nbsp;\u2014 higher efficiency by scanning code for vulnerabilities as it&#8217;s written. Automotive: reduce lengthy cycle times while still meeting software compliance standards. Digital Transformation: enable digital transformation efforts while maintaining the privacy and security of sensitive data per regulations such as GDPR. Code analysis&nbsp;\u2014 deliver code in small chunks so vulnerabilities can be identified quickly. Compliance monitoring&nbsp;\u2014 be ready for an audit at any time that means being in a constant state of compliance, including gathering evidence of&nbsp;GDPR compliance,&nbsp;PCI compliance, etc. Threat investigation&nbsp;\u2014 identify potential emerging threats with each code update and be able to respond quickly. Vulnerability assessment&nbsp;\u2014 identify new vulnerabilities with code analysis and accordingly analyze how quickly they are being responded to and patched. Security training&nbsp;\u2014 train software and IT engineers with guidelines for set routines. Source:&nbsp;https:\/\/accelera.com.au\/ To conclude, DevSecOps is a cultural shift which means security is a shared responsibility, and everyone participating in SDLC has to a play very vital role in building security into the DevOps workflow. Author: Ravi Bhushan, Head- GRC and&nbsp;Ritesh Prasad, Manager DevOps+SRE Wibmo&nbsp;A PayU\/Naspers FinTech Company Compliance, DevOps, Infosec, Risk Management, Security<\/p>\n","protected":false},"author":4,"featured_media":4436,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[82],"tags":[160,164,165,143,134],"class_list":["post-4424","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-insights","tag-compliance","tag-devops","tag-infosec","tag-risk-management-2","tag-security-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"og:description\" content=\"Let\u2019s start with the basics here. Traditionally, we followed Software Development Life Cycle, in short SDLC, a structured approach to develop quality software that meets customer requirements. With a rapid evolution in lifestyle, we moved to the Agile method which is one of the variants of SDLC to develop software in an iterative and fast way. While the agile methodology aims to develop a software or a component of software quicker, there is a need to deploy that component at equal speed in production set up to make it available to the user community. This development process along with the deployment process is together referred to as DevOps. Essentially, DevOps refers to the continuous integration of a software component and its continuous deployment. Now, thinking of security from the early stage of the development cycle instead of retrospectively fitting at the end of the cycle, transcends DevOps to DevSecOps. Here, we are shifting Security at the early stage of the cycle, i.e., shifting to the left of the cycle, which is referred to as Shift Left. To establish an analogy, may not be exact but a crude analogy to understand better, let\u2019s look at some of the household work like cooking. I cook in my free time at home. After cooking, I request my wife to serve the food to family members. Here, the cooking process is Development, serving process is Operations, together with cooking and serving process is DevOps. Now, it\u2019s important to understand in this example what is DevSecOps. While cooking, I am concerned about the hygiene of the food from the beginning, else, retrospectively fitting hygiene is very difficult. Therefore, the cooking and serving process along with maintaining hygiene in the entire process is DevSecOps. In a rapidly moving world where technology is easing the way we do business and lead life, there is a rapid increase in threats to the technology landscape by fraudsters or individuals with malicious intent. Therefore, it\u2019s imperative that security is looked at from the very early stage of the development cycle and all possible threat vectors are identified and appropriate controls or safeguards are built into the software to protect the software and therefore protect its user community and ultimately customers. Let\u2019s look at some of the benefits of DevSecOps. Continuous integration (CI)&nbsp;\u2014 merges code changes to ensure the most recent version is available to developers. Continuous delivery and continuous deployment (CD)&nbsp;\u2014 automate the process of releasing updates to increase efficiency. Microservices \u2014&nbsp;builds an application as a set of smaller services. Infrastructure as code (IaC) \u2014&nbsp;designing, implementing, and managing app infrastructure needs through code. Common weaknesses enumeration (CWE)&nbsp;\u2014 improves the quality of code and increases the level of security during the CI and CD phases. Threat modeling&nbsp;\u2014 implements security testing during the development pipeline to save time and cost in the future. Automated security testing&nbsp;\u2014 test for vulnerabilities in new builds on regular basis. Incident management&nbsp;\u2014 creates a standard framework for responding to security incidents. Fast delivery&nbsp;\u2014 achieve ensure fast delivery of application by embedding automated security controls and tests early in the development cycle. Enriched efficiency&nbsp;\u2014 higher efficiency by scanning code for vulnerabilities as it&#8217;s written. Automotive: reduce lengthy cycle times while still meeting software compliance standards. Digital Transformation: enable digital transformation efforts while maintaining the privacy and security of sensitive data per regulations such as GDPR. Code analysis&nbsp;\u2014 deliver code in small chunks so vulnerabilities can be identified quickly. Compliance monitoring&nbsp;\u2014 be ready for an audit at any time that means being in a constant state of compliance, including gathering evidence of&nbsp;GDPR compliance,&nbsp;PCI compliance, etc. Threat investigation&nbsp;\u2014 identify potential emerging threats with each code update and be able to respond quickly. Vulnerability assessment&nbsp;\u2014 identify new vulnerabilities with code analysis and accordingly analyze how quickly they are being responded to and patched. Security training&nbsp;\u2014 train software and IT engineers with guidelines for set routines. Source:&nbsp;https:\/\/accelera.com.au\/ To conclude, DevSecOps is a cultural shift which means security is a shared responsibility, and everyone participating in SDLC has to a play very vital role in building security into the DevOps workflow. Author: Ravi Bhushan, Head- GRC and&nbsp;Ritesh Prasad, Manager DevOps+SRE Wibmo&nbsp;A PayU\/Naspers FinTech Company Compliance, DevOps, Infosec, Risk Management, Security\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/\" \/>\n<meta property=\"og:site_name\" content=\"Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-29T06:44:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-07T09:30:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1400\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Ravi Bhushan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ravi Bhushan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/\"},\"author\":{\"name\":\"Ravi Bhushan\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/1c14f11ac95d5250c6f863da97b234b2\"},\"headline\":\"DevSecOps \u2014 A necessity in the current landscape\",\"datePublished\":\"2021-09-29T06:44:00+00:00\",\"dateModified\":\"2024-08-07T09:30:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/\"},\"wordCount\":741,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/DevSecOps.webp\",\"keywords\":[\"Compliance\",\"DevOps\",\"Infosec\",\"Risk Management\",\"Security\"],\"articleSection\":[\"Industry Insights\"],\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/\",\"name\":\"DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/DevSecOps.webp\",\"datePublished\":\"2021-09-29T06:44:00+00:00\",\"dateModified\":\"2024-08-07T09:30:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#primaryimage\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/DevSecOps.webp\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/DevSecOps.webp\",\"width\":1400,\"height\":700},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/devsecops-a-necessity-in-the-current-landscape\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DevSecOps \u2014 A necessity in the current landscape\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"width\":220,\"height\":45,\"caption\":\"Digital Payments, Payment Security and Lending - Wibmo\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/1c14f11ac95d5250c6f863da97b234b2\",\"name\":\"Ravi Bhushan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g\",\"caption\":\"Ravi Bhushan\"},\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/author\\\/ravi-bhushan\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/","og_locale":"en_US","og_type":"article","og_title":"DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo","og_description":"Let\u2019s start with the basics here. Traditionally, we followed Software Development Life Cycle, in short SDLC, a structured approach to develop quality software that meets customer requirements. With a rapid evolution in lifestyle, we moved to the Agile method which is one of the variants of SDLC to develop software in an iterative and fast way. While the agile methodology aims to develop a software or a component of software quicker, there is a need to deploy that component at equal speed in production set up to make it available to the user community. This development process along with the deployment process is together referred to as DevOps. Essentially, DevOps refers to the continuous integration of a software component and its continuous deployment. Now, thinking of security from the early stage of the development cycle instead of retrospectively fitting at the end of the cycle, transcends DevOps to DevSecOps. Here, we are shifting Security at the early stage of the cycle, i.e., shifting to the left of the cycle, which is referred to as Shift Left. To establish an analogy, may not be exact but a crude analogy to understand better, let\u2019s look at some of the household work like cooking. I cook in my free time at home. After cooking, I request my wife to serve the food to family members. Here, the cooking process is Development, serving process is Operations, together with cooking and serving process is DevOps. Now, it\u2019s important to understand in this example what is DevSecOps. While cooking, I am concerned about the hygiene of the food from the beginning, else, retrospectively fitting hygiene is very difficult. Therefore, the cooking and serving process along with maintaining hygiene in the entire process is DevSecOps. In a rapidly moving world where technology is easing the way we do business and lead life, there is a rapid increase in threats to the technology landscape by fraudsters or individuals with malicious intent. Therefore, it\u2019s imperative that security is looked at from the very early stage of the development cycle and all possible threat vectors are identified and appropriate controls or safeguards are built into the software to protect the software and therefore protect its user community and ultimately customers. Let\u2019s look at some of the benefits of DevSecOps. Continuous integration (CI)&nbsp;\u2014 merges code changes to ensure the most recent version is available to developers. Continuous delivery and continuous deployment (CD)&nbsp;\u2014 automate the process of releasing updates to increase efficiency. Microservices \u2014&nbsp;builds an application as a set of smaller services. Infrastructure as code (IaC) \u2014&nbsp;designing, implementing, and managing app infrastructure needs through code. Common weaknesses enumeration (CWE)&nbsp;\u2014 improves the quality of code and increases the level of security during the CI and CD phases. Threat modeling&nbsp;\u2014 implements security testing during the development pipeline to save time and cost in the future. Automated security testing&nbsp;\u2014 test for vulnerabilities in new builds on regular basis. Incident management&nbsp;\u2014 creates a standard framework for responding to security incidents. Fast delivery&nbsp;\u2014 achieve ensure fast delivery of application by embedding automated security controls and tests early in the development cycle. Enriched efficiency&nbsp;\u2014 higher efficiency by scanning code for vulnerabilities as it&#8217;s written. Automotive: reduce lengthy cycle times while still meeting software compliance standards. Digital Transformation: enable digital transformation efforts while maintaining the privacy and security of sensitive data per regulations such as GDPR. Code analysis&nbsp;\u2014 deliver code in small chunks so vulnerabilities can be identified quickly. Compliance monitoring&nbsp;\u2014 be ready for an audit at any time that means being in a constant state of compliance, including gathering evidence of&nbsp;GDPR compliance,&nbsp;PCI compliance, etc. Threat investigation&nbsp;\u2014 identify potential emerging threats with each code update and be able to respond quickly. Vulnerability assessment&nbsp;\u2014 identify new vulnerabilities with code analysis and accordingly analyze how quickly they are being responded to and patched. Security training&nbsp;\u2014 train software and IT engineers with guidelines for set routines. Source:&nbsp;https:\/\/accelera.com.au\/ To conclude, DevSecOps is a cultural shift which means security is a shared responsibility, and everyone participating in SDLC has to a play very vital role in building security into the DevOps workflow. Author: Ravi Bhushan, Head- GRC and&nbsp;Ritesh Prasad, Manager DevOps+SRE Wibmo&nbsp;A PayU\/Naspers FinTech Company Compliance, DevOps, Infosec, Risk Management, Security","og_url":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/","og_site_name":"Digital Payments, Payment Security and Lending - Wibmo","article_published_time":"2021-09-29T06:44:00+00:00","article_modified_time":"2024-08-07T09:30:05+00:00","og_image":[{"width":1400,"height":700,"url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","type":"image\/webp"}],"author":"Ravi Bhushan","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ravi Bhushan","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#article","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/"},"author":{"name":"Ravi Bhushan","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/1c14f11ac95d5250c6f863da97b234b2"},"headline":"DevSecOps \u2014 A necessity in the current landscape","datePublished":"2021-09-29T06:44:00+00:00","dateModified":"2024-08-07T09:30:05+00:00","mainEntityOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/"},"wordCount":741,"commentCount":0,"publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","keywords":["Compliance","DevOps","Infosec","Risk Management","Security"],"articleSection":["Industry Insights"],"inLanguage":"en","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/","url":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/","name":"DevSecOps \u2014 A necessity in the current landscape - Digital Payments, Payment Security and Lending - Wibmo","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#primaryimage"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","datePublished":"2021-09-29T06:44:00+00:00","dateModified":"2024-08-07T09:30:05+00:00","breadcrumb":{"@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#primaryimage","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","width":1400,"height":700},{"@type":"BreadcrumbList","@id":"https:\/\/wibmo.com\/blogs\/devsecops-a-necessity-in-the-current-landscape\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wibmo.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"DevSecOps \u2014 A necessity in the current landscape"}]},{"@type":"WebSite","@id":"https:\/\/wibmo.com\/blogs\/#website","url":"https:\/\/wibmo.com\/blogs\/","name":"Digital Payments, Payment Security and Lending - Wibmo","description":"","publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wibmo.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":"Organization","@id":"https:\/\/wibmo.com\/blogs\/#organization","name":"Digital Payments, Payment Security and Lending - Wibmo","url":"https:\/\/wibmo.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","width":220,"height":45,"caption":"Digital Payments, Payment Security and Lending - Wibmo"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/1c14f11ac95d5250c6f863da97b234b2","name":"Ravi Bhushan","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/39b9f1089adc085ccb4f9869935d2bc546783639975c9430b2c8c42e61586537?s=96&d=mm&r=g","caption":"Ravi Bhushan"},"url":"https:\/\/wibmo.com\/blogs\/author\/ravi-bhushan\/"}]}},"jetpack_featured_media_url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/DevSecOps.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/comments?post=4424"}],"version-history":[{"count":0,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4424\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media\/4436"}],"wp:attachment":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media?parent=4424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/categories?post=4424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/tags?post=4424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}