FNN Expert Edition: Best Practices for Implementing DevSecOps
- OMB defines software security requirements going forward
- GSA, Smithsonian museum and VA share lessons learned
- NGA launches development strategy, metrics and release environment
- Army leans into DevSecOps for ERP consolidation
- NSA issues 鈥榩ost-quantum鈥 guidance
It鈥檚 not surprising that the development, security
and operations approach to building software is
the darling of IT teams across the government.
It鈥檚 essential given the current mandate that
agencies move toward zero trust environments.
Having secure software is fundamental, and DevSecOps helps agencies
get there and deliver user-tailored applications faster.
Ultimately, secure software is essential for transformation, says Federal
Chief Information Security Officer Chris DeRusha. 鈥淲e want everybody
to be truly adopting secure development practices, not for the sake of
adopting them but because security is an enabler to our future 鈥
a future of everything digital,鈥 DeRusha told Federal New Network.
Less clear is the best path for implementing DevSecOps. That鈥檚 in part
because the missions and goals of agencies vary, points out Derrick
Curtis of the Office of Information and Technology at the Veterans
Affairs Department. Evens so, he adds, 鈥渁lmost every scenario has been
covered by someone at least once.鈥 Therefore, people should reach out
to others in government for advice, Curtis recommends.
No matter where your agency is on adopting DevSecOps, it鈥檚 critical
to realize that 鈥 like most things IT 鈥 moving to a methodology for
software that integrates development, security and operations is not
just a matter of making the right technology choices. There鈥檚 a major
people and workflow component that requires people teaming up and
collaborating in new ways.
鈥淗istorically, we鈥檝e let different teams choose their tools and their
different processes of how they build software,鈥 notes Alex Loehr,
chief technology officer, at the National Geospatial-Intelligence Agency.
鈥淭hat led to some really important things, but it also led to a lot of
fragmentation, and what we鈥檙e trying to do is build one set of tooling
and one set of processes.鈥
Vanessa Roberts
Content Editor
Federal News Network
Download the full report to learn how the lessons learned by federal agency and industry experts will help you as your agency embraces DevSecOps. Featuring insights from 5G leaders at Red Hat, Datadog, Second Front, Invicti and Atlassian.
By supplying my contact information, I authorize 探花视频 and its vendors and partner community to contact me with personalized communications about their products and services. Please review our Privacy Policy for more details or to opt-out at any time.