Understanding the Reality of Secure DevOps
November 14, 2016

Ashish Kuthiala
Hewlett Packard Enterprise

As organizations continue to adopt a more collaborative DevOps model, many face a common challenge: effectively integrating security practices into the application development lifecycle process. This challenge was brought to light in a new Application Security and DevOps Report from Hewlett Packard Enterprise (HPE).

According to the report, virtually all IT operations professionals, security leaders and developers (99 percent) agree that adopting a DevOps culture has the opportunity to improve application security. However, only 20 percent are actually conducting application security testing today during the development process.

Even more troublesome, 17 percent of respondents say they are not using any security technology to protect their applications. This statistic highlights a significant disconnect between the perception and the reality of secure DevOps.

DevOps shows great promise for secure software development. It provides organizations with the ability to test for, find and remediate security vulnerabilities earlier and more frequently in the application lifecycle as a result of continuous testing. Security flaws in software are not different from other software bugs – the earlier you detect and fix them, the greater the potential to prevent negative fallouts later on in the cycle. It is much more cost effective and efficient to catch a security flaw earlier in the software development cycle than to hear about it from customers using your application. If you wait to repair a flaw, you have to invest significantly more resources and time to fix the flaw in customer environments (than you would in dev) and you also risk damaging your brand and losing revenue.

However, DevOps is not a magic bullet that automatically makes applications more secure. In fact, DevOps can actually compound the issue if security is not built into the development process. Applications are being developed and released faster than ever before and the lack of an integrated approach can lead to greater security holes. Therefore it is critical that security and DevOps are incorporated and work seamlessly together.

The report shows that there are significant barriers and gaps which prevent organizations from successfully integrating security into the DevOps processes. Some of the key findings include:

Organizational challenges between security professionals and developers: The report reflected a significant disconnect between developers and security teams. In some cases, respondents admitted to not even knowing who their security colleagues were. Ninety percent of security professionals also stated that integrating application security has become more difficult since their organizations have deployed DevOps.

Lack of security awareness, emphasis, and training for developers: Out of more than 100 job postings for software developers at Fortune 1000 companies, none specified security or secure coding experience or knowledge as part of the skills required.

Shortage of application security talent: For every 80 developers in the organizations surveyed, there is only one application security professional. The lack of appropriately staffed security personnel, along with increasingly rapid development cycles, makes secure development extremely difficult.

The report offers the following recommendations to bring down these barriers and achieve better integration of security experts within DevOps teams as organizations continue to adopt DevOps practices:

Make security a shared responsibility across the organization to eliminate barriers: Security must be embedded throughout every stage of the development process, with executive support and metrics to hold teams accountable for secure development. These metrics should focus on mean-time-to-triage (MTTT), mean-time-to-fix (MTTF), and program compliance.

Make it seamless and more intuitive for developers to practice secure development by bridging awareness, emphasis, and training gaps: Organizations should integrate security tools into the development ecosystem to allow developers to find and fix vulnerabilities in real-time as they write code. This makes it easy and efficient to develop software securely, and educates the developer on secure coding in the process.

Leverage automation and analytics to streamline application security: Organizations should leverage enterprise-grade application security automation with analytics built in during the testing audit process. This allows security professionals to focus only on the highest priority risks, reducing the number of security issues that require manual review, saving both time and resources, while lowering overall risk exposure.

Both security practitioners and developers believe that the DevOps movement has the potential to significantly improve application security. Yet, organizations are struggling to realize that potential. By integrating security into the development cycles early on and making it part of the development lifecycle culture, organizations can successfully secure software in this new DevOps world without impeding the speed and agility that it brings.

Ashish Kuthiala is Senior Director of Marketing and Strategy, Hewlett Packard Enterprise DevOps.

Share this

Industry News

May 16, 2024

Pegasystems announced the general availability of Pega Infinity ’24.1™.

May 16, 2024

Mend.io and Sysdig unveiled a joint solution to help developers, DevOps, and security teams accelerate secure software delivery from development to deployment.

May 16, 2024

GitLab announced new innovations in GitLab 17 to streamline how organizations build, test, secure, and deploy software.

May 16, 2024

Kobiton announced the beta release of mobile test management, a new feature within its test automation platform.

May 15, 2024

Gearset announced its new CI/CD solution, Long Term Projects in Pipelines.

May 15, 2024

Rafay Systems has extended the capabilities of its enterprise PaaS for modern infrastructure to support graphics processing unit- (GPU-) based workloads.

May 15, 2024

NodeScript, a free, low-code developer environment for workflow automation and API integration, is released by UBIO.

May 14, 2024

IBM announced IBM Test Accelerator for Z, a solution designed to revolutionize testing on IBM Z, a tool that expedites the shift-left approach, fostering smooth collaboration between z/OS developers and testers.

May 14, 2024

StreamNative launched Ursa, a Kafka-compatible data streaming engine built on top of lakehouse storage.

May 14, 2024

GitKraken acquired code health innovator, CodeSee.

May 13, 2024

ServiceNow introduced a new no‑code development studio and new automation capabilities to accelerate and scale digital transformation across the enterprise.

May 13, 2024

Security Innovation has added new skills assessments to its Base Camp training platform for software security training.

May 13, 2024

CAST introduced CAST Highlight Extensions Marketplace — an integrated marketplace for the software intelligence product where users can effortlessly browse and download a diverse range of extensions and plugins.

May 09, 2024

Red Hat and Elastic announced an expanded collaboration to deliver next-generation search experiences supporting retrieval augmented generation (RAG) patterns using Elasticsearch as a preferred vector database solution integrated on Red Hat OpenShift AI.

May 09, 2024

Traceable AI announced an Early Access Program for its new Generative AI API Security capabilities.