Understanding the Reality of Secure DevOps
November 14, 2016

Ashish Kuthiala
Hewlett Packard Enterprise

As organizations continue to adopt a more collaborative DevOps model, many face a common challenge: effectively integrating security practices into the application development lifecycle process. This challenge was brought to light in a new Application Security and DevOps Report from Hewlett Packard Enterprise (HPE).

According to the report, virtually all IT operations professionals, security leaders and developers (99 percent) agree that adopting a DevOps culture has the opportunity to improve application security. However, only 20 percent are actually conducting application security testing today during the development process.

Even more troublesome, 17 percent of respondents say they are not using any security technology to protect their applications. This statistic highlights a significant disconnect between the perception and the reality of secure DevOps.

DevOps shows great promise for secure software development. It provides organizations with the ability to test for, find and remediate security vulnerabilities earlier and more frequently in the application lifecycle as a result of continuous testing. Security flaws in software are not different from other software bugs – the earlier you detect and fix them, the greater the potential to prevent negative fallouts later on in the cycle. It is much more cost effective and efficient to catch a security flaw earlier in the software development cycle than to hear about it from customers using your application. If you wait to repair a flaw, you have to invest significantly more resources and time to fix the flaw in customer environments (than you would in dev) and you also risk damaging your brand and losing revenue.

However, DevOps is not a magic bullet that automatically makes applications more secure. In fact, DevOps can actually compound the issue if security is not built into the development process. Applications are being developed and released faster than ever before and the lack of an integrated approach can lead to greater security holes. Therefore it is critical that security and DevOps are incorporated and work seamlessly together.

The report shows that there are significant barriers and gaps which prevent organizations from successfully integrating security into the DevOps processes. Some of the key findings include:

Organizational challenges between security professionals and developers: The report reflected a significant disconnect between developers and security teams. In some cases, respondents admitted to not even knowing who their security colleagues were. Ninety percent of security professionals also stated that integrating application security has become more difficult since their organizations have deployed DevOps.

Lack of security awareness, emphasis, and training for developers: Out of more than 100 job postings for software developers at Fortune 1000 companies, none specified security or secure coding experience or knowledge as part of the skills required.

Shortage of application security talent: For every 80 developers in the organizations surveyed, there is only one application security professional. The lack of appropriately staffed security personnel, along with increasingly rapid development cycles, makes secure development extremely difficult.

The report offers the following recommendations to bring down these barriers and achieve better integration of security experts within DevOps teams as organizations continue to adopt DevOps practices:

Make security a shared responsibility across the organization to eliminate barriers: Security must be embedded throughout every stage of the development process, with executive support and metrics to hold teams accountable for secure development. These metrics should focus on mean-time-to-triage (MTTT), mean-time-to-fix (MTTF), and program compliance.

Make it seamless and more intuitive for developers to practice secure development by bridging awareness, emphasis, and training gaps: Organizations should integrate security tools into the development ecosystem to allow developers to find and fix vulnerabilities in real-time as they write code. This makes it easy and efficient to develop software securely, and educates the developer on secure coding in the process.

Leverage automation and analytics to streamline application security: Organizations should leverage enterprise-grade application security automation with analytics built in during the testing audit process. This allows security professionals to focus only on the highest priority risks, reducing the number of security issues that require manual review, saving both time and resources, while lowering overall risk exposure.

Both security practitioners and developers believe that the DevOps movement has the potential to significantly improve application security. Yet, organizations are struggling to realize that potential. By integrating security into the development cycles early on and making it part of the development lifecycle culture, organizations can successfully secure software in this new DevOps world without impeding the speed and agility that it brings.

Ashish Kuthiala is Senior Director of Marketing and Strategy, Hewlett Packard Enterprise DevOps.

Share this

Industry News

March 27, 2025

webAI and MacStadium(link is external) announced a strategic partnership that will revolutionize the deployment of large-scale artificial intelligence models using Apple's cutting-edge silicon technology.

March 27, 2025

Development work on the Linux kernel — the core software that underpins the open source Linux operating system — has a new infrastructure partner in Akamai. The company's cloud computing service and content delivery network (CDN) will support kernel.org, the main distribution system for Linux kernel source code and the primary coordination vehicle for its global developer network.

March 27, 2025

Komodor announced a new approach to full-cycle drift management for Kubernetes, with new capabilities to automate the detection, investigation, and remediation of configuration drift—the gradual divergence of Kubernetes clusters from their intended state—helping organizations enforce consistency across large-scale, multi-cluster environments.

March 26, 2025

Red Hat announced the latest updates to Red Hat AI, its portfolio of products and services designed to help accelerate the development and deployment of AI solutions across the hybrid cloud.

March 26, 2025

CloudCasa by Catalogic announced the availability of the latest version of its CloudCasa software.

March 26, 2025

BrowserStack announced the launch of Private Devices, expanding its enterprise portfolio to address the specialized testing needs of organizations with stringent security requirements.

March 25, 2025

Chainguard announced Chainguard Libraries, a catalog of guarded language libraries for Java built securely from source on SLSA L2 infrastructure.

March 25, 2025

Cloudelligent attained Amazon Web Services (AWS) DevOps Competency status.

March 25, 2025

Platform9 formally launched the Platform9 Partner Program.

March 24, 2025

Cosmonic announced the launch of Cosmonic Control, a control plane for managing distributed applications across any cloud, any Kubernetes, any edge, or on premise and self-hosted deployment.

March 20, 2025

Oracle announced the general availability of Oracle Exadata Database Service on Exascale Infrastructure on Oracle Database@Azure(link sends e-mail).

March 20, 2025

Perforce Software announced its acquisition of Snowtrack.

March 19, 2025

Mirantis and Gcore announced an agreement to facilitate the deployment of artificial intelligence (AI) workloads.

March 19, 2025

Amplitude announced the rollout of Session Replay Everywhere.

March 18, 2025

Oracle announced the availability of Java 24, the latest version of the programming language and development platform. Java 24 (Oracle JDK 24) delivers thousands of improvements to help developers maximize productivity and drive innovation. In addition, enhancements to the platform's performance, stability, and security help organizations accelerate their business growth ...