{"id":14067,"date":"2020-09-18T16:41:48","date_gmt":"2020-09-18T19:41:48","guid":{"rendered":"https:\/\/ostec.blog\/?p=14067"},"modified":"2020-09-18T16:42:38","modified_gmt":"2020-09-18T19:42:38","slug":"devsecops-agility-security","status":"publish","type":"post","link":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/","title":{"rendered":"DevSecOps: the perfect balance between agility and security"},"content":{"rendered":"<p>Creating software and keeping it up to date is a constant and complex process, which requires intense integration between the Development (Dev) and Operation (Ops) teams. This method in which they both work together is called DevOps \u2013 a term that came up ten years ago with software engineers John Allspaw and Paul Hammond when presenting a lecture on their achievements on Flickr with the closest approximation between the development and operations team. However, with the growing demands for greater security in information systems, the term has been updated to\u00a0<b>DevSecOps<\/b>, with the inclusion of a team specialized in security in the processes.<\/p>\n<p>In this context,\u00a0<b>DevSecOps<\/b>\u00a0considers application and infrastructure security from the beginning of the development phase. This leads to the automation of security barriers that bring consistency to deliveries, without impairing the speed of work of DevOps. Therefore, you need to select the right tools to integrate security seamlessly and quickly. However, it must be kept in mind that the inclusion of security in DevOps requires the construction of cultural changes in companies, so that the result meets the expectations of the teams involved in the construction and continuity of products.<\/p>\n<h2>The evolution in the way of making software<\/h2>\n<p>In order to understand more clearly about the team connection, which is the basis of\u00a0<b>DevSecOps<\/b>, it is necessary to tell a little about the evolution of the software production methodology. In decades past, the process that prevailed was known as cascade. In it, the steps followed the following sequence: system requirements, software requirements, analysis, code design, coding, tests and finally operation.<\/p>\n<p>The model worked well, but it had negative points. One of them is the fact that there is no feedback between the stages and the teams in charge. Another flaw is that the tests were at the end of the cycle. Then, any necessary adjustments could impact the previous steps, a situation that tends to worsen deadlines and budgets. With the need for increasingly short delivery cycles, where the demand for quality always increased, the cascading methodology soon became outdated, incompatible with a world that depends more and more on technology \u2013 with increasing frequency.<\/p>\n<p>For these reasons, the development of agile methodologies to conduct software projects has become essential. Such methodologies need practices and tools totally different from those that were in use until then, deeply reordering the development and operational roles \u2013 as well as their very essence.<\/p>\n<h2>An alternative called DevOps<\/h2>\n<p>In the older methodologies, the development team was on one side looking for autonomy and working with smaller release cycles every day; on the other side, there was the operations team, with a completely different pace, in the midst of processes that demand more control and stability. As two areas are so distinct, conflicts arose whose existence was harmful to products and companies as a whole.<\/p>\n<p>Then, there were movements that encouraged the two areas to work together, collaboratively and with common goals. Thus, they would seek tools, processes and practices aimed at optimizing work, leading to more satisfactory results. They were the DevOps embryos.<\/p>\n<p>With DevOps, the development team started to have a better idea about the processes, challenges and problems faced by the operations team. The opposite also occurs. The objectives, then, become the search for ways to simplify procedures, in order to make everything more agile. In this way, issues such as integration and continuous delivery, monitoring, logs and scalability are given greater emphasis and the most effective treatment possible.<\/p>\n<p>Everything settled then? Not even. There was another area not yet involved, whose importance has grown exponentially in recent years, with its own values, practices and processes: the area of information security. Then we have the emergence of the\u00a0<b>DevSecOps<\/b>\u00a0concept.<\/p>\n<h2>Security as part of the development process<\/h2>\n<p>To integrate information security in this context, one must determine risk tolerance and conduct an analysis of risks and benefits. It is necessary to define, for example, the number of security controls for certain applications. In this context, automating repetitive tasks is critical at\u00a0<b>DevSecOps<\/b>, as manual security checks can be time-consuming and undermine effectiveness.<\/p>\n<p>The tip, then, is to keep development cycles short and frequent, as well as to integrate security measures with the least possible amount of interruption of operations. Another measure is to keep pace with innovative technologies and promote close collaboration between teams \u2013 especially those that work in isolation. Due to the complexity of the initiative, the adoption of\u00a0<b>DevSecOps<\/b>\u00a0can be followed by companies specialized in information security, such as<span class=\"apple-converted-space\">\u00a0<\/span><a href=\"https:\/\/www.ostec.com.br\/\">OSTEC<\/a>. Call us and understand which differentials we can bring to your business!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Creating software and keeping it up to date is a constant and complex process, which requires intense integration between the Development (Dev) and Operation (Ops) teams. This method in which they both work together is called DevOps \u2013 a term that came up ten years ago with software engineers John Allspaw and Paul Hammond when [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":14071,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[984,992],"tags":[],"class_list":["post-14067","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","category-learning-and-discovery"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados\" \/>\n<meta property=\"og:description\" content=\"Creating software and keeping it up to date is a constant and complex process, which requires intense integration between the Development (Dev) and Operation (Ops) teams. This method in which they both work together is called DevOps \u2013 a term that came up ten years ago with software engineers John Allspaw and Paul Hammond when [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\" \/>\n<meta property=\"og:site_name\" content=\"OSTEC | Seguran\u00e7a digital de resultados\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ostec\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-18T19:41:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-18T19:42:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"928\" \/>\n\t<meta property=\"og:image:height\" content=\"534\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Thais Souza\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@ostecsecurity\" \/>\n<meta name=\"twitter:site\" content=\"@ostecsecurity\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\"},\"author\":{\"name\":\"Thais Souza\",\"@id\":\"https:\/\/ostec.blog\/#\/schema\/person\/ca88ecd81da20ed5773cd0959c645c33\"},\"headline\":\"DevSecOps: the perfect balance between agility and security\",\"datePublished\":\"2020-09-18T19:41:48+00:00\",\"dateModified\":\"2020-09-18T19:42:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\"},\"wordCount\":772,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/ostec.blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg\",\"articleSection\":[\"General\",\"Learning and discovery\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\",\"url\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\",\"name\":\"DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados\",\"isPartOf\":{\"@id\":\"https:\/\/ostec.blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg\",\"datePublished\":\"2020-09-18T19:41:48+00:00\",\"dateModified\":\"2020-09-18T19:42:38+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage\",\"url\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg\",\"contentUrl\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg\",\"width\":928,\"height\":534},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"In\u00edcio\",\"item\":\"https:\/\/ostec.blog\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DevSecOps: the perfect balance between agility and security\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ostec.blog\/#website\",\"url\":\"https:\/\/ostec.blog\/\",\"name\":\"OSTEC | Seguran\u00e7a digital de resultados\",\"description\":\"Empresa especializada na oferta de produtos e servi\u00e7os de seguran\u00e7a digital.\",\"publisher\":{\"@id\":\"https:\/\/ostec.blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ostec.blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/ostec.blog\/#organization\",\"name\":\"OSTEC Business Security\",\"url\":\"https:\/\/ostec.blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ostec.blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2020\/11\/logo_ostec_250.png\",\"contentUrl\":\"https:\/\/ostec.blog\/wp-content\/uploads\/2020\/11\/logo_ostec_250.png\",\"width\":251,\"height\":67,\"caption\":\"OSTEC Business Security\"},\"image\":{\"@id\":\"https:\/\/ostec.blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/ostec\",\"https:\/\/x.com\/ostecsecurity\",\"https:\/\/www.instagram.com\/ostecsecurity\/\",\"https:\/\/linkedin.com\/company\/ostec-security\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/ostec.blog\/#\/schema\/person\/ca88ecd81da20ed5773cd0959c645c33\",\"name\":\"Thais Souza\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ostec.blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/400dde6458954de06efa803109767977?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/400dde6458954de06efa803109767977?s=96&d=mm&r=g\",\"caption\":\"Thais Souza\"},\"url\":\"https:\/\/ostec.blog\/en\/author\/thais-souza\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/","og_locale":"en_US","og_type":"article","og_title":"DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados","og_description":"Creating software and keeping it up to date is a constant and complex process, which requires intense integration between the Development (Dev) and Operation (Ops) teams. This method in which they both work together is called DevOps \u2013 a term that came up ten years ago with software engineers John Allspaw and Paul Hammond when [&hellip;]","og_url":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/","og_site_name":"OSTEC | Seguran\u00e7a digital de resultados","article_publisher":"https:\/\/www.facebook.com\/ostec","article_published_time":"2020-09-18T19:41:48+00:00","article_modified_time":"2020-09-18T19:42:38+00:00","og_image":[{"width":928,"height":534,"url":"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg","type":"image\/jpeg"}],"author":"Thais Souza","twitter_card":"summary_large_image","twitter_creator":"@ostecsecurity","twitter_site":"@ostecsecurity","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#article","isPartOf":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/"},"author":{"name":"Thais Souza","@id":"https:\/\/ostec.blog\/#\/schema\/person\/ca88ecd81da20ed5773cd0959c645c33"},"headline":"DevSecOps: the perfect balance between agility and security","datePublished":"2020-09-18T19:41:48+00:00","dateModified":"2020-09-18T19:42:38+00:00","mainEntityOfPage":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/"},"wordCount":772,"commentCount":0,"publisher":{"@id":"https:\/\/ostec.blog\/#organization"},"image":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage"},"thumbnailUrl":"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg","articleSection":["General","Learning and discovery"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/","url":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/","name":"DevSecOps: the perfect balance between agility and security - OSTEC | Seguran\u00e7a digital de resultados","isPartOf":{"@id":"https:\/\/ostec.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage"},"image":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage"},"thumbnailUrl":"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg","datePublished":"2020-09-18T19:41:48+00:00","dateModified":"2020-09-18T19:42:38+00:00","breadcrumb":{"@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#primaryimage","url":"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg","contentUrl":"https:\/\/ostec.blog\/wp-content\/uploads\/2019\/09\/Mulher-orientando-homem.jpg","width":928,"height":534},{"@type":"BreadcrumbList","@id":"https:\/\/ostec.blog\/en\/general\/devsecops-agility-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"In\u00edcio","item":"https:\/\/ostec.blog\/en\/"},{"@type":"ListItem","position":2,"name":"DevSecOps: the perfect balance between agility and security"}]},{"@type":"WebSite","@id":"https:\/\/ostec.blog\/#website","url":"https:\/\/ostec.blog\/","name":"OSTEC | Seguran\u00e7a digital de resultados","description":"Empresa especializada na oferta de produtos e servi\u00e7os de seguran\u00e7a digital.","publisher":{"@id":"https:\/\/ostec.blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ostec.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/ostec.blog\/#organization","name":"OSTEC Business Security","url":"https:\/\/ostec.blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ostec.blog\/#\/schema\/logo\/image\/","url":"https:\/\/ostec.blog\/wp-content\/uploads\/2020\/11\/logo_ostec_250.png","contentUrl":"https:\/\/ostec.blog\/wp-content\/uploads\/2020\/11\/logo_ostec_250.png","width":251,"height":67,"caption":"OSTEC Business Security"},"image":{"@id":"https:\/\/ostec.blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/ostec","https:\/\/x.com\/ostecsecurity","https:\/\/www.instagram.com\/ostecsecurity\/","https:\/\/linkedin.com\/company\/ostec-security"]},{"@type":"Person","@id":"https:\/\/ostec.blog\/#\/schema\/person\/ca88ecd81da20ed5773cd0959c645c33","name":"Thais Souza","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ostec.blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/400dde6458954de06efa803109767977?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/400dde6458954de06efa803109767977?s=96&d=mm&r=g","caption":"Thais Souza"},"url":"https:\/\/ostec.blog\/en\/author\/thais-souza\/"}]}},"_links":{"self":[{"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/posts\/14067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/comments?post=14067"}],"version-history":[{"count":0,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/posts\/14067\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/media\/14071"}],"wp:attachment":[{"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/media?parent=14067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/categories?post=14067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostec.blog\/en\/wp-json\/wp\/v2\/tags?post=14067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}