Check Point® Software Technologies Ltd. has been recognized as a leader in The Forrester Wave™: Zero Trust Platform Providers, Q3 2023 report.
It's no shock that many organizations have adopted modern software development processes and are leveraging cloud platforms. Some of these companies are already incorporating security into their software development lifecycle (SDLC), while others see it as a mountain they have yet to scale.
A new report from observability data platform provider Mezmo and Enterprise Strategy Group (ESG) shows that the current adoption of DevSecOps is low but it's poised for future growth. Based on a survey of 200 DevOps and IT/information security professionals, only 22% of organizations have a formal DevSecOps strategy, but 62% are evaluating use cases or have a plan to implement it.
DevSecOps is set to gain market traction as it accelerates detecting and responding to attacks in an organization's infrastructure. Most organizations leveraging DevSecOps report improvements in incident detection (95%) and response (96%) efforts. If developers can quickly get accurate information on coding issues that need to be fixed within their workflows, they can efficiently remediate security issues. Of those who've implemented DevSecOps, 84% believe getting developers the right data and tools is the key to success.
Roadblocks to DevSecOps Success
According to the survey, many participants who have not yet transitioned to DevSecOps responded that they anticipated the biggest challenges would be creating a collaborative culture and leveraging security best practices. However, those who have adopted DevSecOps revealed that data capture and analysis are the top obstacles.
As organizations increase the speed and volume of releases to serve more customers, they collect huge amounts of data. Organizations report capturing hundreds of terabytes (32%) and even petabytes (6%) of data per month.
Capturing, processing, and storing this amount of data is costly, which is why it's no surprise that most organizations (69%) don't capture specific data sources. This is a problem if there's an incident and the organization has incomplete data for a comprehensive analysis and quick response. Not to mention this scale of data is time-consuming to analyze, especially if you don't have the right tools in place to parse and route it. An average of 17.5 person-hours is the time it takes to triage and understand security incidents—an amount that 82% of companies would like to reduce.
Observability Data Drives Efficiency
To move fast and build secure applications, organizations need solutions that help them fully harness the value of their data. They must choose the right tools that optimize speed and efficiency and work for multiple data consumers, including developers, ITOps, and security. Leveraging observability data can help drive efficiency by providing insight for better troubleshooting, debugging, and incident response.
Many organizations (91%) use more than one tool to get the most value from their data. This makes it hard for multiple teams to access the data they need to do their jobs. Not having a "single source of truth" (55%) is the greatest challenge holding teams back.
As the report reveals, DevSecOps can be a game-changer for organizations. To overcome current obstacles, a successful strategy involves incorporating security tools and processes into development so that developers can build and deploy secure applications without being slowed down.
Industry News
Red Hat and Oracle announced the expansion of their alliance to offer customers a greater choice in deploying applications on Oracle Cloud Infrastructure (OCI). As part of the expanded collaboration, Red Hat OpenShift, the industry’s leading hybrid cloud application platform powered by Kubernetes for architecting, building, and deploying cloud-native applications, will be supported and certified to run on OCI.
Harness announced the availability of Gitness™, a freely available, fully open source Git platform that brings a new era of collaboration, speed, security, and intelligence to software development.
Oracle announced new application development capabilities to enable developers to rapidly build and deploy applications on Oracle Cloud Infrastructure (OCI).
Sonar announced zero-configuration, automatic analysis for programming languages C and C++ within SonarCloud.
DataStax announced a new JSON API for Astra DB – the database-as-a-service built on the open source Apache Cassandra® – delivering on one of the most highly requested user features, and providing a seamless experience for Javascript developers building AI applications.
Mirantis launched Lens AppIQ, available directly in Lens Desktop and as (Software as a Service) SaaS.
Buildkite announced the company has entered into a definitive agreement to acquire Packagecloud, a cloud-based software package management platform, in an all stock deal.
CrowdStrike has agreed to acquire Bionic, a provider of Application Security Posture Management (ASPM).
Perforce Software announces BlazeMeter's Test Data Pro, the latest addition to its continuous testing platform.
CloudBees announced a new cloud native DevSecOps platform that places platform engineers and developer experience front and center.
Akuity announced a new open source tool, Kargo, to implement change promotions across many application life cycle stages using GitOps principles.
Check Point® Software Technologies Ltd. announced that it has been recognized on Newsweek’s inaugural list of the World’s Most Trustworthy Companies 2023.
CloudBees announced significant performance and scalability breakthroughs for Jenkins® with new updates to its CloudBees Continuous Integration (CI) software.