DevOps and SecOps - Best Friends Forever
June 04, 2018

Mukul Kumar
Cavirin Systems

There is no better approach than starting from a clean slate, but in business reality this is not always possible. It's more complex than just merging the two different schools of thought. DevOps and security traditionally have been siloed functions and security is often seen as a policing function by DevOps team members. However, more mature business leaders are trying to bridge the gap between the two functions to achieve business excellence. This theme was evident from our recent survey where 39% of respondents cited that DevOps and development teams care greatly about their cybersecurity posture, showing that the silo between security/IT and development teams is diminishing.

It's important to understand that when every business is relying on digital technologies to make a difference, the only thing that differentiates one business from another is new capabilities/functionalities provided to their customers. The organizations which provide these functionalities first will clearly lead the market and increase value to their businesses. Yes, speed is the obvious common denominator here, but with speed comes various complexities and risk. Businesses that find the right balance between merging both schools of thought, with agile methodology, are getting ahead in the game.

The execution speed required to achieve this new business reality can only be achieved through the adoption of the cloud at various levels. The DevOps teams have already been aggressively leveraging a DevOps integrated fabric for IAAS and PAAS. This maturity in cloud deployment will slowly start moving towards an immutable model of deployment and then toward FAAS (Function-as-a-Service) which will provide a more integrated and robust framework.

With the adoption of these new models, organizations can no longer rely on old techniques and models which were more serial and reactive in their approach. Today, with DevOps leveraging the cloud for agility, security models need to be integrated into the development process and need to be part of mandatory control checks before production release.

Organizations have started realizing that incorporation of security from the design phase will increase the ROI of their DevOps program and will be more successful in creating lasting business value. Relying on a once-per-quarter pen testing-only approach solves only point-in-time issues and, as a result, becomes costlier. Instead, there must be continuous security oversight and integration to fix security flaws before they become a problem and exploited in the wild. The matured and unique combination of DevOps and security is predictive, integrated "DevSecOps."

Here are 3 suggested approaches to enable continuous security and DevOps when leveraging the cloud:

All infrastructure deployment for IAAS, PAAS, FAAS (Function-as a-Service) in software

All the building blocks of cloud infrastructure from IAAS, PAAS to FAAS should be controlled in code by DevOps. The goal here is to make the environment more reliable, predictable and mutable by replacing the whole system in no time if required by simply changing the code. There will be no guess work involved because all the "recipes" will keep the information about the current and past versions intact. This will not only enforce the logic of version controls but will also provide the much-required capability of rollback to a stable version of code when something goes sideways. This whole approach to the infrastructure will simplify the old back-up and restoration operation model.

API driven security architecture and "Say NO to complex access rules"

Instead of point-in-time assessments by using security tools and leveraging monolithic architecture techniques, security should instead be integrated into code development through APIs.

With the current lack of security talent, there is a possibility that the security team will not be able gain full visibility and detailed information into the compute environment if it's not automated and integrated into a robust CI/CD pipeline. All the security tool vendors will have to provide a standard RESTful API integration with good documentation for the DevOps team. The DevOps team should use this method to build integration for continuous assessment and automated remediation once issues/exploits are detected.

Create a well-defined development environment

TEST, TEST and TEST. We cannot emphasize the importance of investing time and energy for setting up your test environment. Even the best of developers make mistakes – and who doesn't, we are human after all – but a solid test environment gives one the ability to fix issues before they get released into production. Apart from the feature, functionality, speed and business logic, we must pay special attention to issues but not be limited to security vulnerabilities, security best practices and industry guidelines from NIST, API exposure, performance etc.

The cloud is ever-changing but along with that comes an ever-changing set of "tools" to secure it. Thanks to DevOps and SecOps, organizations should no longer be left in the dust as it relates to their approach to security. With an agile cloud available to each organization, it's important to use the right set of tools for the job. Thankfully, security and DevOps have a life-long friendship to look forward to, as together, they can heavily help get the job done right.

Mukul Kumar is CISO and VP of Cybersecurity Practice at Cavirin Systems
Share this

Industry News

December 03, 2024

SmartBear announced its acquisition of QMetry, provider of an AI-enabled digital quality platform designed to scale software quality.

December 03, 2024

Red Hat signed a strategic collaboration agreement (SCA) with Amazon Web Services (AWS) to scale availability of Red Hat open source solutions in AWS Marketplace, building upon the two companies’ long-standing relationship.

December 03, 2024

CloudZero announced the launch of CloudZero Intelligence — an AI system powering CloudZero Advisor, a free, publicly available tool that uses conversational AI to help businesses accurately predict and optimize the cost of cloud infrastructure.

December 03, 2024

Opsera has been accepted into the Amazon Web Services (AWS) Independent Software Vendor (ISV) Accelerate Program, a co-sell program for AWS Partners that provides software solutions that run on or integrate with AWS.

December 02, 2024

Spectro Cloud is a launch partner for the new Amazon EKS Hybrid Nodes feature debuting at AWS re:Invent 2024.

December 02, 2024

Couchbase unveiled Capella AI Services to help enterprises address the growing data challenges of AI development and deployment and streamline how they build secure agentic AI applications at scale.

December 02, 2024

Veracode announced innovations to help developers build secure-by-design software, and security teams reduce risk across their code-to-cloud ecosystem.

December 02, 2024

Traefik Labs unveiled the Traefik AI Gateway, a centralized cloud-native egress gateway for managing and securing internal applications with external AI services like Large Language Models (LLMs).

December 02, 2024

Generally available to all customers today, Sumo Logic Mo Copilot, an AI Copilot for DevSecOps, will empower the entire team and drastically reduce response times for critical applications.

December 02, 2024

iTMethods announced a strategic partnership with CircleCI, a continuous integration and delivery (CI/CD) platform. Together, they will deliver a seamless, end-to-end solution for optimizing software development and delivery processes.

November 26, 2024

Check Point® Software Technologies Ltd. has been recognized as a Leader and Fast Mover in the latest GigaOm Radar Report for Cloud-Native Application Protection Platforms (CNAPPs).

November 26, 2024

Spectro Cloud, provider of the award-winning Palette Edge™ Kubernetes management platform, announced a new integrated edge in a box solution featuring the Hewlett Packard Enterprise (HPE) ProLiant DL145 Gen11 server to help organizations deploy, secure, and manage demanding applications for diverse edge locations.

November 26, 2024

Red Hat announced the availability of Red Hat JBoss Enterprise Application Platform (JBoss EAP) 8 on Microsoft Azure.

November 26, 2024

Launchable by CloudBees is now available on AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS).