The Top Tools to Support DevSecOps - Part 5
May 31, 2018

DEVOPSdigest asked experts from across the IT industry — from analysts and consultants to users and the top vendors — for their opinions on the top tools to support DevSecOps. Part 5, the last installment, offers some final thoughts about "tools" that are not necessarily technology.

Start with The Top Tools to Support DevSecOps - Part 1

Start with The Top Tools to Support DevSecOps - Part 2

Start with The Top Tools to Support DevSecOps - Part 3

Start with The Top Tools to Support DevSecOps - Part 4

THE RIGHT PEOPLE

Investment in quality people is the single best investment in tooling an organization can make to support DevSecOps. From the executives that need to make the command decisions that weigh risk versus business goal, to the developers writing the applications, to the security teams that are trying to implement "Security at the Speed of Code." Without an investment in quality people, you end up with a hamstrung environment where even the most modest security practices are overlooked in favor of doing what is "easy" or "nimble." The "fail fast" mantra of DevOps should not be applied to a security program wherein the consumer bears all the weight of an unfortunate event.
John Stauffacher
Director - Offensive Security, Trace3

DEVSECOPS CULTURE

Your most important tool needed for DevSecOps isn't a actually tool, or even a process: it's culture. You can influence culture — having support from the top is vital — but you can't prescribe it. Instead, you'll need to build a multi-disciplinary team of enthusiasts: not just security experts, but auditors, docs, ops and testing people and beyond. You'll help them through failures and successes, and then encourage them to spread the word across your organization: they become your most important tool for success.
Mike Bursell
Chief Security Architect, Red Hat

DevSecOps is a culture and hence implementing it is mainly a mindset change. The tools will only drive the change, but the most important part is to go from having separate teams with siloed responsibilities in the software development lifecycle to having teams that are fully responsible for implementing, testing and running their code in production.
Isa Vilacides
Quality Engineering Manager, CloudBees

COLLABORATION

Probably the most critical tool when trying to bring security colleagues along on your DevOps transformation is a whiteboard and a stack of post-it notes. Fundamentally the collaboration will rise or fall based on how well people from different teams and with different skills work together. Getting everyone physically together upfront, taking people away from how things work day-to-day, and holding a well organized and well run set of workshops is a great first step on your DevOps journey.
Gareth Rushgrove
Product Manager, Docker

EMPATHY

Simply putting developers and security people into the same cube farm and telling them to work together won't work, of course — and will likely be counterproductive. Collaboration is key — but even the best collaboration tool in the world won't facilitate cooperation among people who feel they are in an adversarial relationship with each other. Just as with DevOps itself, therefore, the most important tool for DevSecOps is empathy — the ability to put yourself into the other person's shoes and see the problem space from their point of view. Once the team has sufficient empathy for each other, collaboration tooling is important to be sure — but tools don't make high-performance teams.
Jason Bloomberg
President, Intellyx

Share this

Industry News

February 27, 2020

Datadog announced an integration with Nessus from Tenable.

February 27, 2020

Talend announced the Winter ‘20 release of Talend Data Fabric.

February 27, 2020

Alcide announced that the Alcide Kubernetes Security Platform now supports compliance scans for PCI and GDPR, enabling DevOps to deliver regulatory compliance checks rapidly and seamlessly alongside Alcide’s leading Kubernetes security capabilities.

February 26, 2020

Perforce Software released a free tool for organizations considering open source software - OpenLogic Stack Builder.

February 26, 2020

Applause announced a new partnership with Infosys to provide broader end-to-end digital experience testing services to clients.

February 26, 2020

RapidMiner announced the release of its platform enhancement, RapidMiner 9.6. This update prioritizes people – not technology – at the center of the enterprise AI journey, providing new, unique experiences to empower users of varying backgrounds and abilities.

February 25, 2020

JFrog announced the availability of the "JFrog Platform," a hybrid, multi-cloud, universal DevOps platform.

February 25, 2020

Nureva added new agile canvas templates to Span Workspace, including a heat map developed by Jeff Sutherland, the co-creator of Scrum and founder of Scrum Inc. and Scrum@Scale.

February 25, 2020

Agiloft announced the addition of its new Agiloft AI Engine, complete with prebuilt AI Capabilities for contract management and an open AI integration that allows customers to incorporate custom-built AI tools into the no-code platform.

February 24, 2020

Cloudify announced that its latest product update - Cloudify version 5 - features an Environment as a Service component, designed to achieve consistent delivery and management of hybrid-cloud services and network infrastructures across CI/CD pipelines - at scale.

February 24, 2020

Checkmarx announced new enhancements to its Software Security Platform to empower more seamless implementation and automation of application security testing (AST) in modern development and DevOps environments.

February 24, 2020

Rapid7 and Snyk announced a strategic partnership to deliver end-to-end application security to organizations developing cloud native applications.

February 20, 2020

The American Council for Technology and Industry Advisory Council (ACT-IAC), the premier public-private partnership dedicated to advancing government through the application of information technology, officially announced the release of the DevOps Primer.

It was produced through a collaborative, volunteer effort by a working group from government and industry, hosted by the ACT-IAC Emerging Technology Community of Interest (COI).

February 20, 2020

DLT Solutions, a subsidiary of Tech Data, launched the Secure Software Factory (SSF), a framework that provides the U.S. public sector with consistent development and deployment of high-quality, scalable, resilient and secure software throughout an application’s lifecycle.

February 20, 2020

Netography announced the general availability of the company’s Security Operations Platform.