Stage 2 – building a security testing team

In this stage, the business is getting stable and mature. The organization may set up a security testing team who is in charge of application security verification before release and continuous environment vulnerability monitoring. The development team may heavily rely on the security testing team for security defects and issues. The development team is only focused on the business's functional development, and not yet involved with the secure design or secure coding.

Dedicated security testing may start to use some security automation testing or open source monitoring tools. Developers are learning secure coding through identified security defects case by case, and still haven't adopted any formal ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.