Security requirements

Security requirements depend on the business environment, regulations, and security compliance. An organization should define a minimum expected security requirement baseline to be part of the release gate. Based on the severity and impact, the release plan may be a release conditional on the readiness of hotfixes, not released until the issue is fixed, released with mitigation protection, and so on.

To have a security requirement release baseline will also help to build consensus among stakeholders such as IT, development teams, security teams, and so on. Otherwise, it may be that business teams would like to release even though there are security defects, while the security team may not endorse the release.

It's a ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.