Security Goals and Metrics

In the previous chapter, we discussed the challenges and the business drivers for DevSecOps. In this chapter, we will discuss security goals and metrics. The adoption of DevSecOps is a continuous learning journey and takes lots of stakeholder involvement, process optimization, business priority conflict, customization of security tools, and security knowledge learning. This chapter will give you some hands-on tips, challenges, and common practices based on a functional role perspective, and will also look at GDPR as an example to explain how to do a privacy impact assessment.

We will cover the following topics in this chapter:

  • Organization goal
  • Development goal/metrics
  • QA goals/metrics
  • Operation goal/metrics

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.