Security guidelines and processes

After looking at the industry practices, SDL, OWASP SAMM, and ISO 27001, it's normally the CSO or CTO security office's job to define the security governance program and the security guidelines. The following table shows an overview of security guidelines. In practice, these security guidelines are templates, suggested centrally and updated in a security knowledge base for every project team to refer to. Again, guidelines won't be effective if these guidelines aren't able to be part of a developer, QA, IT, or DevOps's daily tasks. Providing tools with built-in security practices for DevOps teams is still key to the success of DevSecOps. The following table suggests some industry practices and tools that may ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.