Sacha Labourey, Co-Founder and Chief Strategy Officer of CloudBees, the enterprise software delivery company.
While a lot of progress has been made when it comes to the adoption of best DevSecOps practices, a survey published earlier this year by the research firm Enterprise Strategy Group (ESG) found that 91% of respondents work for organizations that have experienced a software supply chain incident in the past year.
Implementing DevOps security requires time and effort, but its adoption is now in the “plateau of productivity” phase, having reached mainstream maturity, reaching more than half of its target audience, according to Gartner.
Much of that effort needs to be squarely focused on reducing the volume of vulnerabilities that might be exploited. This can be done by improving code quality before the code reaches a production environment. According to a survey of 2,037 IT and security professionals conducted by Cloud Security Alliance (CSA), over a third of respondents (38%) estimated 21% to 40% of their code contains vulnerabilities, while 19% estimated 41% to 60% of their code contains vulnerabilities. Another 13% estimated they have vulnerabilities in 61% to 80% of their code.
On average, organizations have 55.5 security vulnerabilities each day in their remediation queue. Typically, at least one is deemed critical, the CSA survey found. Overall, among these survey respondents, the average number of vulnerabilities that could be remediated is 1,025 per month, with organizations typically only able to fix 270 within a month.
An ounce of prevention is always worth more than a pound of cure, or in this case, remediation. The challenge is to integrate security at the earliest stages of the software development lifecycle. Doing so reduces the burden placed on developers, who are never going to have the time or inclination to become cybersecurity experts.
Top 10 DevSecOps Practices
Integrating security early in the software development process can reduce the burden placed on developers and improve application quality. Reducing that developer burden requires DevSecOps teams to implement 10 best practices, as follows:
• Automate security processes. Use automation tools and AI to handle repetitive security tasks such as code scanning, patch management and compliance checks. Doing so frees developers to focus on coding and innovation.
• Implement continuous security and compliance. You probably have automated software delivery processes. Security and compliance should be part of that automation or occur in parallel to ensure that security is a continuous part of the development process.
• Disconnect logic from specific tools. Define your security and compliance logic in a way that’s abstracted from the specific tools you use to perform checks. Tools come and go. Security and compliance always remain.
• Use security-as-code. Adopt a security-as-code approach, where security policies and configurations are defined in code, to allow for version control, audit trails and easy replication across environments.
• Standardize development environments. Provide standardized development environments with pre-configured security settings and tools, ensuring that all developers work with a secure baseline.
• Educate developers. Regularly train developers on the latest security threats, best practices and tools, empowering them to write secure code and recognize potential security issues.
• Implement the Principle of Least Privilege (PoLP). Ensure that developers have only the minimum levels of access necessary to perform their functions. That reduces the risk of unauthorized access or actions.
• Perform regular security and compliance audits. Conduct regular audits to assess software security and compliance. That provides developers with feedback to identify areas for improvement.
• Foster a culture of security. Promote a security-first mindset across the organization, whereby security is seen as a shared responsibility and integral to the development process.
• Use threat modeling and risk assessments. Regularly perform threat modeling and risk assessments during the software development lifecycle to identify and prioritize potential security risks, allowing developers to focus on critical issues.
The surest and simplest means of implementing these best practices is to adopt a modern continuous integration/continuous delivery (CI/CD) platform that has DevSecOps capabilities baked into it. Some organizations may attempt to extend their existing CI/CD platform, but the time, effort and cost required to extend workflows based on legacy DevOps platforms is substantial.
Even then, there is no guarantee that the approach will reduce the number of false positives generated if the CI/CD platform cannot correlate which alerts stem from the same issue. A survey conducted by Cycode of 500 CISOs, directors of applications and DevSecOps team members found “88% acknowledge that because of alert fatigue, developers are not focused on remediating critical vulnerabilities.”
Similarly, “The vast majority (85%) of CISOs acknowledge dev teams suffer from vulnerability noise and alert fatigue, which strains the relationship between security and dev teams.”
When all the costs involved are fully considered, it may be wise to transition to a modern DevSecOps platform that takes advantage of the latest advances in AI to provide better outcomes for all concerned in a way that is less costly and faster.
It’s now only a matter of time before every organization that builds software will be required to embrace best DevSecOps practices at a deeper level. The European Union (EU) has already defined requirements for securing software supply chains within the Cyber Resilience Act.
The U.S. will eventually follow suit, in light of an executive order issued by the Biden administration that requires agencies to lock down their software supply chains. The fines that might one day be levied because of a failed audit (or worse yet, an actual security breach) will make the cost of investing in DevSecOps seem comparatively trivial.
Summary
Legacy DevOps platforms were not designed to address modern application security mandates. Many organizations are now attempting to extend those platforms to meet security and compliance requirements. However, in many cases, the total cost of those efforts will be more expensive than simply acquiring a DevSecOps platform that’s designed from the ground up to build and deploy secure applications.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?







