The guiding principles and pillars of continuous security
This section describes the guiding principles and pillars of practice that are important to support an effective continuous security strategy.
Figure 1.7 illustrates the pillars of continuous security.
Figure 1.7 – The continuous security pillars
Let’s look at them in brief:
- DevSecOps culture:
- Principle: Collaboration between development, security, and operations enhances security outcomes.
- Pillar: Promote a DevSecOps culture where security is a shared responsibility, integrated into the DevOps practices, encouraging collaboration and communication across teams.
- Security awareness and training:
- Principle: Security is a shared responsibility and requires awareness at all levels.
- Pillar: Provide regular security training and awareness programs for all team members to foster a security-conscious culture. For example, security training on topics such as Open Worldwide Application...