Based on the SAMM, operational goals can be categorized into three functions: are issue management, environmental hardening, and operational enablement. Let's discuss some of the best practices in each function.
Operation goal/metrics
Issue management
Issue management here means how security incidents, vulnerability issues, or security breaches are handled. There should be a vulnerability process in place that involves both the DevOps and Dev team.
In an organization-level security assurance program, it's a must to define security incident and vulnerability response processes and also root cause analysis templates. NIST SP800-61 is a good reference for an organization to establish a security incident response process...