Understanding DevSecOps in the planning phase
We live in a world where many organizations value their software more than their physical infrastructure. Industry giants such as Amazon, Netflix, Airbnb, and Uber have transformed their sectors with innovative software platforms, changing how we read, watch movies, travel, and commute. For these organizations and most modern companies, their key operations do not depend on the physical buildings they own, but on the software, they have developed to offer their services to users.
Despite the critical role that software systems play, many organizations only focus on functionality and stability when planning them. Security often becomes a secondary concern that is addressed much later after the development work has started. As we discussed in Chapter 2, this approach does not scale well in a DevOps workflow. This late consideration of security can be partly attributed to development and operations teams...