Understanding platform security – how to build a secure yet flexible and open system
The platform isn’t the totality of an organization’s security posture; rather, it’s part of an equation. When assessing how to integrate cybersecurity or DevSecOps into the platform, a balance must be stuck. Pushing security to the left helps to reduce the efforts the platform team needs to exert, but a clear and defined scope helps everyone to understand their part of the security story.
Breaking down the problem into consumable chunks
Security and flexibility can also feel like two words that stand diametrically opposed. Good security is inherently inflexible; however, it’s possible and necessary for an IDP’s success to balance both. How do we achieve this? Step one is scope security.
The first part of scoping is to understand what the minimum level of security is that’s required. Obviously, we should always do more than the bare minimum,...