Summary
This chapter provided an introduction to integrating security into DevOps, discussing the concept of DevSecOps. We've discussed the importance of security in enterprise architecture and how this is also driving security in enterprise DevOps. We've learned about the main security risks that are involved in adopting DevOps, and we had a closer look at securing containers as one of the most used technologies in DevOps practices. With that, we defined some critical starting points for adopting DevSecOps.
In the final section, we learned how to collect and assess risks from business goals and business attributes, introducing commonly used security controls frameworks such as the frameworks by CIS. With some examples, we explored the various steps that an architect needs to take to have a security standard that can also be applied to DevOps.
In the next chapter, we will explore the architecture of DevSecOps in more detail, before we start integrating security policies...