Chapter 11: Understanding Security in DevOps
You can't talk about the cloud, modern apps, and—for that matter—digital transformation without talking about security. A popular term is security by design. But even security by design needs to be embedded in the enterprise architecture. It also applies to the DevOps cycle: DevOps needs to have security by design. Before we can discuss this and principles such as zero-trust, we need to get a good understanding of security first and how it's impacting the DevOps practice. This chapter provides an introduction to security in DevOps.
After completing this chapter, you will have learned why it's important to include security in the enterprise architecture and how an architect can collect and assess risks, and be able to identify what specific risks are in DevOps. You will also learn about setting security controls and what the main topics are that need to be addressed in DevSecOps.
In this chapter, we&apos...