Question

In: Computer Science

SecDevOps - Over the past 5–10 years there has been a shift in product and service...

SecDevOps - Over the past 5–10 years there has been a shift in product and service development to use more agile methodologies to provide more continuous delivery.

QUESTION 1:

Considering the article below: Comment on at least two (2) security concerns with a DevOps model and how these concerns can be alleviated with a strong implementation of SecDevOps considerations.

-----------------------------------------------

Agility has become an unavoidable necessity in a fast-moving technology environment, but achieving it can be a challenge for organizations and their development teams. The DevOps philosophy provides a road map; following it is not always as easy.

Even more crucial than the need to transform the development process is the need to protect against ever more sophisticated threats and attacks. But some organizations are finding that agility and security can go hand in hand. SecDevOps is an approach to development that puts security right at the heart of DevOps by making it integral to the development cycle.

SecDevOps: Bridging the Gap Between Security and Agility

According to CIO Insight, organizations such as the endowment-based Dana Foundation have found the SecDevOps approach to be an effective way to bring security into DevOps. The result is faster development cycles and more robust security.

The Dana Foundation is primarily engaged in two fields: web activities related to grant management and publishing and outreach operations, including an annual brain awareness week. James Rutt, the company’s chief information officer (CIO), told CIO Insight that the organization was primarily concerned with “code quality and code security,” with a particular focus on protecting against known code vulnerabilities listed in the Open Web Application Security Project (OWASP) Top 10, such as cross-site scripting and forgery.

The SecDevOps approach helped the company speed up its development process while reducing code vulnerabilities by 40 to 50 percent. This impressive performance shows why and how security and agility can form a perfect partnership.

Building Security Into the DevOps Cycle

Experts have been preaching for years that security needs to be built in, not bolted on after the fact. But the combination of conventional, prolonged development cycles with a fluid security environment has made built-in security almost impossible to achieve. After all, if new versions of a software package were only released every couple of years, the security environment would be radically transformed between two successive versions. Developers had no choice but to bolt on new security features.

In the world of DevOps, the software development cycle has become dramatically faster — so much faster, in fact, that code development can now match the pace of new security challenges. Developers are no longer focused on fixing existing code to handle new security threats. Instead, they are constantly building new code as part of the DevOps cycle, which means that new security features can be built in as part of the overall development process. This is exactly what the security community has been preaching all along.

SecDevOps is not a magic trick, but a natural, organic way to approach new security needs in the context of ongoing code development. This is very good news for organizations that are shifting into the DevOps era.

Solutions

Expert Solution

DevOps ,as the name suggests,is the collaboration of development and operations team for faster implementation of software development.Although the DevOPS methodology is increasingly used in day to day businesses,there remains few security challenges to be addressed:

1) Neglecting Security challenges:Development team often neglects the security challenges as their main focus is on speedy delivery.They find the security challenges as blockers in their pathway which may slow down their delivery.As a result of which,it always leave behind unresolved vulnerabilites which exposes the code to malfunctions in future.

2) Risk associated with the tools being used in DevOps: DevOps usually relies on some open source tools which carries associated risk with them ,for example,container is a packaging platform for applications which can run on any platform and carry forward vulnerabilties which are difficult to be scanned.

Adopting Secured DevOps can eliminate the threats posed by the above mentioned two challenges.DevSecOps is a methodology where everyone involved in sofware development lifecycle takes responsibilty of security issues in their code.Security and other teams can be trained in new skills to be applied in DevSecOps.Security policies can be introduced like configuration management,code reviews for vulnerabilties,firewalls etc.Also,automating tools and security processes can help security operations to keep up the pace with development operations which will overcome the negligence induced due to the pressure of keeping up the speed.


Related Solutions

The company has been growing steadily over the past 5 years, and the financials and future...
The company has been growing steadily over the past 5 years, and the financials and future prospects look good. Your CEO has asked you to run the numbers. After doing some digging into the business, you have gathered information on the following: • The estimated purchase price for the equipment required to move the operation in-house would be $750,000. Additional net working capital to support production (in the form of cash used in Inventory, AR net of AP) would be...
The company has been growing steadily over the past 5 years, and the financials and future...
The company has been growing steadily over the past 5 years, and the financials and future prospects look good. Your CEO has asked you to run the numbers. After doing some digging into the business, you have gathered information on the following: The estimated purchase price for the equipment required to move the operation in-house would be $750,000. Additional net working capital to support production (in the form of cash used in Inventory, AR net of AP) would be needed...
The company has been growing steadily over the past 5 years, and the financials and future...
The company has been growing steadily over the past 5 years, and the financials and future prospects look good. Your CEO has asked you to run the numbers. After doing some digging into the business, you have gathered information on the following: The estimated purchase price for the equipment required to move the operation in-house would be $750,000. Additional net working capital to support production (in the form of cash used in Inventory, AR net of AP) would be needed...
Over the past 5 years Truman Incorporated has been maintaining its total debt ratio in the...
Over the past 5 years Truman Incorporated has been maintaining its total debt ratio in the range of 60%-70%. (Support your answers with a framework of any capital structure theories we discussed in class): a) Give at least three reasons why Truman might be using debt financing, instead of using equity financing only? b) Truman Inc. has been maintaining debt levels in a range of 60%-70% over the past 5 years. Why is Truman not using equity only? Alternatively, why...
QuickE Lube has been monitoring its customer service times over the past 5 days. Each day...
QuickE Lube has been monitoring its customer service times over the past 5 days. Each day they took a sample of 10 customers and recorded the actual service times for those customers. The table below shows the sample mean and sample range for each of the 5 past samples. Excel access Sample 1 2 3 4 5 Mean 22 19 19.4 22.0 21.8 Range 4.4 5.1 3.2 2.9 1.0 What is the three-sigma upper control limits (UCL Only)the company should...
There has been a great deal of discussion in the news over the past few years...
There has been a great deal of discussion in the news over the past few years about raising the minimum wage. Some cities and states have increased minimum wages in their locality above the federal minimum wage, which has brought demands for the federal minimum wage to be increased. Some argue that the federal minimum wage should be increased to $10.10 while others argue for the $15 level. From a microeconomics perspective, who is hurt and who is helped by...
Over the past few years there has been a lot of media coverage on the cost...
Over the past few years there has been a lot of media coverage on the cost of EpiPens. EpiPens, a form of epinephrine is a front line drug for the treatment of anaphylaxis (Drugs, 2018). The company that makes EpiPen, Mylan was the subject of much controversy and media attention. There were lawsuits filed against the company due to the high cost of EpiPens. One brand name EpiPen that contains two auto-injectors cost an estimated $650-700 if bought with cash....
Over the past 35 years, there has been a marked increase in both the flow and...
Over the past 35 years, there has been a marked increase in both the flow and stock of FDI in the world economy. Discuss why FDI has grown more rapidly than world trade and world output. Site examples when possible.
HARLAND CORP has been in existence for 45 years. Over the past, 6 years the stock...
HARLAND CORP has been in existence for 45 years. Over the past, 6 years the stock price has stagnated and remained between $22.15 and $22.82. The CEO, who started the company, believes that the stock price needs to be higher, and the best way to do that is to pay a dividend to increase the demand for the stock. The company has never paid a dividend in their history. The CEO needs to determine what type of dividend policy to...
HARLAND CORP has been in existence for 45 years. Over the past, 6 years the stock...
HARLAND CORP has been in existence for 45 years. Over the past, 6 years the stock price has stagnated and remained between $22.15 and $22.82. The CEO, who started the company, believes that the stock price needs to be higher, and the best way to do that is to pay a dividend to increase the demand for the stock. The company has never paid a dividend in their history. The CEO needs to determine what type of dividend policy to...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT