{"id":33654,"date":"2021-11-29T14:21:42","date_gmt":"2021-11-29T11:21:42","guid":{"rendered":"https:\/\/www.instinctools.com\/?p=33654"},"modified":"2025-04-01T17:28:45","modified_gmt":"2025-04-01T14:28:45","slug":"devsecops-integrating-security-into-devops","status":"publish","type":"post","link":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/","title":{"rendered":"DevSecOps: How to Integrate Security into DevOps"},"content":{"rendered":"\n<p>With data shaping the business landscape today more than ever before, security issues are at the forefront of everything a business does. Being ignorant about the risks of system vulnerability is detrimental no matter which industry you&#8217;re working in, but especially when you&#8217;re dealing with large amounts of consumer data. Financial, healthcare, and many other organizations are required to undergo obligatory security certification processes to prove they are compliant with all the necessary industry standards and regulations.&nbsp;<\/p>\n\n\n\n<p>However, security checks are often considered a bottleneck to deployment because they typically happen at the end of the delivery lifecycle or even after release. These checks are often manual; detecting issues means unplanned work for dev, test, and ops teams, causing delays and frustration.<\/p>\n\n\n\n<p>Fortunately, there\u2019s a way to make security cheaper and, at the same time, avoid time-consuming processes and hindering system development. The solution is DevSecOps. It aims to achieve a secure SDLC and a CI\/CD pipeline all the way through from start to finish by shifting security \u201cleft\u201d to the earliest stages of the project so that the reliability of your system is no longer an area of concern.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-devsecops-vs-devops-a-fresh-look-at-the-security-problem-or-the-same-thing-with-another-name\">DevSecOps vs DevOps: a fresh look at the security problem or the same thing with another name?<\/h2>\n\n\n\n<p>There are two opinions on the term DevSecOps and its place in <a href=\"https:\/\/www.instinctools.com\/devops\/\" target=\"_blank\" rel=\"noreferrer noopener\">DevOps<\/a>.The first one is that to include security in the software development lifecycle from the very beginning, we need an explicit call to action. Many people take the \u201cDevOps\u201d label too literally and think that it encompasses only development and operations. Hence, creating \u201cDevSecOps\u201d looks like a good opportunity to highlight the importance of the security role.&nbsp;&nbsp;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>Good symbols, labels, and stories change the world. The pithiness of \u201cDevOps\u201d drove mass adoption and actual improvement far more than the \u201cAgile System Administration\u201d movement that preceded it. DevSecOps is fine.<\/em><\/p>\n<cite>\u2014 Nigel Kersten, Field CTO, Puppet&nbsp;&nbsp; <\/cite><\/blockquote>\n\n\n\n<p>The second view is that DevSecOps shouldn\u2019t exist as a separate label because security is an integral part of DevOps already.&nbsp;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p><em>If we keep putting every responsibility people should do in the name, we\u2019ll run out of room for the hashtag. \u201cDevSecOps\u201d is dumb.<\/em> <em>#DevSecITSMTestAutomation\u00ad\u00adMonitoringObservability\u00ad\u00ad\u00adPeopleFinanceMarketingQAOps<\/em>.<\/p><cite> \u2014  Michael Stahnke, Director of Engineering, Puppet <\/cite><\/blockquote>\n\n\n\n<p>Sometimes the idea of shifting security to the left may go as far as contradicting SecDevOps vs. DevSecOps. Perhaps you\u2019re thinking: \u201cWhat?! Are you kidding me?\u201d No, we aren\u2019t actually. Anyway, let\u2019s not juggle the words and just agree with Bill, not Gates, but Shakespeare, \u201c&#8230;that which we call a rose by any other name would smell as sweet.\u201d The real issue to solve here is how to deal with the silos between security and DevOps teams? Because perhaps, only in a parallel universe could engineers and developers be okay with waiting for 48 hours while the security team runs their tests. So, then what are the middle ground solutions that DevSecOps practices can offer?&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-fighting-against-the-deadly-waterfall-why-devsecops-is-a-savior\">Fighting against the deadly waterfall: why DevSecOps is a savior<\/h2>\n\n\n\n<p>With a traditional development method, such as the waterfall model, you usually can\u2019t go back to the previous steps to modify a project. Security testing is tucked at the end of the SDLC.&nbsp;<\/p>\n\n\n\n<p>But, what are the consequences of such an approach? Significant security problems are detected only at the last stage of software development. Fixing them is painful for the team, and costly for the business owners as it results in delayed delivery. To deal with this problem, the agile methodology was invented. It allows businesses to minimize risk when adding new functionalities. And with an iterative method, it\u2019s easier to be aware of security during the whole development process because you can go back to the previous stage and quickly fix a bug, monitor cost overruns, or change requirements earlier. With such an approach, you minimize the risk of a small mistake turning into a snowball that cripples the whole project, as it happened with <a href=\"https:\/\/www.businessinsider.com\/solarwinds-hack-explained-government-agencies-cyber-security-2020-12\" target=\"_blank\" rel=\"noreferrer noopener\">SolarWinds<\/a>. The company reported that up to 18,000 of its clients installed insecure updates and became vulnerable to hackers. Considering SolarWinds has many high-profile customers, such as agencies in the US government and Fortune 500 companies, the situation was quite critical for the organization and incredibly beneficial for its competitors.&nbsp;<\/p>\n\n\n\n<p>Outcomes of integrating security into DevOps in the long term:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Accelerating deployment frequency<\/strong>. Even if initially it doesn\u2019t seem like that, the more you learn how to interact with security throughout the entire SDLC, the more frequent your deployments to production become. The case of NIAID proves that DevSecOps practices such as IaC (infrastructure-as-code) and automated testing are helpful in shortening the lead time to deliver software and patch critical defects. But as usual, when you\u2019re changing how you work, things get worse before they get better. Early stages of integration are troublesome as security practices are introduced into stages where they weren\u2019t before. Delivery speed takes a hit, too, and that\u2019s frustrating for all involved. After all, who is happy about deployment time being increased by a third? These problems eventually go away as teams collaborate more smoothly to embed security in the delivery cycle, refine their processes, and see the positive outputs of their work.\u00a0<\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-cta-blog-block-cta cta-blog\"><span class=\"draw draw_color-right draw_undefined\"><\/span><span class=\"draw draw_color-left draw_gray\"><\/span><div class=\"cta-blog__wrap\"><div class=\"cta-blog__left\" style=\"max-width:367px\"><p class=\"cta-blog__title\">Do you need expert&#8217;s advice on how to implement DevSecOps into your SDCL?<\/p><p class=\"cta-blog__desc\"><\/p><\/div><div class=\"button button_undefined button_bg-gray cta-blog__btn\"><a href=\"https:\/\/www.instinctools.com\/contact-us\/\" class=\"\" target=\"_self\" rel=\"noopener\">Let&#8217;s talk<\/a><\/div><\/div><div class=\"cta-blog__form form_light\"><\/div><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Decreasing time to remediate critical vulnerabilities<\/strong> thanks to DevSecOps automated security testing. Meanwhile, without DevOps or DevSecOps integrated into an organization\u2019s development lifecycle, error fixing is manual or, at most, only semi-automated.<\/li>\n\n\n\n<li><strong>Easier risk mitigation and flaw prevention<\/strong>. You are more likely to stop a known-vulnerable code being pushed to production by giving this responsibility not to a centralized security team but to a delivery team. Thus, you make the process faster by removing a bureaucratic constituent and improve decision-making by relying on people from the delivery team who use their knowledge of both the technology and the business to do what is best for the company and the customer. When responsibility for security is shared across delivery teams, rather than siloed within one team, security issues are caught earlier \u2014 there are more eyes looking for potential security threats. It costs much more to fix a bug found during regular maintenance than to fix one identified during the design.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/the-benefits-of-devsecops-1024x683.png\" alt=\"DevSecOps integration\" class=\"wp-image-33663\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-building-a-devsecops-pipeline-within-a-sdlc-theory-and-reality-nbsp\">Building a DevSecOps pipeline within a SDLC: theory and reality&nbsp;<\/h2>\n\n\n\n<p>Efficient security implementation into the DevOps pipeline is a tricky task. According to the <a href=\"https:\/\/learn.gitlab.com\/c\/2021-devsecops-report?x=u5RjB_\" target=\"_blank\" rel=\"noreferrer noopener\">GitLab global survey<\/a> results, 72% of 4,300 respondents described their security level as good or strong. Simultaneously, in almost a third of organizations (30.73%), only the security team is in charge of security. So, organizational silos are still a relevant problem.<\/p>\n\n\n\n<p>There are two options for creating a DevOps security pipeline:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using a traditional DevOps pipeline with security checking tools implemented at every stage: Plan \u2013 Code&amp;Build \u2013 Test \u2013 Release \u2013 Deploy \u2013 Operate&amp;Monitor.<\/li>\n\n\n\n<li>Building a DevSecOps pipeline: Threat modeling \u2013 Scan \u2013 Analyze \u2013 Remediate \u2013 Monitor.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p>In theory, it\u2019s easier to create a pipeline with integrated security when you are only starting the project rather than implementing security checks into the existing DevOps pipeline as security becomes a matter of routine from the beginning. But let\u2019s face the reality, the thing is that barely anyone truly cares about security before the preproduction stage.<\/p>\n\n\n\n<p>According to the <a href=\"https:\/\/www.sonatype.com\/hubfs\/SON_Survey2018_final.pdf?utm_campaign=2018%20DevSecOps%20Survey&amp;utm_medium=email&amp;_hsmi=62088967&amp;_hsenc=p2ANqtz-8WgDOfqSkyDj4M8Zuw3yXbACUzwPoh9nj-BJt777-C4svHSVK-TuSXLqSOqmn5gjP-3YoS5A4q9hsRMgooFvmzBFwCyWWNgedJGdfSqQxUBswm2e8&amp;utm_content=62088967&amp;utm_source=hs_automation\" target=\"_blank\" rel=\"noreferrer noopener\">Sonatype survey<\/a>, 48% of developers know security is important but don\u2019t have enough time to spend on it. It doesn\u2019t mean that it\u2019s deemed unnecessary, but a lot of other issues with a high business priority and value are waiting to be resolved. So, then how does the process work?<\/p>\n\n\n\n<p>When you start building a pipeline, you only have an idea of the final product. So you have to code and build something as fast as possible. It means, first of all, a business owner invests money in development, operational, and sales teams. DevOps security, at this stage, is only a rainbow unicorn perspective. Security implementation from the start is too costly for businesses. It requires specific tools and specialists to set them up. It\u2019s hard to find additional thousands of dollars just for security when you don\u2019t know if the product will be successful.&nbsp;<\/p>\n\n\n\n<p>The desire to turn a blind eye to security checks when you are caught in the crossfire of deadlines and frustrated employees is totally understandable. You may sleep well for many years with your software functioning just fine until one day you awaken to mind-boggling downtime instead of peace and quiet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops-pipeline-1024x683.png\" alt=\"DevSecOps integration\" class=\"wp-image-33665\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-basic-actions-you-can-take-for-devops-pipeline-security-in-any-case-nbsp\">Basic actions you can take for DevOps pipeline security in any case&nbsp;<\/h2>\n\n\n\n<p>Underlining the obvious importance of integrating security into DevOps is a kind of \u201cthanks, Captain Obvious\u201d advice. It\u2019s easy to say and hard to master. That\u2019s why our goal is to show how to integrate security into the DevOps pipeline seamlessly without creating a drag in release times and hold up the deployment cycle, and, of course, without spending a huge part of the project\u2019s budget on it.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-do-threat-modeling-and-risk-assessment\">Do threat modeling and risk assessment<\/h3>\n\n\n\n<p>This practice will help you deepen the understanding of the weak points in your DevOps security, the types and sensitivities of your assets, and how to protect them. You can do threat modeling even before you shift to DevSecOps. It\u2019ll provide you with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inventory of sensitive data<\/li>\n\n\n\n<li>List of vulnerabilities with possible migration options<\/li>\n\n\n\n<li>Summary of potential attack scenarios<\/li>\n<\/ul>\n\n\n\n<p>With threat modeling, you kill two birds with one stone: eliminate vulnerabilities in the DevSecOps pipeline and improve the security knowledge within the development and operational teams. At first sight, threat modeling may seem quite a time-consuming process that affects the speed of deployment. But it won\u2019t be an obstacle if you analyze which types of attacks are more likely to happen beforehand and choose the appropriate security checking tools.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tools-to-check-how-secure-your-sdlc-and-ci-cd-pipeline\">Tools to check how secure your SDLC and CI\/CD pipeline<\/h3>\n\n\n\n<p>Automated security testing is a key component of the successful implementation of DevSecOps. With that, the speed of deployment will be affected minimally. Specially designed tools can provide you with static, dynamic, and interactive analysis of CI\/CD pipeline\u2019s security.<\/p>\n\n\n\n<p>What are these tools specifically?<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>SAST<\/strong> (static analysis security testing) software is used for white-box security testing (the \u201cdeveloper approach\u201d) to check the security of the DevOps pipeline from the inside out during the building phase. You have access to the underlying framework, design, and implementation of the software.&nbsp;<\/li>\n\n\n\n<li><strong>DAST<\/strong> (dynamic analysis security testing) tools are needed for black-box security testing (the \u201chacker approach\u201d) to prove the system\u2019s security from external attacks outside its environment during the testing phase. In this case, you don\u2019t have access to the underlying framework, design, and implementation of the software.<\/li>\n\n\n\n<li><strong>IAST<\/strong> (interactive analysis security testing) works inside the product and analyzes code for security vulnerabilities in real-time during the QA or testing phase. It may seem like a win-win situation as far as you check security and don\u2019t add extra time to your CI\/CD pipeline. But remember that IAST tests aren\u2019t always suitable for testing a codebase or an entire application. They only check whatever is exercised by the functional test, so you can select the activity that is a part of continuous integration, and check how secure it is. The best use for IAST tools is in combination with QA tests.&nbsp;<\/li>\n<\/ol>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/sast-dast-iast-1024x683.png\" alt=\"SDLC pipeline\" class=\"wp-image-33655\"\/><\/figure>\n\n\n\n<p>Define why your company needs continuous security monitoring for DevOps because security for security\u2019s sake is a trap and a waste of time and money. First of all, specify your security priorities, choose testing tools accordingly, and decide on the phases of the DevOps pipeline where you\u2019d like to implement them.<\/p>\n\n\n\n<p>DevSecOps automated security testing is a heavy hitter in any sphere but there are three industries where security plays a crucial part: Finance, Healthcare, and Politics. The worst thing that can happen to a bank or a medical lab isn\u2019t downtime. It\u2019s data leakage. That\u2019s why bank staff may not even have permission to install unrequired programs on computers. And if a database of a medical laboratory is attacked, executives are likely to shut down the whole infrastructure until the breach is found. It means that customers won\u2019t get the results of their analyses or be able to book an appointment for 1-2 days minimum. But the risk of a hacker publishing customers\u2019 data or using it against them is much worse than negative reviews.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-finding-the-middle-ground-between-security-level-and-deployment-speed-nbsp\">Finding the middle ground between security level and deployment speed&nbsp;<\/h2>\n\n\n\n<p>By putting speed-to-market on a pedestal while ignoring other DevSecOps objectives, you risk leaving a lot of value on the table and, more importantly, you imperil your entire business by jeopardizing customers\u2019 data. Without security incorporated into your SDLC, users will suffer from repercussions caused by the unreliability of your system. That\u2019s why prioritizing security is the key to better outcomes overall.<\/p>\n\n\n\n<p>In theory, the ways of seamless integration security into the DevOps pipeline are clear and understandable. But once you start putting them into practice on your own, reality might kick in. If you have fallen into the trap of security implementation challenges, <a href=\"https:\/\/www.instinctools.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener\">*instinctools security experts<\/a> are ready to help.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-group\"><div class=\"wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow\">\n<h2 class=\"wp-block-heading schema-faq__title\" id=\"h-faq\"><strong>FAQ:<\/strong><\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1628599803316\"><strong class=\"schema-faq-question\">What is a DevSecOps pipeline?<\/strong> <p class=\"schema-faq-answer\">A DevSecOps pipeline is a set of security practices integrated into different stages of SDLC to recognize the security threats faster and earlier in the workflow and fix them straight away. The steps may differ according to your goals and the peculiarities of the industry. E.g., in healthcare, continuous security monitoring for DevOps is relevant, therefore security requirements are high and implemented from the very first stage. Meanwhile, some companies prefer completing penetration tests at the pre-production stage because security implementation at the very beginning might slow down deployment time.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1628600059241\"><strong class=\"schema-faq-question\"> How is DevSecOps implemented?<\/strong> <p class=\"schema-faq-answer\"> Integrating security into DevOps is not as easy as putting two and two together. Firstly, answer the question: \u201cWhat do you expect from a secure SDLC and CI\/CD pipeline?\u201d Solutions will vary depending on the answer. You may build a DevSecOps pipeline from scratch or implement security into your existing DevOps pipeline. In both cases, you\u2019ll need to unite dev, sec, and ops teams\u2019 expertise and use specific tools for security checks.<\/p> <\/div> <\/div>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>With data shaping the business landscape today more than ever before, security issues are at the forefront of everything a business does. Being ignorant about the risks of system vulnerability is detrimental no matter which industry you&#8217;re working in, but especially when you&#8217;re dealing with large amounts of consumer data. Financial, healthcare, and many other [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":33659,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"cta":"","footnotes":""},"categories":[361],"products_posts":[],"consulting_posts":[],"industry_posts":[],"engagement_model_posts":[],"class_list":["post-33654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devops-services"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.5 (Yoast SEO v24.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DevSecOps: Integrating Security into DevOps<\/title>\n<meta name=\"description\" content=\"Learn the theory &amp; practice of DevSecOps implementation with *instinctools to support the reliability of your product!\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DevSecOps: How to Integrate Security into DevOps\" \/>\n<meta property=\"og:description\" content=\"Learn the theory &amp; practice of DevSecOps implementation with *instinctools to support the reliability of your product!\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/\" \/>\n<meta property=\"og:site_name\" content=\"*instinctools\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-29T11:21:42+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-01T14:28:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops_-integrating-security-into-devops-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"kostyn.gricuk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"kostyn.gricuk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DevSecOps: Integrating Security into DevOps","description":"Learn the theory & practice of DevSecOps implementation with *instinctools to support the reliability of your product!","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/","og_locale":"en_US","og_type":"article","og_title":"DevSecOps: How to Integrate Security into DevOps","og_description":"Learn the theory & practice of DevSecOps implementation with *instinctools to support the reliability of your product!","og_url":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/","og_site_name":"*instinctools","article_published_time":"2021-11-29T11:21:42+00:00","article_modified_time":"2025-04-01T14:28:45+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops_-integrating-security-into-devops-1.png","type":"image\/png"}],"author":"kostyn.gricuk","twitter_card":"summary_large_image","twitter_misc":{"Written by":"kostyn.gricuk","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/","url":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/","name":"DevSecOps: Integrating Security into DevOps","isPartOf":{"@id":"https:\/\/www.instinctools.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#primaryimage"},"image":{"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#primaryimage"},"thumbnailUrl":"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops_-integrating-security-into-devops.png","datePublished":"2021-11-29T11:21:42+00:00","dateModified":"2025-04-01T14:28:45+00:00","author":{"@id":"https:\/\/www.instinctools.com\/#\/schema\/person\/3802820e1dea1526ce4a22d1b5ffa04b"},"description":"Learn the theory & practice of DevSecOps implementation with *instinctools to support the reliability of your product!","breadcrumb":{"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628599803316"},{"@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628600059241"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#primaryimage","url":"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops_-integrating-security-into-devops.png","contentUrl":"https:\/\/www.instinctools.com\/wp-content\/uploads\/2021\/11\/devsecops_-integrating-security-into-devops.png","width":1200,"height":800,"caption":"DevSecOps integration"},{"@type":"BreadcrumbList","@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.instinctools.com\/"},{"@type":"ListItem","position":2,"name":"DevSecOps: How to Integrate Security into DevOps"}]},{"@type":"WebSite","@id":"https:\/\/www.instinctools.com\/#website","url":"https:\/\/www.instinctools.com\/","name":"*instinctools","description":"Software development company","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.instinctools.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.instinctools.com\/#\/schema\/person\/3802820e1dea1526ce4a22d1b5ffa04b","name":"kostyn.gricuk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.instinctools.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/98bc5486e0bad3647ed79ac91a2ac01e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/98bc5486e0bad3647ed79ac91a2ac01e?s=96&d=mm&r=g","caption":"kostyn.gricuk"}},{"@type":"Question","@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628599803316","position":1,"url":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628599803316","name":"What is a DevSecOps pipeline?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"A DevSecOps pipeline is a set of security practices integrated into different stages of SDLC to recognize the security threats faster and earlier in the workflow and fix them straight away. The steps may differ according to your goals and the peculiarities of the industry. E.g., in healthcare, continuous security monitoring for DevOps is relevant, therefore security requirements are high and implemented from the very first stage. Meanwhile, some companies prefer completing penetration tests at the pre-production stage because security implementation at the very beginning might slow down deployment time.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628600059241","position":2,"url":"https:\/\/www.instinctools.com\/blog\/devsecops-integrating-security-into-devops\/#faq-question-1628600059241","name":"How is DevSecOps implemented?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":" Integrating security into DevOps is not as easy as putting two and two together. Firstly, answer the question: \u201cWhat do you expect from a secure SDLC and CI\/CD pipeline?\u201d Solutions will vary depending on the answer. You may build a DevSecOps pipeline from scratch or implement security into your existing DevOps pipeline. In both cases, you\u2019ll need to unite dev, sec, and ops teams\u2019 expertise and use specific tools for security checks.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/posts\/33654","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/comments?post=33654"}],"version-history":[{"count":4,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/posts\/33654\/revisions"}],"predecessor-version":[{"id":101452,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/posts\/33654\/revisions\/101452"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/media\/33659"}],"wp:attachment":[{"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/media?parent=33654"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/categories?post=33654"},{"taxonomy":"products_posts","embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/products_posts?post=33654"},{"taxonomy":"consulting_posts","embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/consulting_posts?post=33654"},{"taxonomy":"industry_posts","embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/industry_posts?post=33654"},{"taxonomy":"engagement_model_posts","embeddable":true,"href":"https:\/\/www.instinctools.com\/wp-json\/wp\/v2\/engagement_model_posts?post=33654"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}