DevSecOps
What is DevSecOps?
It is the combination of DevOps and SecOps. This is essential in an increasingly cloud centered software development practices.
Areas of DevSecOps
- Everything in DevOps
- SecOps related to DevOps
- "Keep Security Left" i.e. Consider security in the early stages of development
- Security as Code (SaC) - on IaC
- Common Weakness Enumeration (CWE)
- Threat Modelling
- Automated Security Testing
- Incident Management
- Security Testing Methods - SAST, IAST, DAST, RAST (?)