DEV Community

Discussion on: What is DevSecOps? A Comprehensive Look at DevSecOps

Collapse
 
leon_sparrow_08eb1d05272e profile image
Leon Sparrow

SecDevOps is better than DevSecOps.
Shift your security left!

Collapse
 
smakintel profile image
Kavashgar

DevSecOps shift to center is always better. Responsibility of Dev as well as ops when it comes to post deployment

Collapse
 
leon_sparrow_08eb1d05272e profile image
Leon Sparrow

SecDevOps integrates security from the start, as in security lead not delivery lead.
It defines the mindset, dealing with security 1st and shifting left (eg. Threat modelling, sast linters). If your talking about dependency and dast patching post deployment that should be in your cost model and processes anyway.
Its about applying the 3 pillars properly.

Education
Secure by design
Automation

To drive security, shifting left where possible but more importantly adopting the right culture to build safely.