Ali Yazdani

DevSecOps culture

Stop thinking about security tools. DevSecOps is a cultural transformation, not a technology problem.

DevSecOps culture
#1about 2 minutes

The evolution from traditional security to DevSecOps

Traditional security testing at the end of the pipeline creates friction and downtime, leading to the rise of DevSecOps to integrate security with development and operations.

#2about 2 minutes

DevSecOps is a culture, not just a set of tools

Implementing DevSecOps successfully requires focusing on its three core pillars—people, process and tools, and governance—rather than just adopting new technologies.

#3about 3 minutes

The people pillar and establishing shared responsibility

Breaking down traditional silos between development, security, and operations is crucial for creating a shared responsibility model where everyone contributes to security.

#4about 2 minutes

The technology pillar and automating security tests

Technology enables DevSecOps by automating repeatable security tests like secret scanning, SAST, and software composition analysis within the CI/CD pipeline.

#5about 2 minutes

The governance pillar for tracking progress and compliance

Governance provides structure through policy as code and visualization, helping teams track security posture, manage expectations, and ensure compliance.

#6about 2 minutes

Overcoming common DevSecOps implementation challenges

Successfully implementing DevSecOps involves navigating cultural resistance, ensuring seamless tool integration, and meeting complex compliance requirements like ISO 27001 and SOC 2.

#7about 2 minutes

Reducing costs by shifting security left

Shifting security practices earlier in the development lifecycle, such as with pre-commit hooks, significantly reduces the cost and effort required to find and fix vulnerabilities.

#8about 1 minute

Communication is key to a successful DevSecOps journey

Clear and consistent communication with developers about the purpose and implementation of security measures is the most critical factor in reducing friction and ensuring adoption.

Related jobs
Jobs that call for the skills explored in this talk.

d

Saby Company
Delebio, Italy

Junior

job ad

Saby Company
Delebio, Italy

Intermediate

Featured Partners

Related Articles

View all articles
CH
Chris Heilmann
Dev Digest 131 - AI'm not sure about OSS
News and ArticlesRust and Typescript are rising stars in programming languages 2024 survey, the State of CSS 2024 survey is open and here is what's new in ECMAScript.In security news, a Microsoft update bricks Linux dual-boot systems, they patched a ...
Dev Digest 131 - AI'm not sure about OSS
CH
Chris Heilmann
Dev Digest 110 - XY marks the spotty security
This time we give you a collection of links about the XZ backdoor, solve the last CODE100 puzzle, announce the next round of it, let you play with colours and explain why Lava lamps are great to keep the web secure.News and ArticlesThe big piece of n...
Dev Digest 110 - XY marks the spotty security
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
Hello there! This is the 2nd "out of the can" edition of 3 as I am on vacation in Greece eating lovely things on the beach. So, fewer news, but lots of great resources. Many around the topic of security. Enjoy! News and ArticlesGoogle Pixel phones t...
Dev Digest 138 - Are you secure about this?

From learning to earning

Jobs that call for the skills explored in this talk.

DevSecOps

DevSecOps

Devsecops

40-60K
DevOps
Docker
Jenkins
Openshift
+3
DevSecOps

DevSecOps

Robert Half

DevOps
Docker
Kubernetes
DevSecOps

DevSecOps

Azertuim IT

Remote
Senior
DevOps
DevOps Engineer

DevOps Engineer

Socium - Teams Done Differently

56K
Linux
DevOps
Docker
Terraform
+1