1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/devsecops-will-help-security-and-developers-play-nice/
6/15/2017 3:02:21 PM
DevSecOps will help security and developers play nice
DevSecOps Report,DevOps Security Report,Application Security Report,DevOps Security Tools
/Security-Teams-and-Developers-Must-Get-Along-App-Developer-Magazine_gd4jd5gn.jpg
App Developer Magazine
DevSecOps will help security and developers play nice

Security

DevSecOps will help security and developers play nice


Thursday, June 15, 2017

Richard Harris Richard Harris

Veracode finds we really need DevSecOps after it releases new study that finds that security and development teams must work together.

Veracode, a security software company acquired by CA Technologies, has announced the results of a study examining the relationships between application developers and security teams.

The study, conducted in conjunction with Enterprise Strategy Group (ESG), shows that despite the pervasive belief that security and development teams have conflicting priorities, initiatives such as creating DevOps environments and focusing on product innovation have the two teams aligned toward a common goal of creating secure software. In fact, according to the research, 58 percent of survey respondents stated their organization is taking a collaborative approach to securing applications.

Growing Need for DevSecOps


The research aims to determine security and development professionals' views of application security and software development trends. Among respondents reporting their organization currently uses application security solutions like static application security testing, 43 percent report their organization does so because including application security in the development process is more efficient than reactively patching production systems.

Interestingly, 45 percent of respondents whose organization has adopted formal DevOps principles and best practices indicate DevOps makes the software development team's job easier, and only eight percent feel adding application security into the development process would slow down a DevOps environment. This is contrary to the common perception that a focus on security will slow down software development.

"Software continues to be the major driver of innovation and economic growth. Eliminating perception that there is friction between security and development is a priority for IT professionals," said Pete Chestna, director of developer engagement, Veracode. "The positive perception of how security and DevOps can align, as indicated by this research, shows that development teams can and should consider security an integral part of their process."

This development could not come at a better time for businesses, as attacks leveraging software vulnerabilities are increasingly common and damaging. The WannaCry ransomware attack is the most recent example, exploiting a vulnerability in an older version of the Microsoft Windows operating system. While Microsoft had issued a patch for the vulnerability, thousands of organizations had not implemented the fix and became infected by WannaCry.

The research also indicates showed that nearly 70 percent of respondents plan to increase Application Security investments in the next 12 to 24 months. This increased investment further validates the growing importance of Application Security in the development process.

DevOps Influencing Technology Requirements


The research points to the need for application security to become an integrated part of the DevOps process - the combination increasingly known as DevSecOps - and that this need is both recognized and accepted. The data also highlights the technology requirements necessary to make DevSecOps a reality. Tool complexity and the inability to integrate application security into the DevOps workflow are major obstacles to organizations deploying these tools effectively. In fact, the ability to integrate static software testing and software lifecycle tools (42 percent) and the ability to integrate dynamic software testing and software lifecycle tools (34 percent) into the application development and DevOps processes was the most cited consideration when evaluating static and dynamic application security testing products and services respectively.

"Contemporary application development methodologies such as DevOps foster communication and collaboration between the application development, operations and security teams with the goal of identifying and fixing vulnerabilities as early as possible to increase efficiency and enhance security," said Doug Cahill, senior analyst at ESG. "The increased adoption of DevOps combined with the eagerness to integrate and automate security testing throughout the entire software lifecycle indicates a shift towards DevSecOps, which means thinking of secure code as an element of creating quality code."





Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


What can you build with ChatGPT in 48 hours
What can you build with ChatGPT in 48 hours Friday, April 3, 2026




Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes
Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes Tuesday, March 31, 2026


Accelerating corporate ai investment returns
Accelerating corporate ai investment returns Monday, March 30, 2026


Enviromates tech startup launches global participation platform
Enviromates tech startup launches global participation platform Friday, March 27, 2026


Private Repository Secures the AI-driven Development Boom
Private Repository Secures the AI-driven Development Boom Friday, March 27, 2026


UK Fintech Platform Enviromates Connects Projects Brands and Consumers
UK Fintech Platform Enviromates Connects Projects Brands and Consumers Thursday, March 26, 2026


Env Zero and CloudQuery Announce Merger
Env Zero and CloudQuery Announce Merger Thursday, March 26, 2026


How Industrial AI Is Transforming Operations in 2026
How Industrial AI Is Transforming Operations in 2026 Wednesday, March 25, 2026


AI generated work from managers is damaging trust among employees
AI generated work from managers is damaging trust among employees Wednesday, March 25, 2026


Foresight Secures $25M to Bridge Infrastructure Execution Gap
Foresight Secures $25M to Bridge Infrastructure Execution Gap Tuesday, March 24, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>