Operations

6/7/2018
04:55 PM
50%
50%

DevSecOps Gains Enterprise Traction

Enterprise adoption of DevSecOps has surged in the past year, according to a study conducted at this year's RSA Conference.

DevSecOps is a great portmanteau word, but is it a concept in wide use? According to a survey of attendees at this year's RSA Conference, it's not yet universal, but many more organizations are now embracing at least some DevSecOps principles than was the case even a year ago.

The survey, conducted by Aqua Security, asked IT security professionals attending the San Francisco conference questions about whether their organizations were using DevSecOps principles and, if so, some of the details of that use.

In all, 63% of the participants said they have a formal or informal DevSecOps team in place. According to Andy Feit, VP, go-to-market, at Aqua Security, the "informal" part is important.

"That means they don't have to have a director, but they can say that they use some DevSecOps activities," Feit says. "We talk to a lot of organizations every day, but we don't always find a person who has 'DevSecOps' on their business card."

No matter how you define the word, though, its expansion has been impressive. "Last year only 13% of a similar pool of respondents reported they had a DevSecOps team in place; less than a year later, that number has skyrocketed to 62%," Feit says.

Perhaps more important, he says, is that a healthy percentage of the individuals responding said that their organizations were committing resources to the DevSecOps effort. "Sixty perfect said they have the people and the money," he says, adding that another 10% said they have the people but not the money, while 11% said they have the money but not the people.

Asked why so many organizations feel it's important to move in the direction of DevSecOps, Feit talks about the effort to have security "shift left" in the application creation and deployment process. "When you ask why people deploy DevSecOps, applying security across the app life cycle is No. 1, and shifting security left is No. 2," he says.

The most critical factor in DevSecOps' expansion, Feit says, is the unending need for speed in getting applications in front of users. "Everyone's trying to move more quickly through the process. They don't want to get things done and then get into a wait state," he says.

Still, the embrace of DevSecOps is not universal. In response to a Twitter query on DevSecOps deployment, Twitter user @p3l was succinct: "| sed -e s/sec//" he tweeted.

Related content:

 

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
8 Security Tips to Gift Your Loved Ones For the Holidays
Steve Zurier, Freelance Writer,  12/18/2018
How to Engage Your Cyber Enemies
Guy Nizan, CEO at Intsights Cyber Intelligence,  12/18/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
[Sponsored Content] The State of Encryption and How to Improve It
[Sponsored Content] The State of Encryption and How to Improve It
Encryption and access controls are considered to be the ultimate safeguards to ensure the security and confidentiality of data, which is why they're mandated in so many compliance and regulatory standards. While the cybersecurity market boasts a wide variety of encryption technologies, many data breaches reveal that sensitive and personal data has often been left unencrypted and, therefore, vulnerable.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-16883
PUBLISHED: 2018-12-19
sssd versions from 1.13.0 to before 2.0.0 did not properly restrict access to the infopipe according to the "allowed_uids" configuration parameter. If sensitive information were stored in the user directory, this could be inadvertently disclosed to local attackers.
CVE-2018-17192
PUBLISHED: 2018-12-19
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. Mitigation: The fix to consistently apply the security headers was applied on th...
CVE-2018-17193
PUBLISHED: 2018-12-19
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sanitize the request attribute value was applied on the Apache NiFi 1.8.0 release. Users running a prior ...
CVE-2018-17194
PUBLISHED: 2018-12-19
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial request had a Content-Length value other than 0, the receiving nodes would wait for the body and even...
CVE-2018-17195
PUBLISHED: 2018-12-19
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certificate authentication, same subnet access, a...