Walk in Developer Shoes
Some of the biggest impediments to baking security work into DevOps comes down to security pros who have never worked in software development and who don't understand how a sprint team delivers software.
"You always hear complaints from infosec that training developers doesn’t work, but the biggest challenge is in educating information security staff about developer processes so they can learn to speak the same language," Chubirka says. "I actually struggle more with those 'old-school' colleagues than with developers."
Understanding the unique challenges of securing code earlier in the development process requires security professionals to actually know what that process looks like. Rather than writing off developers as disinterested in security, infosec pros need to become better partners and find ways to work closer with them. For example, Chubirka suggests potentially embedding security champions into developer teams who will "advocate for 'security as a feature.'"
Image Source: Adobe Stock