Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

12/20/2016
03:20 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Application Security Still Slows Developer Work

Cooperation among DevOps teams might be growing, but security testing still seen as a road block to continuous delivery.

The cooperative nature of DevOps software delivery has done a lot to reduce friction between operations staff and developers, but looping security into the greater process still remains a challenge. According to a survey out today from Veracode, over half of developers report that security causes delays in the development process.

Conducted among more than 350 developers worldwide, the survey took a look at developer perceptions of application security and the impact that security testing has on their professional lives. As things stand, 52% of developers and 54.3% of DevOps managers report that security testing slows down development and threatens deadlines. This was the biggest challenge they reported about their work. Closely following that challenge is the difficulty of legacy application security processes adding complexity and slowing time-to-market, which was reported as a top challenge by 46% of developers and 44% of DevOps managers.

This is a huge business problem considering the intense heat turned up by the business on developers and DevOps to shorten development timelines. In a report earlier this year, Forrester found that 88% of developers feel increased pressure to produce more frequent releases. A little more than half of developers surveyed for that report now release at least monthly and 77% say that the business is also demanding software with more complex requirements and capabilities.

While there's clearly a lot of work to offer a more seamless mode of injecting security into the development process, the Veracode survey shows that a statistically significant ratio of organizations are moving in the right direction.

"Although it’s a best practice to address security early in the software development lifecycle, the shift towards continuous delivery and DevOps is providing more opportunities to integrate security throughout the entire lifecycle," the survey report explained. The study shows that the majority of organizations are seeking to incorporate security earlier in the software development lifecycle, with only about 16% relying inserting it after the programming stage. One of the best signs is that almost one in three organizations say they're involving security during requirements or design phases of development.

According to analysts with Forrester, that's huge not just for the security of the software but also the value an organization gets out of it.  

"Developers who regularly collaborate with their security colleagues on software development tasks get significant value from their efforts, which produce major and tangible business and technical benefit," Forrester experts write.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Christian Bryant
50%
50%
Christian Bryant,
User Rank: Ninja
12/22/2016 | 2:41:05 AM
Common Ground
I hear this complaint all the time, have even been the one complaining in the past.  Perhaps the answer is in refining the existing processes of development and operations to make security an integral function.  If you've been hired as a programmer for a killer app that uses some new killer lib, you'd never say "Gee, learning how to program against this new library is really slowing my time to market down!"  That's your job, to learn, to experiment, and to do it in a timely fashion.  So should secure programming be, and so should security in general.  It is as integral to software projects and release infrastructures as learning how to program is.  DevOps especially should be an innovator of finding common ground for security to be embraced on by both coders and security engineers.  You know what a really killer app is?  An unhackable app; uncrackable and well coded.  A secure app that protects the user's data while still being useful.  That kind of app doesn't just appear, it needs to be intentionally created, and lovingly created.  These rifts and complaints about security bringing down the dev process isn't going to produce that killer app. 
rickkaun
50%
50%
rickkaun,
User Rank: Apprentice
12/21/2016 | 11:01:27 AM
Application Security Still Slows Developer Work
Wow! Is everyone ever missing the point here!  When cybersecurity testing is included in functional testing or QA then these types of surveys go away.  Cybersecurity is a core component of any code or it should be.  Failing to see this and recognize its importance just shows how ignorant the development community still is.  None of these survey respondents seemed to complain about functionality testing or QA cycles in their development plans did they?  
7 Truths About BEC Scams
Ericka Chickowski, Contributing Writer,  6/13/2019
DNS Firewalls Could Prevent Billions in Losses to Cybercrime
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/13/2019
10 Notable Security Acquisitions of 2019 (So Far)
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12865
PUBLISHED: 2019-06-17
In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2017-10720
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi name. This application is installed o...
CVE-2017-10721
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car ga...
CVE-2017-10722
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack overflow if more than 26 characters are passed to it as the Wi-Fi password. This application is install...
CVE-2017-10723
PUBLISHED: 2019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruption issue and execute remote code on the device. This device acts as an Endoscope camera that allows it...