People practices
Your people are the most important asset you have, which is why their inclusion in your DevSecOps strategy is paramount. Doing
DevSecOps will challenge the way many of your teams work, setting aside a traditional approach for a security-first outlook. For a successful transition, you need to get buy-in from the people who will be impacted. That means a top-down approach, where everyone is on the same page and encouraged to be involved from the start. Here are a few specific practices to focus on.
Collaboration
Traditionally, developers, operations, and security professionals are stuck in their silos, each seeing the other as problematic. Working this way means security and engineering teams can’t scale with the speed needed, and efforts will be duplicated because of poor communication. DevSecOps is all about bringing these teams together for a more collaborative approach.
One way of keeping a dialogue going is by installing a security champion in each team. These people are there to emphasise the importance of security, liaise with other teams about security issues, and make decisions about how to address them, fostering collaboration across the organisation.
Skills
Invest in your people so they have the awareness, skills, and expert knowledge they need to help your DevSecOps strategy soar. That means good quality training rooted in your security goals for all existing staff and new hires. It can be carried out by in-house security specialists or external expert trainers.
Culture
DevSecOps does away with a single security team – the kind that ends up being a blocker and, as a result, is maligned and misunderstood by the rest of the business. Instead, it puts the onus on everyone at each stage of the SDLC to ensure security is front and centre when decisions get made.