{"id":12493,"date":"2021-08-19T17:54:27","date_gmt":"2021-08-19T17:54:27","guid":{"rendered":"http:\/\/ismiletechnologies.com\/?p=12493"},"modified":"2021-10-07T00:47:42","modified_gmt":"2021-10-06T19:17:42","slug":"devsecops-best-practices","status":"publish","type":"post","link":"https:\/\/ismiletechnologies.com\/en_us\/devsecops\/devsecops-best-practices\/","title":{"rendered":"DevsecOps best practices"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>The best practices for implementing Dev&nbsp;Sec Ops in the organization involves<\/strong>&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><strong>People training and management<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The weakest link in the entire Dev&nbsp;Sec ops is the human element because with humans the chances of errors&nbsp;arise. Raising awareness and training your team for the&nbsp;DevSec&nbsp;Ops is the most important part of the entire set of Dev&nbsp;Sec Ops practices. Your&nbsp;DevSec&nbsp;Ops must embrace the DevOps mindset and should ensure be trained to help with QA and tests, building of the continuous&nbsp;environments (CI), ensure that security doesn\u2019t act as blockers&nbsp;in the development process.&nbsp;The training must be aligned with the goals of the organization and the standards of security that the&nbsp;organizations&nbsp;want&nbsp;to achieve.&nbsp;Continuous&nbsp;auditing of the team skills and regular workshops can facilitate learning in the&nbsp;DevSec&nbsp;Ops team. The teams must be empowered to make security decisions and should work on mitigation strategies with the AppSec team&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\"><li><strong>Integration of security in the process<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In the agile&nbsp;DevSec&nbsp;Ops environment, the integration of security measures must start from the beginning of the&nbsp;DevSec&nbsp;Ops pipeline. The shift left strategy is apt for&nbsp;DevSec&nbsp;Ops security It helps in reducing the cost&nbsp;of production&nbsp;and release by finding out errors and testing them in the early stages of software lifecycle development.&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\"><li><strong>Implementing continuous security<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Proper security tooling and testing is one of the most important practice in&nbsp;DevSec&nbsp;Ops.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are two types of security testing employed&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SAST (Static Analysis Security Testing)<\/strong>&nbsp;\u2013 This involves&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Detecting where coding best practices have been violated&nbsp;<\/li><li>Identifying the security vulnerabilities in the code you posses and those that have been imported from libraries&nbsp;<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DAST (Dynamic Analysis Security Testing)-<\/strong>&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It involves examining the application externally when it is running&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"4\"><li><strong>Proactive incident management<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Response to any incident should be proactive so that workflows do not get disrupted. For this action plans and security scripts must be formed in advance and the security measures developed should consistent and repeatable. There should be proper documentation of each incident and the security measures being applied. This tribal knowledge should be shared across the entire&nbsp;DevSec&nbsp;Ops team.&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"5\"><li><strong>Using orchestration software, metadata and version control<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">In the automated environment, the only thing that is constant is change. You must ensure that you have an immutable versioning in place to track the changes. Every change needs a version and should be converted to metadata so that your operations team can track that change.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using orchestration software, you are able to deploy your infrastructure in a repeatable manner. It also generates&nbsp;a&nbsp;large&nbsp;amount&nbsp;of metadata for any task. Orchestration software combined with versioning can act as a great information source for your operations team.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Orchestration and automation&nbsp;help&nbsp;in making auditing easier by use of metadata generated&nbsp;<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"6\"><li><strong>Auditing and scanning<\/strong>&nbsp;<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Auditing at the application level enables businesses to access their risk posture. Pre-deployment and post-deployment auditing help\u00a0in providing the requirements to the\u00a0DevSecops\u00a0team early in the production process and help them assess how much the deployment has been successful, respectively\u00a0\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other best practices include&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Checking all coding standards against the most updated and new security recommendations&nbsp;<\/li><li>Minimizing&nbsp;the attack surface by restraining from running any script, applications and others that are not mandatory for core applications&nbsp;<\/li><li>Utilizing&nbsp;those security features that are native to the OS&nbsp;( kernel&nbsp;security modules while working with Linux)&nbsp;<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The best practices for implementing Dev&nbsp;Sec Ops in the organization involves&nbsp; People training and management&nbsp; The weakest link in the entire Dev&nbsp;Sec ops is the human element because with humans the chances of errors&nbsp;arise. Raising awareness and training your team for the&nbsp;DevSec&nbsp;Ops is the most important part of the entire set of Dev&nbsp;Sec Ops practices. [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":13146,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[],"class_list":["post-12493","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devsecops"],"_links":{"self":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/12493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/comments?post=12493"}],"version-history":[{"count":2,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/12493\/revisions"}],"predecessor-version":[{"id":18391,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/12493\/revisions\/18391"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media\/13146"}],"wp:attachment":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media?parent=12493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/categories?post=12493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/tags?post=12493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}