当前位置:网站首页>Five key technologies to improve the devsecops framework
Five key technologies to improve the devsecops framework
2022-04-23 05:16:00 【Fried broad beans eat bouncing beans】
Markets and Markets A study of Show , The global DevOps Our market size ranges from 2017 Year of 29 Billion dollars to 2023 Year of 103.1 Billion dollars , Compound annual growth rate for the forecast period (CAGR) by 24.7%. People are right. DevOps More and more interested in , because DevOps It can not only compress the software delivery cycle , It can also improve the speed and quality of delivery .
Verified Market Research Also forecast ,2019 In the world DevSecOps The market value is 21.8 Billion dollars , Expect to 2027 The years will reach 171.6 Billion dollars , from 2020 Year to 2027 The compound annual growth rate in is 30.76%.
IT In the community , use DevOps There are more and more methods , Many organizations recognize DevSecOps The advantages of . seeing the name of a thing one thinks of its function , It means that the DevOps The safety of the method . During the whole development process , Flowers are keeping 、 The time to maintain development security will be reduced . The security code is to promote DevOps An important part of .
DevSecOps My important goal is : Integrate security protection into the whole life cycle of software development . This goal will be accomplished by the security team and the operation team . This article will describe how to implement DevSecOps Method , And how the whole process from continuous integration to deployment can be successfully automated .
1. The team needs to understand DevSecOps New culture of
DevSecOps The team consists of three teams : The development team 、 Operation and maintenance team and security team .DevSecOps The team's goal is to enhance security protocols at the application and infrastructure levels .
Modern development best practices force companies to develop 、 The O & M and security teams are integrated into one DevSecOps Under the umbrella , By integrating security with the move left policy , Build faster at 、 Post code .
It's through frequent communication 、 Participate in 、 Collaboration and team coordination to reduce the burden , Build trust and authorize the deployment process .
2. stay DevSecOps Using agile development in
DevSecOps It cannot replace Agile Methodology . It's a compliment to agility , But it cannot replace the process from rapid development to product delivery .DevSecOps The agile approach in helps to be faster 、 More frequent product releases deliver code .
Agile methods cover software testing 、 Quality assurance and production support , and DevSecOps Provides tools to facilitate agile adaptation .DevSecOps At an early stage, emphasis has been placed on security testing , So as to improve the quality of software .DevSecOps It is regarded as an integral part of continuous integration and continuous delivery of software .
3. Adopt automated testing
DevSecOps A combination of DevOps And automated testing . Automated testing helps keep DevOps The connection of the model . It increases the delivery speed in the pipeline 、 The quality has been improved . It also provides a platform for software release and subsequent error detection .
Cyber attacks are intensifying in all walks of life ,DevSecOps It also plays a key role in dealing with cyber attacks . Automated testing methods provide a comprehensive security testing strategy , Ensure the security of enterprise critical applications . Make this part of the release cycle , It can effectively deal with early common vulnerabilities and patches . therefore , It starts with an application or infrastructure that plays the role of an attacker , In this way, such loopholes can be overcome .
4. 24 / 7 continuous monitoring and expansion
7*24 Our 24 / 7 continuous monitoring is DevSecOps Basic requirements . This process includes various continuous monitoring tools , It can ensure the intelligent operation of the safety system . So that we can better track 、 Audit and fully understand security .
Besides , When maintaining large data centers , Continuous monitoring and expansion helps to expand IT Automated processes for infrastructure , Avoid waste of resources .
5. Guarantee CI-CD Safety of pipelines
In recent years ,DevSecOps The adoption of has helped many enterprises in charge of products 、 The product manager 、 Development 、 Testing and CloudOps And other areas to assume security responsibility and ownership . Problems include large gaps 、 The sudden resignation of executives and their failure to meet consumer needs . To solve these problems , Enterprise emphasis ,DevSecOps Need a joint security team 、 partners , To develop CI-CD Safety automation scheme in pipeline .
Besides , Many teams also follow agile development processes , among ,DevSecOps Play the role of safety audit and penetration test .
DevSecOps Designers and continuous CI-CD Delivery pipeline integration , Ensure products ( Software ) Security of delivery . This allows the company to follow a predictable time and budget , Quick response to security incidents .
版权声明
本文为[Fried broad beans eat bouncing beans]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204230510215868.html
边栏推荐
- At pgconf Asia Chinese technology forum, listen to Tencent cloud experts' in-depth understanding of database technology
- 机器学习---线性回归
- Streamexecutionenvironment of Flink source code
- Solution of how to log in with mobile phone verification code in wireless network
- API slow interface analysis
- Qingdao agile tour, coming!
- Get the number of days between dates, get the Chinese date, get the date of the next Monday of the date, get the working day, get the rest day
- MySQL external connection, internal connection, self connection, natural connection, cross connection
- Chapter II project scope management of information system project manager summary
- 无线网怎么用手机验证码登录解决方案
猜你喜欢
云计算与云原生 — OpenShift 的架构设计
Discussion on flow restriction
MySQL slow query
One month countdown, pgconf What are the highlights of the latest outlook of asia2021 Asian Conference?
[2021] Spatio-Temporal Graph Contrastive Learning
[2022 ICLR] Pyramid: low complexity pyramid attention for long range spatiotemporal sequence modeling and prediction
开源规则引擎——ice:致力于解决灵活繁复的硬编码问题
Servlet3 0 + event driven for high performance long polling
MFC实现资源单独Dll实现
Redis persistence
随机推荐
The WebService interface writes and publishes calls to the WebService interface (2)
MySQL foreign key constraint
MySQL realizes row to column SQL
The applet calls the function of scanning QR code and jumps to the path specified by QR code
The WebService interface writes and publishes calls to the WebService interface (I)
Interview summary
[2021] Spatio-Temporal Graph Contrastive Learning
Redis lost key and bigkey
API slow interface analysis
One month countdown, pgconf What are the highlights of the latest outlook of asia2021 Asian Conference?
Basic theory of Flink
什么是指令周期,机器周期,和时钟周期?
MySQL uses or to query SQL, and SQL execution is very slow
A trinomial expression that causes a null pointer
2022/4/22
JS engine loop mechanism: synchronous, asynchronous, event loop
何时适合进行自动化测试?(下)
Harmonious dormitory (linear DP / interval DP)
MySQL external connection, internal connection, self connection, natural connection, cross connection
Installing kuberneters using kubedm