It’s time for engineering teams to own DevSecOps
Summary
This trend, combined with the broader introduction of software-as-a-service (SaaS), has led to quick, iterative development cycles in which changes are made to software weekly, daily, and even hourly. Although the vulnerability was patched before threat actors could cause major damage, it exposed how much is still unknown about the many pieces of software that are part of a wide range of systems. And although the SolarWinds attack affected supply chains, it points to a similar visibility issue: too many companies don’t fully understand the scope of their software operations or how their code impacts their overall threat profile, providing opportunity for cyber criminals to target back-end infrastructure tools and other unmonitored vulnerabilities. Because of their current incentive structure, many engineering teams focus on facilitating product availability and quality, but security also directly impacts these business metrics. Read more from this Security Think Tank series • It is imperative to make our colleagues and customers know that when we talk DevSecOps, we are facing a multiphase challenge that starts at the very beginning of DevOps, and one that never ends.