The CISO View on DevOps: New Report Highlights Approaches to Reduce Cyber Security Risk
Summary
The report is part of The CISO View industry initiative and features contributions from executives at leading organizations who are adopting DevOps methodologies and tools, including American Express Company, American Financial Group, Asian Development Bank, Carlson Wagonlit Travel, CIBC, GIC Private Limited, ING Bank, Lockheed Martin, NTT Communications, Orange Business Services, Pearson, Rockwell Automation and Starbucks. While security strategies should address privileged access and the risk of unsecured secrets and credentials, they should also closely align with DevOps culture and methods to avoid negatively impacting developer velocity and slowing the release of new services. Despite this, 73 percent of organizations surveyed for the 2018 CyberArk Global Advanced Threat Landscape report have no strategy to address privileged access security for DevOps. Evaluate the results of DevOps security programs – Test secrets management solution deployments, measure and promote improvements and educate auditors. “This CISO View report captures the experiences and recommendations of senior executives who are securely embracing DevOps workflows, ” said Marianne Budnik, CMO, CyberArk.