Neglected Step Child: Security in DevOps
Summary
Providing the agility that business have long awaited, these new technologies also introduce inherent security implications that cannot be ignored at a time when the enterprise attack surface continues to grow wider. This confirms the hype surrounding these emerging technologies, which are meant to simplify the life of application developers and DevOps teams. For example, one of the key capabilities of these technologies – the ability to start up and power down almost instantly – has created a significant security challenge for enterprises and expanded their attack surface dramatically. There are several steps that both information security and DevOps teams can take to minimize their attack surface in the context of these emerging technologies and development practices: 1. However, security practitioners have to apply a more holistic approach and incorporate DevOps environments and processes into their cyber risk assessments.