TU Darmstadt / ULB / TUbiblio

SecDevOps: Is It a Marketing Buzzword?

Mohan, Vaishnavi and Othmane, Lotfi Ben (2016):
SecDevOps: Is It a Marketing Buzzword?
In: Proc. of the 11th International Conference on Availability, Reliability and Security (ARES), [Conference or Workshop Item]

Abstract

DevOps is changing the way organizations develop and deploy applications and service customers. Many organizations want to apply DevOps, but they are concerned by the security aspects of the produced software. This has triggered the creation of the terms SecDevOps and DevSecOps. These terms refer to incorporating security practices in a DevOps environment by promoting the collaboration between the development teams, the operations teams, and the security teams. This paper surveys the literature from academia and industry to identify the main aspects of this trend. The main aspects that we found are: definition, security best practices, compliance, process automation, tools for SecDevOps, software configuration, team collaboration, availability of activity data and information secrecy. Although the number of relevant publications is low, we believe that the terms are not buzzwords; they imply important challenges that the security and software communities shall address to help organizations develop secure software while applying DevOps processes.

Item Type: Conference or Workshop Item
Erschienen: 2016
Creators: Mohan, Vaishnavi and Othmane, Lotfi Ben
Title: SecDevOps: Is It a Marketing Buzzword?
Language: German
Abstract:

DevOps is changing the way organizations develop and deploy applications and service customers. Many organizations want to apply DevOps, but they are concerned by the security aspects of the produced software. This has triggered the creation of the terms SecDevOps and DevSecOps. These terms refer to incorporating security practices in a DevOps environment by promoting the collaboration between the development teams, the operations teams, and the security teams. This paper surveys the literature from academia and industry to identify the main aspects of this trend. The main aspects that we found are: definition, security best practices, compliance, process automation, tools for SecDevOps, software configuration, team collaboration, availability of activity data and information secrecy. Although the number of relevant publications is low, we believe that the terms are not buzzwords; they imply important challenges that the security and software communities shall address to help organizations develop secure software while applying DevOps processes.

Title of Book: Proc. of the 11th International Conference on Availability, Reliability and Security (ARES)
Uncontrolled Keywords: Secure Software Engineering Group;Security;SecDevOps, DevSecOps, agile development
Divisions: LOEWE > LOEWE-Zentren > CASED – Center for Advanced Security Research Darmstadt
LOEWE > LOEWE-Zentren > CRISP - Center for Research in Security and Privacy
20 Department of Computer Science > System Security Lab
LOEWE > LOEWE-Zentren
20 Department of Computer Science
LOEWE
Date Deposited: 30 Dec 2016 20:23
Identification Number: TUD-CS-2016-0166
Related URLs:
Export:
Suche nach Titel in: TUfind oder in Google

Optionen (nur für Redakteure)

View Item View Item