SlideShare a Scribd company logo
2
Most read
3
Most read
4
Most read
DevSecOps
A.R.M. NIZZAD
CTO | SENIOR LECTURER | RESEARCHER | SOFTWARE ENGINEER | DIGITAL MEDIA
STRATEGIST | TECHNICAL W RITER | FREELANCER
Outline
DevOps DevSecOps Characteristics Practices
Benefits Implementation Challenges
DevOps
DevOps is a set of practices that works to automate and
integrate the processes between software development and IT
teams, so they can build, test, and release software faster and
more reliably
DevSecOps
DevSecOps is a further development
of the DevOps concept that, besides
automation, addresses the issues of
code quality and reliability assurance.
DevSecOps Characteristics
DevOps Culture Automation Measurement Sharing
DevSecOps Practices
• Threat modeling and risk assessments
• Continuous testing
• Monitoring and logging
• Security as code
• Red-Team and security drills
Benefits of
Implementing
DevSecOpsSHIFTING SECURITY
TO THE LEFT
AUTOMATING
SECURITY
VALUE
Implementing DevSecOps
Different Security implementation models have been proposed by
researchers and experts in the field of Security with respect to
DevSecOps.
• Three pillars of a DevSecOps model
• OWASP DevSecOps Maturity Model
• Deloitte’s transformational pillars in DevSecOps
Three pillars of a DevSecOps model
• Test-driven security
• Monitoring and responding to attacks
• Assessing risks and maturing security
OWASP DevSecOps Maturity Model
LEVEL 1: BASIC
UNDERSTANDING OF
SECURITY PRACTICES
LEVEL 2: ADOPTION OF
BASIC SECURITY PRACTICES
LEVEL 3: HIGH ADOPTION
OF SECURITY PRACTICES
LEVEL 4: ADVANCED
DEPLOYMENT OF SECURITY
PRACTICES AT SCALE
Deloitte’s transformational pillars in
DevSecOps
Governance
People
Technology
Process
Challenges in
implementing
DevSecOpsKEEPING UP WITH
DEVOPS
ORGANIZATIONAL
CHALLENGES
TOOLS AND
PRACTICES
DevOps is not a Goal, But a never-ending process of continual Improvement
Thank you

More Related Content

PDF
DevSecOps Implementation Journey
PDF
The State of DevSecOps
PPTX
DevSecOps : an Introduction
PDF
DevSecOps and the CI/CD Pipeline
PPTX
Introduction to DevSecOps
PDF
DevSecOps What Why and How
PDF
Practical DevSecOps Course - Part 1
DevSecOps Implementation Journey
The State of DevSecOps
DevSecOps : an Introduction
DevSecOps and the CI/CD Pipeline
Introduction to DevSecOps
DevSecOps What Why and How
Practical DevSecOps Course - Part 1

What's hot (20)

PDF
DevSecOps: What Why and How : Blackhat 2019
PPTX
DevOps to DevSecOps Journey..
PDF
2019 DevSecOps Reference Architectures
PDF
Demystifying DevSecOps
PPTX
DevSecOps
PDF
DevSecOps The Evolution of DevOps
PPTX
DEVSECOPS: Coding DevSecOps journey
PDF
DevSecOps Jenkins Pipeline -Security
PDF
DevSecOps in Baby Steps
PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
PDF
The What, Why, and How of DevSecOps
PDF
DevSecOps | DevOps Sec
PPTX
DEVSECOPS.pptx
PDF
DevSecOps - The big picture
PDF
Devops Devops Devops, at Froscon
PPTX
DevSecOps reference architectures 2018
PDF
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
PPTX
DevOps Foundation
PDF
Introduction to DevSecOps
PDF
DevSecOps: Taking a DevOps Approach to Security
DevSecOps: What Why and How : Blackhat 2019
DevOps to DevSecOps Journey..
2019 DevSecOps Reference Architectures
Demystifying DevSecOps
DevSecOps
DevSecOps The Evolution of DevOps
DEVSECOPS: Coding DevSecOps journey
DevSecOps Jenkins Pipeline -Security
DevSecOps in Baby Steps
[DevSecOps Live] DevSecOps: Challenges and Opportunities
The What, Why, and How of DevSecOps
DevSecOps | DevOps Sec
DEVSECOPS.pptx
DevSecOps - The big picture
Devops Devops Devops, at Froscon
DevSecOps reference architectures 2018
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
DevOps Foundation
Introduction to DevSecOps
DevSecOps: Taking a DevOps Approach to Security
Ad

Similar to DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and challenges (20)

PPTX
DevSecOps Training Bootcamp - A Practical DevSecOps Course
PPTX
DevOps vs DevSecOps: How to Balance Speed and Security in Software Development
PDF
Continuous Security / DevSecOps- Why How and What
PPTX
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
PDF
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
PPTX
DevSecOps Best Practices-Safeguarding Your Digital Landscape
PPTX
Testing in DevOps world
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
PDF
DevSecOps Implement Making Security Central to Your DevOps Pipeline
PDF
DevSecOps - Background, Status and Future Challenges
PDF
Strengthen and Scale Security for a dollar or less
PPTX
Dev secops indonesia-devsecops as a service-Amien Harisen
PPTX
PPTX
Why You Should Implement DevSecOps Approach?
PPTX
DevSecOps: Integrating Security Into Your SDLC
PPTX
DevOps Security: How to Secure Your Software Development and Delivery
PDF
Why You Should Implement DevSecOps Approach?
PDF
Scale security for a dollar or less
PDF
Understanding DevOps Security - Full Guide
PDF
understanding devops security - DevSecOps
DevSecOps Training Bootcamp - A Practical DevSecOps Course
DevOps vs DevSecOps: How to Balance Speed and Security in Software Development
Continuous Security / DevSecOps- Why How and What
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
DevSecOps Best Practices-Safeguarding Your Digital Landscape
Testing in DevOps world
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
DevSecOps Implement Making Security Central to Your DevOps Pipeline
DevSecOps - Background, Status and Future Challenges
Strengthen and Scale Security for a dollar or less
Dev secops indonesia-devsecops as a service-Amien Harisen
Why You Should Implement DevSecOps Approach?
DevSecOps: Integrating Security Into Your SDLC
DevOps Security: How to Secure Your Software Development and Delivery
Why You Should Implement DevSecOps Approach?
Scale security for a dollar or less
Understanding DevOps Security - Full Guide
understanding devops security - DevSecOps
Ad

Recently uploaded (20)

PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Electronic commerce courselecture one. Pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
A Presentation on Artificial Intelligence
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPT
Teaching material agriculture food technology
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Modernizing your data center with Dell and AMD
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Cloud computing and distributed systems.
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
NewMind AI Monthly Chronicles - July 2025
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Electronic commerce courselecture one. Pdf
The AUB Centre for AI in Media Proposal.docx
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
A Presentation on Artificial Intelligence
Encapsulation_ Review paper, used for researhc scholars
The Rise and Fall of 3GPP – Time for a Sabbatical?
Teaching material agriculture food technology
Chapter 3 Spatial Domain Image Processing.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Modernizing your data center with Dell and AMD
Dropbox Q2 2025 Financial Results & Investor Presentation
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Cloud computing and distributed systems.
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
NewMind AI Monthly Chronicles - July 2025

DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and challenges