This document discusses leveraging DevOps and Agile development practices to transform application testing programs. It provides examples of how Cisco has implemented continuous security practices. Continuous security involves running static and dynamic application security testing at various stages of the development lifecycle. It also involves managing security incident data and mapping it to application and environment attacks. Continuous security helps manage risk holistically by minimizing attack surfaces and facilitating bottom-up and top-down vulnerability management. Key resources are provided to learn more about secure DevOps practices and application security testing.