Download Publication

The Six Pillars of DevSecOps: Automation
Release Date: 07/06/2020
Working Group: DevSecOps
Automation is a critical component of DevSecOps because it enables process efficiency, allowing developers, infrastructure, and information security teams to focus on delivering value rather than repeating manual efforts and errors with complex deliverables. This paper focuses on a risk-based security automation approach that strings automated security actions throughout the continuous software development deployment cycle. This paper is part of a planned series on the six pillars of DevSecOps.
This publication is part of an entire series on the Six Pillars of DevSecOps. You can find all the papers in the series that have been released so far here.
Related Research | Working Group
Related Research | Working Group
Download this Resource
Related Resources
Acknowledgements

Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Since 2012, Michael Roza has been a pivotal member of the Cloud Security Alliance (CSA) family. He has contributed to over 125 projects, as a Lead Author or Author/Contributor and many more as a Reviewer/Editor.
Michael's extensive contributions encompass critical areas including Artificial Intelligence, Zero Trust/Software Defined Perimeter, Internet of Things, Top Threats, Cloud Control Matrix, DevSecOps, and Key Management. H...

Sean Heide
Sean Heide

Ankur Gargi
Ankur Gargi

John Martin
John Martin

Souheil Moghnie
Souheil Moghnie

Altaz Valani
Altaz Valani

Theodore Niedzialkowski
Theodore Niedzialkowski

Raj Handa
Raj Handa

Manuel Ifland
Manuel Ifland

Kamran Sadique
Kamran Sadique

Charanjeet Singh
Charanjeet Singh

Sam Sehgal
Sam Sehgal
Sam is the program leader and a distinguished engineer in the security organization at Dell. Sam has extensive experience with the modern secure DevOps practices needed to govern product and application security programs. He currently leverages his skills at Dell and leads the DevSecOps program. In this role, he focuses on DevSecOps security and architecture, as well as Secure Development Lifecycle (SDL) automation.
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training

CSA's Cloud Infrastructure Security training provides a high-level introduction to the most critical cloud security topics through virtual self-paced courses. Each Cloud Infrastructure Security training focuses on a specific area of cloud computing, and is design to be succinct, taking one-hour to complete.
Learn more
Learn more