Download Publication
The Six Pillars of DevSecOps: Collective Responsibility
Release Date: 02/21/2020
Working Group: DevSecOps
The DevSecOps Working Group identified and defined six focus areas critical to integrating DevSecOps into an organization, in accordance with the six pillars described in CSA’s Reflexive Security Framework. More detailed research and guidance across each of the six pillars of DevSecOps will be revisited and established over time in order to maintain industry specific standards. This paper is part of a planned series and will focus on the area that is arguably the foundation for all others – collective responsibility. Fostering a sense of collective security responsibility is not only an essential element of driving security into a DevOps environment, but it is also one of the most challenging. It requires cultivating a change to the organization’s mindset, its ideas and its customs and behaviors regarding software security. In this paper, we refer to this effort as building a security-supportive culture.
This publication is part of an entire series on the Six Pillars of DevSecOps. You can find all the papers in the series that have been released so far here.
Related Research | Working Group
Related Research | Working Group
Download this Resource
Prefer to access this resource without an account? Download it now.
Acknowledgements
Stacy Simpson
Stacy Simpson
John Martin
John Martin
Sean Heide
Technical Research Director, CSA
Sean Heide
Technical Research Director, CSA
Souheil Moghnie
Souheil Moghnie
Sam Sehgal
Sam Sehgal
Sam is the program leader and a distinguished engineer in the security organization at Dell. Sam has extensive experience with the modern secure DevOps practices needed to govern product and application security programs. He currently leverages his skills at Dell and leads the DevSecOps program. In this role, he focuses on DevSecOps security and architecture, as well as Secure Development Lifecycle (SDL) automation.
Altaz Valani
Altaz Valani
Ashleigh Buckingham
Ashleigh Buckingham
Melissa Riley
Melissa Riley
Dennis Bush
Dennis Bush
Glenn Leifheit
Glenn Leifheit
Steve Lipner
Steve Lipner
Mathew Lyon
Mathew Lyon
Xiping Song
Xiping Song
Are you a research volunteer? Request to have your profile displayed on the website here.
Interested in helping develop research with CSA?
Related Certificates & Training
CSA's Cloud Infrastructure Security training provides a high-level introduction to the most critical cloud security topics through virtual self-paced courses. Each Cloud Infrastructure Security training focuses on a specific area of cloud computing, and is design to be succinct, taking one-hour to complete.
Learn more
Learn more