Cloud 101CircleEventsBlog

Download Publication

The Six Pillars of DevSecOps: Collective Responsibility
The Six Pillars of DevSecOps: Collective Responsibility

The Six Pillars of DevSecOps: Collective Responsibility

Release Date: 02/21/2020

Working Group: DevSecOps

The DevSecOps Working Group identified and defined six focus areas critical to integrating DevSecOps into an organization, in accordance with the six pillars described in CSA’s Reflexive Security Framework. More detailed research and guidance across each of the six pillars of DevSecOps will be revisited and established over time in order to maintain industry specific standards. This paper is part of a planned series and will focus on the area that is arguably the foundation for all others – collective responsibility. Fostering a sense of collective security responsibility is not only an essential element of driving security into a DevOps environment, but it is also one of the most challenging. It requires cultivating a change to the organization’s mindset, its ideas and its customs and behaviors regarding software security. In this paper, we refer to this effort as building a security-supportive culture.

This publication is part of an entire series on the Six Pillars of DevSecOps. You can find all the papers in the series that have been released so far here.

Related Research | Working Group
Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
The Six Pillars of DevSecOps - Collaboration and Integration
The Six Pillars of DevSecOps - Collaboration an...
The Six Pillars of DevSecOps - Pragmatic Implementation
The Six Pillars of DevSecOps - Pragmatic Implem...
DevSecOps - Pillar 4 Bridging Compliance and Development
DevSecOps - Pillar 4 Bridging Compliance and De...
6 Surprising Findings from the CSA State of Security Remediation Report
6 Surprising Findings from the CSA State of Security Remediation Re...
Published: 03/28/2024
For Game-Changing Cloud Workload Protection, Focus on Quality Over Quantity
For Game-Changing Cloud Workload Protection, Focus on Quality Over ...
Published: 03/27/2024
Architecture Drift: What It Is and How It Leads to Breaches
Architecture Drift: What It Is and How It Leads to Breaches
Published: 03/22/2024
Cloud Security: The Fundamental Role of Identities
Cloud Security: The Fundamental Role of Identities
Published: 03/20/2024

Acknowledgements

Stacy Simpson Headshot Missing
Stacy Simpson

Stacy Simpson

This person does not have a biography listed with CSA.

John Martin Headshot Missing
John Martin

John Martin

This person does not have a biography listed with CSA.

Sean Heide
Sean Heide
Technical Research Director, CSA

Sean Heide

Technical Research Director, CSA

This person does not have a biography listed with CSA.

Souheil Moghnie Headshot Missing
Souheil Moghnie

Souheil Moghnie

This person does not have a biography listed with CSA.

Sam Sehgal
Sam Sehgal

Sam Sehgal

Sam is the program leader and a distinguished engineer in the security organization at Dell. Sam has extensive experience with the modern secure DevOps practices needed to govern product and application security programs. He currently leverages his skills at Dell and leads the DevSecOps program. In this role, he focuses on DevSecOps security and architecture, as well as Secure Development Lifecycle (SDL) automation.

Read more

Altaz Valani Headshot Missing
Altaz Valani

Altaz Valani

This person does not have a biography listed with CSA.

Ashleigh Buckingham Headshot Missing
Ashleigh Buckingham

Ashleigh Buckingham

This person does not have a biography listed with CSA.

Melissa Riley Headshot Missing
Melissa Riley

Melissa Riley

This person does not have a biography listed with CSA.

Dennis Bush Headshot Missing
Dennis Bush

Dennis Bush

This person does not have a biography listed with CSA.

Glenn Leifheit Headshot Missing
Glenn Leifheit

Glenn Leifheit

This person does not have a biography listed with CSA.

Steve Lipner Headshot Missing
Steve Lipner

Steve Lipner

This person does not have a biography listed with CSA.

Mathew Lyon Headshot Missing
Mathew Lyon

Mathew Lyon

This person does not have a biography listed with CSA.

Xiping Song Headshot Missing
Xiping Song

Xiping Song

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training