Download Publication
Who it's for:
- CISOs
- DevOps Professionals
- Quality Assurance Specialists
- Internal Auditors
DevSecOps - Pillar 4 Bridging Compliance and Development
Release Date: 02/08/2022
Working Group: DevSecOps
- How to conduct assessments, which are the first port of call for gauging maturity and effectiveness in DevSecOps processes
- Key considerations for shifting the mindset of how to design and implement compliance into applications
- How to translate compliance objectives into security measures
- The different practices in security tooling that can provide assurance for compliance requirements
- How to implement guardrails
This publication is part of an entire series on the Six Pillars of DevSecOps. You can find all the papers in the series that have been released so far here.
Download this Resource
Prefer to access this resource without an account? Download it now.
Acknowledgements
Michael Roza
Risk, Audit, Control and Compliance Professional at EVC
Since 2012, Michael Roza has been a pivotal member of the Cloud Security Alliance (CSA) family. He has contributed to over 125 projects, as a Lead Author or Author/Contributor and many more as a Reviewer/Editor.
Michael's extensive contributions encompass critical areas including Artificial Intelligence, Zero Trust/Software Defined Perimeter, Internet of Things, Top Threats, Cloud Control Matrix, DevSecOps, and Key Management. His lea...
Roupe Sahans
DevSecOps Leader
Roupe leads DevSecOps delivery and thought leadership for technology and media clients embracing digital transformation.
Roupe started his DevOps journey in 2016, building containerised microservices on AWS for government platforms. He has since been working with engineers to c-suite executives to embed security and resilience into digital products, secure cloud services, and reduce cyber technical-debt.
Most recently Roupe ha...
Ashleigh Buckingham
Chris Hughes
Co-Founder and CISO at Aquia
Chris currently serves as the Co-Founder and CISO of Aquia. Chris has nearly 20 years of IT/Cybersecurity experience. This ranges from active duty time with the U.S. Air Force, a Civil Servant with the U.S. Navy and General Services Administration (GSA)/FedRAMP as well as time as a consultant in the private sector. In addition, he also is an Adjunct Professor for M.S. Cybersecurity programs at Capitol Technology University and University of...