DevSecOps
What is DevSecOps?
The practice of integrating security practices within the DevOps process. DevSecOps ensures that security is a shared responsibility throughout the entire software development and deployment lifecycle.
Terms that appear alongside devsecops
Each of these is named in at least one of the same controls as devsecops. The number is how many controls name both.
- governance 7 shared controls
- compliance 6 shared controls
- vulnerability 5 shared controls
- audit 5 shared controls
- owasp 4 shared controls
- secure coding 4 shared controls
- risk assessment 4 shared controls
- penetration testing 4 shared controls
Frameworks that govern devsecops
What the standards actually require on devsecops
Requirements naming devsecops across 6 standards, quoted from the control text.
Implement Acquisition Development Maintenance + Supplier Relationships + Vulnerability Management per MTCS SS 584. Acquisition Development and Maintenance (ISO 27001 Annex A.14) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Co...
MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container · MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA →HKMA C-RAF Domain 3 PROTECTION + Domain 4 DETECTION. DOMAIN 3 PROTECTION (6 sub-areas): (1) ACCESS CONTROL - identity + access management + privileged access (PAM) + MFA + zero trust + just-in-time access + role-based access + access reviews + offboarding;
HKMA-CRAF-Domain3-4-Protection-Detection · HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel →HKMA TM-G-1 IT Strategy + Policies + Risk + Development + Change. (1) IT STRATEGY AND PLANNING (TM-G-1.3.1) - documented + Board-approved IT strategy aligned with business strategy + risk appetite + technology innovation + customer experience + investment plan...
HKMA-TMG1-Strategy-Policies-RiskAssessment-Dev-Change · TM-G-1 IT Strategy + Policies + Risk Assessment + Project Management + System Development + Change Management →X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions.
X805-Threats-Destruction-Corruption-Removal-Disclosure-Interruption-72Cell-Matrix-Application · ITU-T X.805 5 Threat Categories - Destruction + Corruption + Removal + Disclosure + Interruption + Threat-Dimension Countermeasure Matrix + 72-Cell Matrix Application + STRIDE + MITRE ATT and CK + Network Modular Risk Assessment →Apply secure software development and integration practices (DevSecOps) for applications.
DODZT-3.2 · Secure Software Development and Integration →Operations + Lifecycle cover IEEE 7000 in deployed system operation. Per public IEEE 7000-2021 abstract + Wikipedia + academic literature (full IEEE text NOT reproduced): monitoring in operation including: ethical KPIs continuous tracking + drift monitoring (c...
IEEE7000-Operations-Lifecycle-OngoingMonitoring-Incident-Decommissioning · IEEE 7000 - Operations + Lifecycle + Ongoing AI Risk Monitoring + Data Provenance + Retention + Privacy + Safe Deployment + Decommissioning + Disposal →Questions people ask about devsecops
What is DevSecOps?
Why is DevSecOps important for compliance?
Which compliance frameworks address DevSecOps?
Where can I learn more about DevSecOps?
See how DevSecOps applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.