Threat Modeling Framework
Securing the journey to continuous delivery

Securing the journey to continuous delivery

10/30/2019 · Vanessa Wegner

What this post added

This post details the Department for Work and Pensions' (DWP) transition to continuous delivery and how they integrated security into their organization's infrastructure and culture. Key aspects include bringing services in-house, adopting an iterative mindset, implementing continuous vulnerability monitoring with GitLab for risky dependencies, and using GitLab as a central point of control. Lessons learned include the importance of automation, identifying pain points, anticipating risks through threat modeling from an external perspective, and understanding that 'continuous' doesn't always mean 'automatic' due to the need for separation of duties.

Read the original post ↗