
3/12/2020 · Vanessa Wegner
What this post added
This post introduces the concept of 'security as code' as a key practice for DevSecOps. It defines security as code as integrating security policies, tests, and scans into DevOps tools and workflows. It highlights six capabilities to prioritize: automating security scans and tests within the pipeline, building a continuous feedback loop, evaluating and monitoring automated security policies, automating complex manual tests, testing new code in staging environments, and creating logs for review dashboards. It positions security as code as a best practice for the larger goal of integrating security throughout the SDLC.