Custom Compliance Frameworks
Why implementing security as code is important for DevSecOps

Why implementing security as code is important for DevSecOps

3/12/2020 · Vanessa Wegner

What this post added

This post introduces the concept of 'security as code' as a key practice for DevSecOps. It defines security as code as integrating security policies, tests, and scans into DevOps tools and workflows. It highlights six capabilities to prioritize: automating security scans and tests within the pipeline, building a continuous feedback loop, evaluating and monitoring automated security policies, automating complex manual tests, testing new code in staging environments, and creating logs for review dashboards. It positions security as code as a best practice for the larger goal of integrating security throughout the SDLC.

Read the original post ↗