Security impacts of sub-optimal DevSecOps implementations in a highly regulated environment


연구 분야: Analysis



학회: ARES '20: Proceedings of the 15th International Conference on Availability, Reliability and Security


초록

This work presents lessons learned from a multi-year support effort of a large and well-funded software development project. The focus is on the security impacts to the DevSecOps culture, process, and pipeline. These impacts stem from faulty implementations of requirements in order to achieve a full DevSecOps environment. The faulty implementations resulted in a lax security posture facilitating potential compromise in many areas of the software development environment. We discuss each of the faulty implementations in detail and provide recommendations to avoid in future engagements. The main lesson learned was the organization's inability to strictly adhere to DevSecOps principles resulted in a dysfunctional software development environment and a reduced security posture.


Author Profile
Jose Andre Morales

Carnegie Mellon University

정보 없음
Author Profile
Thomas P Scanlon

Carnegie Mellon University

정보 없음
Author Profile
Aaron Volkmann

Carnegie Mellon University

정보 없음

📄 논문 정보

발행 연도 2020년
인용수 13
출판 국가
사이트 ACM
좋아요 수 0

연관 논문 목록 (350건)