As DevOps Accelerates, Security's Role Changes

As DevOps Accelerates, Security's Role Changes
There remains a disconnect between developers and security teams, with uncertainty around who should handle software security.

DevOps adoption rates have increased, with 25% of companies reporting three to five years of practice, and another 37% reporting one to three years. The jump has accelerated development but driven what researchers call "a clear disconnect" between developers and security teams.


As part of its 2020 Global DevSecOps Survey, GitLab researchers polled more than 3,650 people on their DevOps successes and challenges. They learned the accelerating adoption of DevOps in general and implementation of new tools has led to changes in job functions and tool choices, as well as organizational charts within the developer, security, and operations teams.


"One of the biggest changes is a majority of respondents indicated that even today their roles are changing dramatically," says Jonathan Hunt, vice president of security with GitLab. "Over 60% of developers indicated they feel their role is changing and about 80% of security teams feel their roles and responsibilities are changing as well, with respect to DevSecOps strategy." 


No longer is DevSecOps a futuristic concept or cutting-edge strategy people don't know much about, Hunt adds. Businesses are subscribed to the idea that DevOps and DevSecOps provide a significant advantage into developing code faster and identifying vulnerabilities sooner. These thoughts are echoed in a Dark Reading study focused on secure application development: 75% of organizations surveyed credit their development team with being knowledgeable about application security, and 70% say security is involved in their software development efforts.


Many organizations continue to experience a disconnect between developer and security teams. Dark Reading data shows 30% of developers are promoting code without security's involvement, a ..

Support the originator by clicking the read the rest link below.