页数:9 阅读:185 次 标签:数字工程  DevSecOps  

Digital Engineering and DevSecOps

featuring David Shepard as Interviewed by Suzanne Miller

上传于 2024-07-06 15:48
页数:18 阅读:319 次 标签:软件开发  DevSecOps  

DevOps isn’t the buzzword it was over a decade ago. Today, pretty much everyone in the software game has integrated their development and operations teams, and it’s easy to see why. Together, they’re able to deploy software faster and more reliably. It’s been an absolute gamechanger.

上传于 2022-01-13 13:09
页数:31 阅读:582 次 标签:美国国防部  数字工程  DevSecOps  

Modern information systems and weapons platforms are driven by software. As such, the DoD is working to modernize its software practices to provide the agility to deliver resilient software at the speed of relevance. DoD Enterprise DevSecOps Reference Designs are expected to provide clear guidance on how specific collections of technologies come together to form a secure and effective software factory.

上传于 2022-01-13 11:56
页数:39 阅读:462 次 标签:美国国防部  数字工程  DevSecOps  

The ability to deliver capability “at the speed of relevance” requires an innovative approach to providing secure access to cloud environments. As highlighted in a recent report by the Defense Innovation Board, “...the threats that the United States faces are changing at an ever-increasing pace, and the Department of Defense’s (DoD’s) ability to adapt and respond is now determined by its ability to develop and deploy software to the field rapidly.” To effectively and efficiently achieve the objective, access to cloud environments must be flexible, ubiquitous, and at the same time, provide the requisite level of security and monitoring to protect from, detect, respond to, and recover from cyber-attacks. The purpose of a Cloud Native Access Point (CNAP) is to provide secure authorized access to DoD resources in a commercial cloud environment, leveraging zero trust architecture (ZTA), by authorized DoD users and endpoints from anywhere, at any time, from any device.

上传于 2022-01-13 11:56
页数:13 阅读:436 次 标签:美国国防部  数字工程  DevSecOps  

DevSecOps is a software engineering culture that guides a team to break down silos and unify software development, deployment, security and operations. Critical to the success of DevSecOps adoption is buy-in from all stakeholders, including: leadership, acquisition, contracting, middle-management, engineering, security, operations, development, and testing teams. Stakeholders across the organization must change their way of thinking from “I” to “we”, while breaking team silos, and understanding that the failure to successfully deliver, maintain, and continuously engineer software and its underlying infrastructure is the failure of the entire organization, not one specific team or individual.

上传于 2022-01-13 11:56
页数:43 阅读:329 次 标签:美国国防部  数字工程  DevSecOps  

Practicing DevSecOps requires an array of purpose-built tools and a wide range of activities that rely on those tools. This document conveys the relationship between each DevSecOps phase, a taxonomy of supporting tools for a given phase, and the set of activities that occur at each phase cross-referenced to the tool(s) that support the specific activity.

上传于 2022-01-13 11:56
页数:45 阅读:527 次 标签:美国国防部  数字工程  DevSecOps  

This document is intended as an educational compendium of universal concepts related to DevSecOps, including normalized definitions of DevSecOps concepts. Other pertinent information is captured in corresponding topic-specific guidebooks or playbooks. Guidebooks are intended to provide deep knowledge and industry best practices with respect to a specific topic area. Playbooks consist of one-page plays, structured to consist of a best practice introduction, salient points, and finally a checklist or call-to-action.

上传于 2022-01-13 11:56