Proceedings of the 12th International Conference on Availability, Reliability and Security 2017
DOI: 10.1145/3098954.3105819
|View full text |Cite
|
Sign up to set email alerts
|

Implementing Secure DevOps assessment for highly regulated environments

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
5
0

Year Published

2020
2020
2024
2024

Publication Types

Select...
3
1
1

Relationship

0
5

Authors

Journals

citations
Cited by 8 publications
(5 citation statements)
references
References 3 publications
0
5
0
Order By: Relevance
“…Only some articles such as those by Lwakatare, 16 Smeds, 17 and Jones 18 have been written to show how organizations have adopted DevOps or continuous delivery and describe different challenges, which include (1) the redesign of systems toward continuous delivery, (2) the way DevOps is deployed in an organization, (3) the quality assessment of DevOps practices in organizations, and (4) the qualification of engineers for DevOps practice. Some other papers, as those published by Bobrov, 19 Yasar, 20 or Airaj, 21 revolve around the definition of concepts in the academic area, as they show the basics of DevOps and give insights about possible implementation curricula. When it comes to training DevOps practices, there is not much research done according to Leite et al 15 Moreover, according to these authors, there is a clear need of research regarding the training of operation topics in software engineers courses, as the adoption of DevOps is greatly conditioned by the level skill of the stakeholders.…”
Section: Related Workmentioning
confidence: 99%
“…Only some articles such as those by Lwakatare, 16 Smeds, 17 and Jones 18 have been written to show how organizations have adopted DevOps or continuous delivery and describe different challenges, which include (1) the redesign of systems toward continuous delivery, (2) the way DevOps is deployed in an organization, (3) the quality assessment of DevOps practices in organizations, and (4) the qualification of engineers for DevOps practice. Some other papers, as those published by Bobrov, 19 Yasar, 20 or Airaj, 21 revolve around the definition of concepts in the academic area, as they show the basics of DevOps and give insights about possible implementation curricula. When it comes to training DevOps practices, there is not much research done according to Leite et al 15 Moreover, according to these authors, there is a clear need of research regarding the training of operation topics in software engineers courses, as the adoption of DevOps is greatly conditioned by the level skill of the stakeholders.…”
Section: Related Workmentioning
confidence: 99%
“…In general, publications, that refer to DevOps and regulations-based security, are scarce. Authors explore security in regulated environments [30,19] and where to introduce security activities in DevOps [31,12]. However DevSecOps compliant with a particular standard or domain is still missing.…”
Section: Devsecops and Security Standardsmentioning
confidence: 99%
“…While DevOps was originally conceptualized for IT companies, industrial companies have started as well to embrace DevOps practices [1,5]. However, there are yet several challenges to overcome before DevOps can be largely applied in highly regulated domains with high demand for quality attributes, in particular security [30].…”
Section: Introductionmentioning
confidence: 99%
See 1 more Smart Citation
“…In this work, we approach one of the several issues for agile and DevOps: security automation in continuous integration (cI) pipelines. In our experience from Finance, Health, and critical Infrastructure industries, development teams are urged by regulators to involve security activities in their development processes [10], [11]. This implies that CI pipelines should include checks to identify a set of security issues.…”
Section: Introductionmentioning
confidence: 99%