Security has to build its own pipelines for DevSecOps (Image Credit: Johnson Martin from Pixabay )Every DevOps conference likes to talk about the benefits from DevSecOps, shifting security left. The challenge for most organisations is how to do it. Part of the problem is breaking down cultural barriers and success there is patchy. A more important issue is working out where security integrates with DevOps. The stock answer is shift-left but exactly how and what that means still seems to be a secret.

At RSA 2020, Enterprise Times cornered Chris Kirsch who is responsible for product strategy at Veracode. As Veracode is an application security vendor, we wanted to know what was going on and how to better secure apps.

Chris Kirsch, Director Product Strategy, Veracode (Image Credit: LinkedIn)
Chris Kirsch, Director Product Strategy, Veracode

We started off by asking Kirsch why security teams were building their own pipelines to insert into the DevSecOps process. Kirsch started by saying that security teams complain that: “Developers don’t understand security.” He then turned that around saying that: “Security needs to understand development better.

Kirsch continued saying: “Development has moved on a lot and understanding pipelines and automation is really critical for software security.” Kirsch sees automation as the key to keep up with the current cadence of software development. He also sees automation as allowing the testing of a much larger set of software inside the business.

Kirsch talks about the complexity that open source brings when it comes to testing libraries. He also says that investing in app sec has to start at the top of the company, There needs to be buy-in at the people level. Interestingly, Kirsch brings up the issue that not all testing can be automated and not all software can be pentested.

To hear what else Kirsch has to say, listen to the podcast

Where can I get it?

obtain it, for Android devices from play.google.com/music/podcasts

use the Enterprise Times page on Stitcher

use the Enterprise Times page on Podchaser

listen to the Enterprise Times channel on Soundcloud

listen to the podcast (below) or download the podcast to your local device and then listen there

Previous articleAsana delivers hybrid platform for Sales and Operations
Next articleNTT Ltd expands partnership with Palo Alto
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here