Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Practices
Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Practices
复制标题
DevOps 中的软件安全:综合从业者的看法和实践
DOI:
10.1145/2896941.2896946
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
L. Williams
中科院分区:
文献类型:
--
作者:
A. Rahman;L. Williams
In organizations that use DevOps practices, software changes can be deployed as fast as 500 times or more per day. Without adequate involvement of the security team, rapidly deployed software changes are more likely to contain vulnerabilities due to lack of adequate reviews. The goal of this paper is to aid software practitioners in integrating security and DevOps by summarizing experiences in utilizing security practices in a DevOps environment. We analyzed a selected set of Internet artifacts and surveyed representatives of nine organizations that are using DevOps to systematically explore experiences in utilizing security practices. We observe that the majority of the software practitioners have expressed the potential of common DevOps activities, such as automated monitoring, to improve the security of a system. Furthermore, organizations that integrate DevOps and security utilize additional security activities, such as security requirements analysis and performing security configurations. Additionally, these teams also have established collaboration between the security team and the development and operations teams.