An excellent DevSecOps guide from
@PagerDuty to help DevOps folks bring security practices into their work
I love the choices of what they included: cultural change, building empathy, shadowing, establishing trust, communication guidelines
devsecops.pagerduty.com/
ALT Text from link:
PagerDuty P logo
DevSecOps
Who is This For?
This guide is written primarily for individual contributors who are not currently security engineers, but are interested in learning ways to improve how they implement security practices in their code and how they interact with their security teams and/or consultants. The focus of this guide is to define DevSecOps and dive into ways to support it within an organization
ALT What is Covered?#
Introduction#
What is DevSecOps, its benefits, and how to implement
Security Terminology
Cultural Changes#
Building Empathy & Team Interactions#
Walk A Mile: Shadowing
Full-Service Ownership
Security Champions Program
Meet Needs to Gain Momentum
Team Interactions
Implementation#
Shift Left#
Identify Your Needs With a Security Assessment
Assessment Frameworks
Training and Education#
Threat Modeling Exercises
Capture the Flag Games
Establish Trust: Don't Do Gotchas
Socially Engineer Security Trainings
Additional Information#
Secure Software Development Life Cycle
Resources and References