Manage HR Magazine | Monday, February 28, 2022
Organizations can now build software at breakneck speed because of advancements in developer tools, containers, and code repositories
FREMONT, CA: Almost every application security team is currently overloaded and unable to keep up with the rapid pace of modern software development. Organizations can now build software at breakneck speed because of advancements in developer tools, containers, and code repositories. Shifting security left in the development cycle is a proven strategy for helping AppSec teams stay on top of security updates and freeing them up for additional high-value security responsibilities. When security is shifted to the left, developers are held responsible for writing secure code. AppSec teams give assistance and expertise at the same time, but a developer-first application security programme is much more than just shifting left.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
One prevalent misconception concerning developer-first application security is that it just entails integrating security scanning technologies into continuous integration and delivery (CI/CD) pipelines. While this strategy helps to move one piece of AppSec forward in the pipeline, it is only a small part of what it takes to build an AppSec programme that is developer-centric. While using security tools in the CI pipeline yields findings early in the development process, it does not guarantee that developers will respond to or even look at the results. Presenting security problems to developers earlier in the development cycle is beneficial, but it is only the beginning of a developer-first security approach.
To fully embed security into software from the beginning, security teams must first understand the project's business context and purpose. Additionally, early in the development cycle, developers must be aware of the security risks and ramifications. Developers should be trained to apply risk-appropriate security controls to code repositories and services, as not all of them pose the same amount of risk. Much more severe risk is presented in a web service taking untrusted traffic and handling confidential information, when compared to an internal service that does not handle sensitive information or touch critical components.
More in News