8. Security and Security Audits

To err is human; to really screw up you need the root password.

—Anonymous

An initial reaction to discussing security in a DevOps context is to assume that security practices are not agile and can actually hinder improving the time between a code commit and acceptance into normal production. We believe that this reaction is totally backward. Discussing adoption of DevOps practices without considering security makes the security team a critic of these practices and dooms the adoption of these practices in many enterprises. In our case study in Chapter 12, we see an approach that advocates integrating the security team into the adoption process. Other DevOps activities that are candidates for the discussion of security ...

Get DevOps: A Software Architect’s Perspective now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.