Guide to Implementing DevSecOps for a System of Systems in Highly Regulated Environments

作者: Jose Morales , Patrick Place , Suzanne Miller , David James Shepard , Richard Turner

DOI: 10.1184/R1/12363770.V1

关键词:

摘要: DevSecOps (DSO) is an approach that integrates development (Dev), security (Sec), and delivery/operations (Ops) of software systems to reduce the time from need capability provide continuous integration delivery (CI/CD) with high quality. The rapid acceptance demonstrated effectiveness DSO in system have led proposals for its adoption more complex projects. This document provides guidance projects interested implementing defense or other highly regulated environments, including those involving systems.The report rationale adopting dimensions change required adoption. It introduces DSO, principles, operations, expected benefits. describes objectives activities needed implement ecosystem, preparation, establishment, management. Preparation necessary create achievable goals expectations establish feasible increments building ecosystem. Establishing ecosystem includes evolving culture, automation, processes, architecture their initial state toward capability. Managing measuring monitoring both health performance organization. Additional information on conceptual foundations also provided.

参考文章(5)
Gerald M. Weinberg, Quality software management: volume 4: anticipating change Dorset House Publishing Co., Inc.. ,(1997)
Stephany Bellomo, Neil Ernst, Robert Nord, Rick Kazman, Toward Design Decisions to Enable Deployability: Empirical Study of Three Projects Reaching for the Continuous Delivery Holy Grail dependable systems and networks. pp. 702- 707 ,(2014) , 10.1109/DSN.2014.104
Robert W Zmud, L Eugene Apple, None, Measuring technology incorporation/infusion Journal of Product Innovation Management. ,vol. 9, pp. 148- 155 ,(1992) , 10.1016/0737-6782(92)90006-X
Eileen Wrubel, Timothy A Chick, Mary Ann Lapham, Deborah Brey, Suzanne Miller, Kenneth Nidiffer, Robert W Boardman, Portia Crowe, Jennifer C Walker, Richard Carlson, Agile Software Teams: How They Engage with Systems Engineering on DoD Acquisition Programs ,(2014)
Jose Andre Morales, Hasan Yasar, Aaron Volkman, Implementing DevOps practices in highly regulated environments international conference on agile software development. pp. 4- ,(2018) , 10.1145/3234152.3234188