Continuous Compliance Through Value Stream Management
A presentation delivered to the Nat West DevOps Center of Excellence, focused on how Value Stream Management drives continuous compliance - a topic of particular interest to banks since they are highly regulated.
Involve the GRC people at this point. Create gates before items can leave the backlog and arrive in development – manual or automated. Do your threat model during development and ensure quality, performance and security requirements are met in CI – or even in the IDE. VSM tools manage these gates too. VSM manages test environments to make sure they are available, correctly versioned. Test results are correlated from builds through the route to live – making cause analysis easier. And intelligence into incidences. Gate delivery based upon compliance – so nothing can go to live unless it has passed all the checklists and had the right level of quality. Multiple release trains can be managed in a single screen. What was the level of effort to deliver the software and measure the quality – bottlenecks are identified. Risk levels can be monitored. Push NFRs forward into the next backlog iteration.