Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Continuous Compliance Through Value Stream Management

Continuous Compliance Through Value Stream Management

A presentation delivered to the Nat West DevOps Center of Excellence, focused on how Value Stream Management drives continuous compliance - a topic of particular interest to banks since they are highly regulated.

Helen Beal

June 24, 2020
Tweet

More Decks by Helen Beal

Other Decks in Business

Transcript

  1. value noun /ˈvæl.juː/ 1. The amount of money that can

    be received for something 2. The importance or worth of something for someone
  2. 5Selecting Which Value Stream to Start With 6Understanding the Work

    in Our Value Stream, Making it Visible, and Expanding it Across the Organization
  3. Ensure that all required items are involved in the planning.

    Involve the GRC people at this point. Create gates before items can leave the backlog and arrive in development – manual or automated. Do your threat model during development and ensure quality, performance and security requirements are met in CI – or even in the IDE. VSM tools manage these gates too. VSM manages test environments to make sure they are available, correctly versioned. Test results are correlated from builds through the route to live – making cause analysis easier. And intelligence into incidences. Gate delivery based upon compliance – so nothing can go to live unless it has passed all the checklists and had the right level of quality. Multiple release trains can be managed in a single screen. What was the level of effort to deliver the software and measure the quality – bottlenecks are identified. Risk levels can be monitored. Push NFRs forward into the next backlog iteration.