Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DevOps Days Baltimore 2017 - DevSecOpsNess: Adding the Business Dimension to DevOps

DevOps Days Baltimore 2017 - DevSecOpsNess: Adding the Business Dimension to DevOps

An ignite talk about the value of being proactive in applying business understanding to DevOps activities.

Tanusree McCabe

March 08, 2017
Tweet

More Decks by Tanusree McCabe

Other Decks in Technology

Transcript

  1. 2 If you’re doing DevSecOps well, you’re: ✓ Collaborating ✓

    Integrating security early and often ✓ Expediting releases ✓ Embracing automation ✓ Improving quality
  2. 5 DevSecOps still doesn’t ensure that you’re adding any value

    to the business. Sure, you’re delivering faster. Maybe even cheaper. Maybe even ‘failing fast’. But are you really and truly delivering what your business needs?
  3. 9 Development: Challenge the Requirement • What benefit is this

    providing? • Would the end user really want it this way? • Does this fit with the business’ strategy? • Functionality • Bug fix • Chore
  4. 10 Operations: Challenge the Process • What benefit is this

    providing? • Is the expectation accurate? • Is this being done efficiently? • Continuous Deployment • Continuous Delivery • Continuous Monitoring • Incident Response
  5. 11 Security: Challenge the Risk • What benefit is this

    providing? • Does the solution address the real problem? • Is the solution based on quantitative analysis? • Regulation • Controls • Assessments • Monitoring
  6. 13 • What is the purpose of the application or

    system? Mission critical or not…
  7. 14 • How does the requirement/process/control fit into the business’

    mission or strategy? Alignment, alignment, alignment!
  8. 15 • What is the cost of the proposed alternatives

    and how does that factor into trade-off analysis? $$$