DevSecOps best practices – people
Employees are one of the most valuable assets in any organization. A cultural change in the organization, as it relates to DevSecOps, begins by changing the way people look at security and security teams.
Adopting a security-by-design approach
Although you might be thinking that mandatory security training will provide the necessary awareness about security and application security practices, there are better ways to do so.
To adopt a security-by-design approach, the following is recommended:
- Security teams should be an integral part of the development process from the design stage and for the entire development until moving to the production and maintenance stages
- Having a security team as part of the development team allows effective communication of security issues (from sharing knowledge about new vulnerabilities published on the internet to explanation of how to implement security controls)