Summary
In this chapter, we focused on DevSecOps. We started by talking about DevOps (a cultural change meant to break silos between developers and operations teams) and then explored how DevSecOps comes into the picture.
We explained how DevSecOps is an organization’s cultural change and how to make security teams part of development and operational teams. We looked at DevSecOps from the process perspective and how to implement security as part of a CI/CD pipeline for developing modern applications. Finally, we looked at some tools – from AWS, Azure, and GCP and open source tools – that can be integrated as part of the development process.
In the final chapter of the book, we will try to understand how to implement security in large-scale cloud environments.