SlideShare a Scribd company logo
DevSecOps
Reference Architectures
Derek E. Weeks
VP and DevOps Advocate
Sonatype
2018
About this
collection
1. The reference architectures can be used to validate choices you have made or
are planning to make.
2. They are curated from the community. You will notice a number of common
elements that are used repeatedly.
3. Each image has a link to its original source in the speaker notes, enabling you
to deep dive for more knowledge.
If you would like to have your reference architecture added to this deck, please send it to
weeks@sonatype.com.
Integration Points and Degree of Automation
DevSecOpsTooling Design Development (IDE) Repository
Manager
CI/CD Post-Deployment
Open source
governance
Open source
software analysis
n/a
Static Application
Security Testing
(SAST)
n/a
Dynamic
Application
Security Testing
(DAST)
n/a n/a n/a
Interactive
Application
Security Testing
(IAST)
n/a n/a n/a
Mobile Application
Security Testing
(MAST)
n/a n/a
Run-time
Application Self
Protection (RASP)
n/a n/a
n/a
Container and
Infrastructure
Security
n/a
Source: Gartner, December 2017, Structuring Application Security Practices and Tools to Support DevOps and DevSecOps
Degrees of
DevSecOp
s
Automatio
n
Common Elements of a DevSecOps Pipeline
DevSecOps according to U.S. Dept of Defense/JIDO
DevSecOps according to Magno Rodrigues
DevSecOps according to Carnegie Mellon’s
SEI
DevSecOps
according to
Jim Bird
DevSecOps according to Larry Maccherone
DevSecOps according to Steve Springett
DevSecOps according to TeachEra
Learn More
From Your
Peers
21 DevSecOps practitioners from leading enterprises to shared their experiences and best practices. All 21
recordings are available for free at www.alldaydevops.com.
DevSecOps according to Coveros
DevSecOps according to Aaron Weaver
DevSecOps according to Dr. Ravi Rajamiyer
DevSecOps according to ACROSEC
DevSecOps according to Ranger4
DevSecOps according to AWS
@IanMmmm
DevSecOps according to AWS
DevSecOps according to Accenture
DevSecOps according to Shine Solutions
DevSecOps according to Ellucian
DevSecOps according to WhiteHat Security
DevSecOps according to GSA
https://tech.gsa.gov/guides/building_devsecops_culture/
DevSecOps according to Sense of Security
We would love to add your DevSecOps
reference architecture to this deck.
How?
1. Send it to me (weeks@sonatype.com), with
the subject line: DevSecOps reference
architecture.
2. Provide me link as to where people can find
more information about the architecture (e.g.,
your blog, a video, a SlideShare deck).
3. I’ll add it to this deck with full attribution to
you, and let you know that it’s been updated.
It’s that easy. We all learn with help from
the community. Thank you for your
contributions!
DevSecOps reference architectures 2018

More Related Content

What's hot (20)

PDF
Introduction to DevSecOps
Setu Parimi
 
PDF
DevSecOps What Why and How
NotSoSecure Global Services
 
PDF
Demystifying DevSecOps
Archana Joshi
 
PDF
DevSecOps Implementation Journey
DevOps Indonesia
 
PDF
The State of DevSecOps
DevOps Indonesia
 
PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Mohammed A. Imran
 
PPTX
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
Mohamed Nizzad
 
PDF
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
PDF
Security Process in DevSecOps
Opsta
 
PDF
Slide DevSecOps Microservices
Hendri Karisma
 
PDF
DevSecOps and the CI/CD Pipeline
James Wickett
 
PDF
Dos and Don'ts of DevSecOps
Priyanka Aash
 
PDF
DevSecOps - The big picture
Stefan Streichsbier
 
PPTX
How to Get Started with DevSecOps
CYBRIC
 
PPTX
DevSecOps
Cheah Eng Soon
 
PPTX
Introduction to DevSecOps
abhimanyubhogwan
 
PPTX
DevSecOps: Key Controls to Modern Security Success
Puma Security, LLC
 
PPTX
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
PPTX
DevSecOps : an Introduction
Prashanth B. P.
 
Introduction to DevSecOps
Setu Parimi
 
DevSecOps What Why and How
NotSoSecure Global Services
 
Demystifying DevSecOps
Archana Joshi
 
DevSecOps Implementation Journey
DevOps Indonesia
 
The State of DevSecOps
DevOps Indonesia
 
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Mohammed A. Imran
 
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
Mohamed Nizzad
 
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
Security Process in DevSecOps
Opsta
 
Slide DevSecOps Microservices
Hendri Karisma
 
DevSecOps and the CI/CD Pipeline
James Wickett
 
Dos and Don'ts of DevSecOps
Priyanka Aash
 
DevSecOps - The big picture
Stefan Streichsbier
 
How to Get Started with DevSecOps
CYBRIC
 
DevSecOps
Cheah Eng Soon
 
Introduction to DevSecOps
abhimanyubhogwan
 
DevSecOps: Key Controls to Modern Security Success
Puma Security, LLC
 
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
DevSecOps : an Introduction
Prashanth B. P.
 

Similar to DevSecOps reference architectures 2018 (20)

PDF
devsecops-reference-architectures-2018.pdf
EvinHernandez1
 
PPTX
Dev{sec}ops
Steven Carlson
 
PDF
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
mohitd6
 
PDF
DevSecOps - Background, Status and Future Challenges
dsc71656
 
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
PDF
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
PPTX
DoD-Enterprise-DevSecOps-Initiative-Introduction-v4.52.pptx
TomGrand4
 
PDF
4 approaches to integrate dev secops in development cycle
Enov8
 
PDF
Pentest is yesterday, DevSecOps is tomorrow
Amien Harisen Rosyandino
 
PPTX
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
Bryan Len
 
PDF
Scale security for a dollar or less
Mohammed A. Imran
 
PPTX
DoD Enterprise DevSecOps Initiative by Mr. Nicolas Chaillan
HermanKBeta
 
PDF
The DevSecOps Builder’s Guide to the CI/CD Pipeline
James Wickett
 
PPTX
Top 5 DevSecOps Tools- You Need to Know About
Dev Software
 
PPTX
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
CREST
 
PDF
DevSecOps: The DoD Software Factory
scoopnewsgroup
 
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
PDF
Are You Ready to Ace Your DevSecOps Interview?
Azpirantz Technologies
 
PDF
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
PDF
Top 20 DevSecOps Interview Questions and Answers
priyanshamadhwal2
 
devsecops-reference-architectures-2018.pdf
EvinHernandez1
 
Dev{sec}ops
Steven Carlson
 
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
mohitd6
 
DevSecOps - Background, Status and Future Challenges
dsc71656
 
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
DoD-Enterprise-DevSecOps-Initiative-Introduction-v4.52.pptx
TomGrand4
 
4 approaches to integrate dev secops in development cycle
Enov8
 
Pentest is yesterday, DevSecOps is tomorrow
Amien Harisen Rosyandino
 
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
Bryan Len
 
Scale security for a dollar or less
Mohammed A. Imran
 
DoD Enterprise DevSecOps Initiative by Mr. Nicolas Chaillan
HermanKBeta
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
James Wickett
 
Top 5 DevSecOps Tools- You Need to Know About
Dev Software
 
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
CREST
 
DevSecOps: The DoD Software Factory
scoopnewsgroup
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
Are You Ready to Ace Your DevSecOps Interview?
Azpirantz Technologies
 
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
Top 20 DevSecOps Interview Questions and Answers
priyanshamadhwal2
 
Ad

More from Sonatype (20)

PPTX
DevOps Days Columbus - Derek Weeks - 2019
Sonatype
 
PDF
RSAC DevSecOpsDays 2018 - We are all Equifax
Sonatype
 
PDF
30+ Nexus Integrations to Accelerate DevOps
Sonatype
 
PDF
2017 DevSecOps Survey
Sonatype
 
PPTX
Starting and Scaling DevOps In the Enterprise
Sonatype
 
PPTX
DevOps Friendly Doc Publishing for APIs & Microservices
Sonatype
 
PDF
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
Sonatype
 
PPTX
DevOps and All the Continuouses w/ Helen Beal
Sonatype
 
PDF
Serverless and the Way Forward
Sonatype
 
PDF
A Small Association's Journey to DevOps w/ Edward Ruiz
Sonatype
 
PDF
What's My Security Policy Doing to My Help Desk w/ Chris Swan
Sonatype
 
PDF
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
Sonatype
 
PDF
Static Analysis For Security and DevOps Happiness w/ Justin Collins
Sonatype
 
PDF
Automated Infrastructure Security: Monitoring using FOSS
Sonatype
 
PDF
System Hardening Using Ansible
Sonatype
 
PDF
There is No Server: Immutable Infrastructure and Serverless Architecture
Sonatype
 
PDF
Getting out of the Job Jungle with Jenkins
Sonatype
 
PDF
Modern Infrastructure Automation
Sonatype
 
PDF
Continuous Everyone: Engaging People Across the Continuous Pipeline
Sonatype
 
PDF
The Road to Continuous Deployment
Sonatype
 
DevOps Days Columbus - Derek Weeks - 2019
Sonatype
 
RSAC DevSecOpsDays 2018 - We are all Equifax
Sonatype
 
30+ Nexus Integrations to Accelerate DevOps
Sonatype
 
2017 DevSecOps Survey
Sonatype
 
Starting and Scaling DevOps In the Enterprise
Sonatype
 
DevOps Friendly Doc Publishing for APIs & Microservices
Sonatype
 
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
Sonatype
 
DevOps and All the Continuouses w/ Helen Beal
Sonatype
 
Serverless and the Way Forward
Sonatype
 
A Small Association's Journey to DevOps w/ Edward Ruiz
Sonatype
 
What's My Security Policy Doing to My Help Desk w/ Chris Swan
Sonatype
 
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
Sonatype
 
Static Analysis For Security and DevOps Happiness w/ Justin Collins
Sonatype
 
Automated Infrastructure Security: Monitoring using FOSS
Sonatype
 
System Hardening Using Ansible
Sonatype
 
There is No Server: Immutable Infrastructure and Serverless Architecture
Sonatype
 
Getting out of the Job Jungle with Jenkins
Sonatype
 
Modern Infrastructure Automation
Sonatype
 
Continuous Everyone: Engaging People Across the Continuous Pipeline
Sonatype
 
The Road to Continuous Deployment
Sonatype
 
Ad

Recently uploaded (20)

PPTX
Milwaukee Marketo User Group - Summer Road Trip: Mapping and Personalizing Yo...
bbedford2
 
PDF
How to Hire AI Developers_ Step-by-Step Guide in 2025.pdf
DianApps Technologies
 
PDF
The 5 Reasons for IT Maintenance - Arna Softech
Arna Softech
 
PDF
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pdf
Varsha Nayak
 
PDF
Driver Easy Pro 6.1.1 Crack Licensce key 2025 FREE
utfefguu
 
PDF
vMix Pro 28.0.0.42 Download vMix Registration key Bundle
kulindacore
 
PPTX
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
Shane Coughlan
 
PDF
Digger Solo: Semantic search and maps for your local files
seanpedersen96
 
PDF
Linux Certificate of Completion - LabEx Certificate
VICTOR MAESTRE RAMIREZ
 
PDF
Automate Cybersecurity Tasks with Python
VICTOR MAESTRE RAMIREZ
 
PPTX
Hardware(Central Processing Unit ) CU and ALU
RizwanaKalsoom2
 
PPTX
Homogeneity of Variance Test Options IBM SPSS Statistics Version 31.pptx
Version 1 Analytics
 
PPTX
Transforming Mining & Engineering Operations with Odoo ERP | Streamline Proje...
SatishKumar2651
 
PPTX
Finding Your License Details in IBM SPSS Statistics Version 31.pptx
Version 1 Analytics
 
PPTX
Help for Correlations in IBM SPSS Statistics.pptx
Version 1 Analytics
 
PPTX
Agentic Automation Journey Series Day 2 – Prompt Engineering for UiPath Agents
klpathrudu
 
PPTX
Home Care Tools: Benefits, features and more
Third Rock Techkno
 
PPTX
Agentic Automation Journey Session 1/5: Context Grounding and Autopilot for E...
klpathrudu
 
PDF
4K Video Downloader Plus Pro Crack for MacOS New Download 2025
bashirkhan333g
 
PDF
AI + DevOps = Smart Automation with devseccops.ai.pdf
Devseccops.ai
 
Milwaukee Marketo User Group - Summer Road Trip: Mapping and Personalizing Yo...
bbedford2
 
How to Hire AI Developers_ Step-by-Step Guide in 2025.pdf
DianApps Technologies
 
The 5 Reasons for IT Maintenance - Arna Softech
Arna Softech
 
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pdf
Varsha Nayak
 
Driver Easy Pro 6.1.1 Crack Licensce key 2025 FREE
utfefguu
 
vMix Pro 28.0.0.42 Download vMix Registration key Bundle
kulindacore
 
OpenChain @ OSS NA - In From the Cold: Open Source as Part of Mainstream Soft...
Shane Coughlan
 
Digger Solo: Semantic search and maps for your local files
seanpedersen96
 
Linux Certificate of Completion - LabEx Certificate
VICTOR MAESTRE RAMIREZ
 
Automate Cybersecurity Tasks with Python
VICTOR MAESTRE RAMIREZ
 
Hardware(Central Processing Unit ) CU and ALU
RizwanaKalsoom2
 
Homogeneity of Variance Test Options IBM SPSS Statistics Version 31.pptx
Version 1 Analytics
 
Transforming Mining & Engineering Operations with Odoo ERP | Streamline Proje...
SatishKumar2651
 
Finding Your License Details in IBM SPSS Statistics Version 31.pptx
Version 1 Analytics
 
Help for Correlations in IBM SPSS Statistics.pptx
Version 1 Analytics
 
Agentic Automation Journey Series Day 2 – Prompt Engineering for UiPath Agents
klpathrudu
 
Home Care Tools: Benefits, features and more
Third Rock Techkno
 
Agentic Automation Journey Session 1/5: Context Grounding and Autopilot for E...
klpathrudu
 
4K Video Downloader Plus Pro Crack for MacOS New Download 2025
bashirkhan333g
 
AI + DevOps = Smart Automation with devseccops.ai.pdf
Devseccops.ai
 

DevSecOps reference architectures 2018

Editor's Notes

  • #2: DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #3: DevOps 2018
  • #4: DevOps 2018
  • #5: DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #6: https://www.youtube.com/watch?v=LNL5J6gIkv0 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #7: https://www.slideshare.net/StefanStreichsbier/devsecops-the-big-picture-66944652?qid=c3898139-ccc1-414e-8924-210428f93ba6&v=&b=&from_search=25 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #8: https://dzone.com/articles/from-water-scrum-fall-to-devsecops DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #9: http://www.oreilly.com/webops-perf/free/devopssec.csp DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #10: https://twitter.com/LMaccherone/status/843644744538427392 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #11: https://github.com/stevespringett/dependency-track DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #12: https://www.slideshare.net/secfigo/practical-devsecops-course-part-1-82334619?qid=c3898139-ccc1-414e-8924-210428f93ba6&v=&b=&from_search=7 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #13: DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #14: https://www.coveros.com/implementing-devsecops-process/ DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #15: https://www.slideshare.net/StefanStreichsbier/devsecops-the-big-picture-66944652?qid=c3898139-ccc1-414e-8924-210428f93ba6&v=&b=&from_search=25 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #16: http://devops.sys-con.com/node/4151782 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #17: https://www.acrosec.jp/qwertz/wp-content/uploads/2018/01/A1_Acrosec_Application_Security_Shift_Left_Security-by-Design_DevSecOps_V1.2.19_english.pdf DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #18: https://www.slideshare.net/DevOpstastic/devsecops-is-it-a-good-thing DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #19: https://www.slideshare.net/AmazonWebServices/securing-systems-at-cloud-scale-with-devsecops DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #20: https://www.slideshare.net/cisoplatform7/devsecops-in-baby-steps-59371055 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #21: https://www.youtube.com/watch?v=Vkn4oIIjyDs DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #22: https://shinesolutions.com/2016/05/13/the-emergence-of-the-3-towers-devsecops/ DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #23: https://www.slideshare.net/secfigo/practical-devsecops-course-part-1-82334619?qid=c3898139-ccc1-414e-8924-210428f93ba6&v=&b=&from_search=7 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #24: https://www.slideshare.net/DevOpsWebinars/take-control-design-a-complete-devsecops-program-82918313?from_action=save DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #25: https://tech.gsa.gov/guides/building_devsecops_culture/ DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #26: https://www.youtube.com/watch?v=YVa8Bn9CRK8 DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix DevOps 2018
  • #27: DevSecOps reference architectures: Sonatype Nexus, Sonatype Nexus Lifecycle, HP Fortify, SonarQube, Jenkins, Twistlock, JIRA, Contrast, aqua, OWASP Zap, Find Bugs, Gaunltl, OWASP Depedency check, NESSUS, ThreadFix