How to Bring DevOps and Security Together

In the ideal world, everyone shifts left using a series of unobtrusive tests before production code is pushed live. In the real world, however, the cycle is running weeks behind, teams are under capacity, and senior stakeholders are shouting. Code is often pushed live before an audit has even taken place. It’s not uncommon for the team to be onto the next project before security spots errors. When the inevitable issues do arrive, bug fixes of any scale are seen as a drag on innovation. Heels are dug in, lines drawn, and corporate politics further weighs on productivity and innovation.

