Devops is transforming application development; the same principles of automation, integration, and collaboration can vastly improve security as well Credit: Matt Moor Enterprise security pros are often seen as heavy-handed gatekeepers obsessed with reducing risk. They’d rather be viewed as enablers who help the organization complete tasks and gain access to needed data.To make that transformation, security teams must become faster, more efficient, and more adaptable to change. That sounds a lot like devops.Indeed, security can derive inspiration from devops, says Haiyan Song, VP of security markets at Splunk. Devops encourages automation and better integration among tools, two trends security professionals are increasingly exploring to make security more transparent throughout the enterprise.“Make security part of the fabric so that people don’t have to think about it,” says Song. As more companies embrace devops principles to help developers and operations teams work together to improve software development and maintenance, those organizations also increasingly seek to embed security into their processes. Continuous automated testing improves application security. Increased visibility in operations improves network security.“[Working] faster means taking care of security vulnerabilities better,” Song says. This isn’t just about catching the bugs during development, but also being able to respond and fix when something has gone wrong. [ ALSO ON CSO: CSO Survival Guide: Securing DevOps ]When data collection and analysis is automated, developers, security teams, and operations can work together. The benefits go beyond application security. Song describes an organization that saw sales drop dramatically after pushing out a feature update to their ecommerce application. Was the problem with the update or the application itself? It turned out that the SSL certificate had expired. With all the players in one place, it was easier to identify and fix the problem. There is a “fusion of different operations and teams working together,” she says.Devops makes it easier for everyone involved to be transparent about what’s happening, why it’s happening, and what will happen next. That visibility is important for security teams, too, since security people don’t necessarily control network operations or the various systems. Automate data collection and data analysis across all domains so that “situationally aware” actually encompasses all processes. Bring security teams to the same table as the database and network administrators, business stakeholders, operations, and developers so that everyone works together.Security doesn’t operate in a silo, Song says. Removing barriers between teams gives security operations information about what is happening faster. Faster alerts means security operations are looking at the problem earlier in the cycle, and better information on hand helps the team figure out a solution. Related content news analysis Attackers breach US government agencies through ColdFusion flaw Both incidents targeted outdated and unpatched ColdFusion servers and exploited a known vulnerability. By Lucian Constantin Dec 06, 2023 5 mins Advanced Persistent Threats Advanced Persistent Threats Advanced Persistent Threats news BSIMM 14 finds rapid growth in automated security technology Embrace of a "shift everywhere" philosophy is driving a demand for automated, event-driven software security testing. By John P. Mello Jr. Dec 06, 2023 4 mins Application Security Network Security news Almost 50% of organizations plan to reduce cybersecurity headcounts: Survey While organizations are realizing the need for knowledgeable teams to address unknown threats, they are also looking to reduce their security headcount and infrastructure spending. By Gagandeep Kaur Dec 06, 2023 4 mins IT Jobs Security Practices feature 20 years of Patch Tuesday: it’s time to look outside the Windows when fixing vulnerabilities After two decades of regular and indispensable updates, it’s clear that security teams need take a more holistic approach to applying fixes far beyond the Microsoft ecosystem. By Susan Bradley Dec 06, 2023 6 mins Patch Management Software Threat and Vulnerability Management Windows Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe