Security DevOps (SecDevOps)

At InfoSec World a few weeks ago, I was in a talk with Rich Mogull (@rmogull) of Securosis. Rich spoke on the concept of SecDevOps while demonstrating how he applies this concept to workloads running within Amazon. Now, some would argue that already contains practices within the workflows. The unfortunate reality is that, in many cases, is overlooked in the rush to get product out the door. So, how does SecDevOps differ from ? Not a lot, except that it has a higher degree of security focus. The goal of SecDevOps is not to change the , but to get the security team involved as a part of development at carefully planned locations within the workflow.

