Skip to main content

Solving the challenges of shifting security left

Amidst the “Shift Left and Extend Right” security trend, developers find themselves needing to implement more robust security practices into their processes. Idan Plotnik, co-founder and CEO of Apiiro, provider of an application risk management platform, discussed the ways in which developers can mitigate critical security risks in order to better protect themselves and their organization.

According to Plotnik, it is a myth that developers will be able to handle security all on their own. “I don’t think that this will happen in the next five to 10 years. What will happen is that you have something like a security champion in the development group and you have an application security program or leader across business units that is putting the security and compliance controls in place,” he said. Plotnik explained that the reason it is very challenging to completely shift security left is that it will result in too many noisy tools sending too many alerts with a lack of context. “We need more context throughout this process if we want the developers to feel ownership and start helping us as security practitioners,” he said.

Plotnik believes that if more security context can be added to DevOps practices already in place, achieving an automated DevSecOps process becomes much more attainable. He said, “If you have the context and can automate it this will help DevOps move faster and allow the developers to provide more value with less time and reduce the costs and the risks early in the development process.” 

A big issue that many organizations face when it comes to implementing security into their development processes is deciding where to start. According to Plotnik, the key aspect businesses need at the start is visibility. “How can you start building an application security program or how do you start remediating risks if you don’t have the visibility? This is the fundamental thing that you need to do as a security leader… you need visibility before you can start anything,” he said. “There is another important thing and that is that you need to build trust with your team because if you don’t have that trust, everything breaks.”

Plotnik also believes that a big mistake many organizations are making is that they begin shifting security left with an emphasis on tooling. With this, he circled back to the essential context and visibility he spoke about earlier. “Don’t start with the tools, start with understanding what you have and from there you can prioritize the relevant tools and processes,” he said. 

According to Plotnik, if there is one thing developers can do to counteract the challenges they face in this process it is being continuously curious about security processes. “Training or reading or just being curious because if you don’t care about it, I don’t think anything will help you. If I don’t care about my code and if I don’t care about the perception or consequences of my code on the rest of the organization, then nothing will help.”

The post Solving the challenges of shifting security left appeared first on SD Times.



from SD Times https://ift.tt/3p7qP84

Comments

Popular posts from this blog

A guide to data integration tools

CData Software is a leader in data access and connectivity solutions. It specializes in the development of data drivers and data access technologies for real-time access to online or on-premise applications, databases and web APIs. The company is focused on bringing data connectivity capabilities natively into tools organizations already use. It also features ETL/ELT solutions, enterprise connectors, and data visualization. Matillion ’s data transformation software empowers customers to extract data from a wide number of sources, load it into their chosen cloud data warehouse (CDW) and transform that data from its siloed source state, into analytics-ready insights – prepared for advanced analytics, machine learning, and artificial intelligence use cases. Only Matillion is purpose-built for Snowflake, Amazon Redshift, Google BigQuery, and Microsoft Azure, enabling businesses to achieve new levels of simplicity, speed, scale, and savings. Trusted by companies of all sizes to meet...

Olive and NTT DATA Join Forces to Accelerate the Global Development and Deployment of AI Solutions

U.S.A., March 14, 2021 — Olive , the automation company creating the Internet of Healthcare, today announced an alliance with NTT DATA , a global digital business and IT services leader. The collaboration will fast track the creation of new healthcare solutions to transform the health experience for humans — both in the traditional healthcare setting and at home. As a member of Olive’s Deploy, Develop and Distribute Partnership Programs , NTT DATA is leveraging Olive’s open platform to innovate, build and distribute solutions to Olive’s customers, which include some of the country’s largest health providers. Olive and NTT DATA will co-develop new Loops — applications that work on Olive’s platform to provide humans real-time intelligence — and new machine learning and robotic process automation (RPA) models. NTT DATA and Olive will devote an early focus to enabling efficiencies in supply chain and IT, with other disciplines to follow. “This is an exciting period of growth at Olive, so...

2022: The year of hybrid work

Remote work was once considered a luxury to many, but in 2020, it became a necessity for a large portion of the workforce, as the scary and unknown COVID-19 virus sickened and even took the lives of so many people around the world.  Some workers were able to thrive in a remote setting, while others felt isolated and struggled to keep up a balance between their work and home lives. Last year saw the availability of life-saving vaccines, so companies were able to start having the conversation about what to do next. Should they keep everyone remote? Should they go back to working in the office full time? Or should they do something in between? Enter hybrid work, which offers a mix of the two. A Fall 2021 study conducted by Google revealed that over 75% of survey respondents expect hybrid work to become a standard practice within their organization within the next three years.  Thus, two years after the world abruptly shifted to widespread adoption of remote work, we are dec...