Skip to main content

Solving the challenges of shifting security left

Amidst the “Shift Left and Extend Right” security trend, developers find themselves needing to implement more robust security practices into their processes. Idan Plotnik, co-founder and CEO of Apiiro, provider of an application risk management platform, discussed the ways in which developers can mitigate critical security risks in order to better protect themselves and their organization.

According to Plotnik, it is a myth that developers will be able to handle security all on their own. “I don’t think that this will happen in the next five to 10 years. What will happen is that you have something like a security champion in the development group and you have an application security program or leader across business units that is putting the security and compliance controls in place,” he said. Plotnik explained that the reason it is very challenging to completely shift security left is that it will result in too many noisy tools sending too many alerts with a lack of context. “We need more context throughout this process if we want the developers to feel ownership and start helping us as security practitioners,” he said.

Plotnik believes that if more security context can be added to DevOps practices already in place, achieving an automated DevSecOps process becomes much more attainable. He said, “If you have the context and can automate it this will help DevOps move faster and allow the developers to provide more value with less time and reduce the costs and the risks early in the development process.” 

A big issue that many organizations face when it comes to implementing security into their development processes is deciding where to start. According to Plotnik, the key aspect businesses need at the start is visibility. “How can you start building an application security program or how do you start remediating risks if you don’t have the visibility? This is the fundamental thing that you need to do as a security leader… you need visibility before you can start anything,” he said. “There is another important thing and that is that you need to build trust with your team because if you don’t have that trust, everything breaks.”

Plotnik also believes that a big mistake many organizations are making is that they begin shifting security left with an emphasis on tooling. With this, he circled back to the essential context and visibility he spoke about earlier. “Don’t start with the tools, start with understanding what you have and from there you can prioritize the relevant tools and processes,” he said. 

According to Plotnik, if there is one thing developers can do to counteract the challenges they face in this process it is being continuously curious about security processes. “Training or reading or just being curious because if you don’t care about it, I don’t think anything will help you. If I don’t care about my code and if I don’t care about the perception or consequences of my code on the rest of the organization, then nothing will help.”

The post Solving the challenges of shifting security left appeared first on SD Times.



from SD Times https://ift.tt/3p7qP84

Comments

Popular posts from this blog

Difference between Web Designer and Web Developer Neeraj Mishra The Crazy Programmer

Have you ever wondered about the distinctions between web developers’ and web designers’ duties and obligations? You’re not alone! Many people have trouble distinguishing between these two. Although they collaborate to publish new websites on the internet, web developers and web designers play very different roles. To put these job possibilities into perspective, consider the construction of a house. To create a vision for the house, including the visual components, the space planning and layout, the materials, and the overall appearance and sense of the space, you need an architect. That said, to translate an idea into a building, you need construction professionals to take those architectural drawings and put them into practice. Image Source In a similar vein, web development and design work together to create websites. Let’s examine the major responsibilities and distinctions between web developers and web designers. Let’s get going, shall we? What Does a Web Designer Do?

A guide to data integration tools

CData Software is a leader in data access and connectivity solutions. It specializes in the development of data drivers and data access technologies for real-time access to online or on-premise applications, databases and web APIs. The company is focused on bringing data connectivity capabilities natively into tools organizations already use. It also features ETL/ELT solutions, enterprise connectors, and data visualization. Matillion ’s data transformation software empowers customers to extract data from a wide number of sources, load it into their chosen cloud data warehouse (CDW) and transform that data from its siloed source state, into analytics-ready insights – prepared for advanced analytics, machine learning, and artificial intelligence use cases. Only Matillion is purpose-built for Snowflake, Amazon Redshift, Google BigQuery, and Microsoft Azure, enabling businesses to achieve new levels of simplicity, speed, scale, and savings. Trusted by companies of all sizes to meet

2022: The year of hybrid work

Remote work was once considered a luxury to many, but in 2020, it became a necessity for a large portion of the workforce, as the scary and unknown COVID-19 virus sickened and even took the lives of so many people around the world.  Some workers were able to thrive in a remote setting, while others felt isolated and struggled to keep up a balance between their work and home lives. Last year saw the availability of life-saving vaccines, so companies were able to start having the conversation about what to do next. Should they keep everyone remote? Should they go back to working in the office full time? Or should they do something in between? Enter hybrid work, which offers a mix of the two. A Fall 2021 study conducted by Google revealed that over 75% of survey respondents expect hybrid work to become a standard practice within their organization within the next three years.  Thus, two years after the world abruptly shifted to widespread adoption of remote work, we are declaring 20