Scribe
Scribe

¿Te gusta? Haz que Scribe sea aún mejor dejando una reseña

Obtener Extensión para Chrome

Explorar

  • Videos Populares
  • Videos Recientes
  • Todos los Canales

Herramientas Gratuitas

  • Descargador de Subtítulos de Video
  • Generador de Marcas de Tiempo de Video
  • Resumidor de Videos
  • Contador de Palabras de Video
  • Analizador de Títulos de Video
  • Búsqueda de Transcripciones de Video
  • Analíticas de Video
  • Creador de Capítulos de Video
  • Generador de Cuestionarios de Video
  • Chat con Video

Producto

  • Precios
  • Blog

Developers

  • Transcript API
  • API Documentation

Legal

  • Términos
  • Privacidad
  • Soporte
  • Mapa del sitio

Derechos de autor © 2026. Hecho con ♥ por Scribe

— Si esto hizo tu vida más fácil (o al menos un poco menos caótica), ¡déjanos una reseña! Prometemos que nos alegrará el día. 😊

Related Videos

What is DevSecOps?

Video thumbnail
82.25k793 Palabras3m readGrade 18
Compartir
Channel
IBM Technology
hi I'm Andrea Crawford with IBM cloud so we're going to talk about dev sec ops dev sec ops is all about DevOps with the lens on security the benefits of dev sec ops primarily address observability this is observability in context of how observable is your application delivery process in and of itself do we know what's happening between user story all the way through to code bill deploying manage and continuous improvement another benefit is traceability so are we able to understand what user stories are being deployed and managed in the runtime environment and can we prove
it the next benefit is confidence and this is all about the business having a trustful relationship with the IT organization that what is being delivered is actually what started off in the beginning of the pipeline as a requirement or a user story and the last benefit here is compliance this becomes increasingly important for specific industries like healthcare public federal banking and the like we need to have compliance built into this release pipeline and it needs to be engineered from day one dev sack ops can really involve a lot of different activities in the supply chain
or this pipeline part of those are things like well-formed user stories over here these user stories have to be the appropriate sized well-formed and be understandable by the development team additional security features are going to be piped in over here in the code phase these involve things like test-driven development pair programming these are specific activities and new ways of working that mitigate the risk of someone or somebody introducing a bug or a defect at the coding level we also are able to achieve better test code coverage by writing our test cases first and then writing
our code we also have security aspects that we can infuse into the build phase here and this is more along the lines of linting and making sure that our code is able to conform to standard coding practices we also have this notion of scanning particularly for things like infinite loops or undeclared variables these are all potential vulnerabilities that could manifest themselves in very adverse ways once we get into production and then some additional security practices around the deploy aspect can also be infused so with the advent of cloud native and images there are even things
like notary services where we can ensure that images are not only immutable but docker images that are being deployed are in fact the same in images that are produced from the build process and then we have in the manage section here activities such as mutation detection and this is all about making sure that any runtime containers that are in your operational environment don't all of a sudden spark some sort of vulnerability in the runtime environment that you may not have caught in the build phase so dev sack ops is all about infusing risk mitigating activities
throughout this pipeline here so what are some of the use cases for infusing secure well pretty much everything but in particular if you have issues with a lack of visibility in terms of how how your applications are progressing through the pipeline and who's deploying what when and in which environment if you have cases where you are troubled with audits and being able to prove with empirical data that what you are delivering is in fact what you started out with in the beginning of the pipeline empirically tracing back all the way through from beginning to end
if you have issues with unified governance and being able to use this pipeline here across your enterprise in a uniform way so making sure that we are delivering software by appropriate by appropriating the right kind of risk mitigation are we doing the right kind of activities throughout this pipeline to mitigate the risk of getting our digital reputation in trouble at an enterprise level so these are the use cases for employing some of these dev sec ops principles there are industry standard organizations like Oh wasp or open web application security project that actually have Software Assurance
maturity models to address not just these pipeline activities but also governance construction and even recommending secure coding practices that you would find over here so to sum all of this up Duff's a cop's is all about a holistic secured by design approach to code to delivery and it all involves people process and tools thanks for watching this video if you have any questions or comments be sure to drop a line below if you want to see more videos like this in the future be sure to LIKE and subscribe
Videos Relacionados
What is DevOps?
5:59
What is DevOps?
IBM Technology
171,616 views
What Is DevSecOps (and why is this a DevOps problem)?
5:40
What Is DevSecOps (and why is this a DevOp...
DevOps For Developers
2,158 views
What is edge computing?
10:40
What is edge computing?
IBM Technology
245,740 views
Cloud Security Risks: Exploring the latest Threat Landscape Report
11:33
Cloud Security Risks: Exploring the latest...
IBM Technology
23,329 views
What is DevSecOps? DevSecOps explained in 8 Mins
8:20
What is DevSecOps? DevSecOps explained in ...
TechWorld with Nana
227,055 views
What is DevSecOps | Overview of DevSecOps | DevOps Training | Edureka
28:50
What is DevSecOps | Overview of DevSecOps ...
edureka!
35,026 views
What is DevSecOps? (Getting a Job as a  DevSecOps Engineer)
12:29
What is DevSecOps? (Getting a Job as a De...
Andrew Roe
7,010 views
Life of a DevSecOps Engineer (w/ Aras "Russ" Memisyazici)
1:06:45
Life of a DevSecOps Engineer (w/ Aras "Rus...
Cyberspatial
50,090 views
How to Create a DevSecOps CI/CD Pipeline
34:41
How to Create a DevSecOps CI/CD Pipeline
DevOps Journey
9,320 views
The Importance of DevSecOps and 5 Steps for Doing it Properly (DevSecOps EXPLAINED)
13:24
The Importance of DevSecOps and 5 Steps fo...
CoderDave
9,885 views
What is DevSecOps? DevSecOps explained in under 7 mins | 2022
7:00
What is DevSecOps? DevSecOps explained in ...
Snyk
9,471 views
Explaining DevSecOps Engineer FULLY (Is It Right For You?)
24:29
Explaining DevSecOps Engineer FULLY (Is It...
Gerald Auger, PhD - Simply Cyber
4,883 views
What is DevSecOps?
4:23
What is DevSecOps?
Plutora
13,094 views
What is GitOps, How GitOps works and Why it's so useful
11:33
What is GitOps, How GitOps works and Why i...
TechWorld with Nana
354,240 views
What Is DevSecOps ? | DevSecOps Explained in 10 Minutes | Overview of DevSecOps | Simplilearn
10:08
What Is DevSecOps ? | DevSecOps Explained ...
Simplilearn
6,245 views
Overview of DevSecOps
6:25
Overview of DevSecOps
Prevent Breach
31,358 views
DevOps vs. SRE: What's the difference?
8:23
DevOps vs. SRE: What's the difference?
IBM Technology
68,861 views
What is DevSecOps? | DevOps vs DevSecOps | KodeKloud
8:50
What is DevSecOps? | DevOps vs DevSecOps |...
KodeKloud
5,919 views
What is DNS (Domain Name System)?
7:25
What is DNS (Domain Name System)?
IBM Technology
129,396 views