Modern software engineering practices of Agile and DevSecOps have provided a foundation for producing working software products faster and more reliably than ever before. Far too often, however, these practices do not address the non-software concerns of business mission and capability delivery even though these concerns are critical to the successful delivery of a software product. Through our work with government organizations, we have found that expanding DevSecOps beyond product development enables other teams to increase their capabilities and improve their processes. Agile methodologies are also being used for complex system and hardware developments. In this podcast from the Carnegie Mellon University Software Engineering Institute, Lyndsi Hughes, a senior systems engineer and David Sweeney, an associate software developer, both with the SEI CERT Division, share their experiences leveraging DevSecOps pipelines in atypical situations in support of teams focused on the capability delivery and business mission for their organizations.
A Penetration Testing Findings Repository
Understanding Vulnerabilities in the Rust Programming Language
We Live in Software: Engineering Societal-Scale Systems
Secure by Design, Secure by Default
Key Steps to Integrate Secure by Design into Acquisition and Development
An Exploration of Enterprise Technical Debt
The Messy Middle of Large Language Models
An Infrastructure-Focused Framework for Adopting DevSecOps
Software Security in Rust
Improving Interoperability in Coordinated Vulnerability Disclosure with Vultron
Asking the Right Questions to Coordinate Security in the Supply Chain
Securing Open Source Software in the DoD
A Model-Based Tool for Designing Safety-Critical Systems
Managing Developer Velocity and System Security with DevSecOps
A Method for Assessing Cloud Adoption Risks
Software Architecture Patterns for Deployability
ML-Driven Decision Making in Realistic Cyber Exercises
A Roadmap for Creating and Using Virtual Prototyping Software
Software Architecture Patterns for Robustness
A Platform-Independent Model for DevSecOps
Create your
podcast in
minutes
It is Free