DevSecOps | Dynatrace news The tech industry is moving fast and our customers are as well. Stay up-to-date with the latest trends, best practices, thought leadership, and our solution's biweekly feature releases. Fri, 12 Jun 2026 11:55:02 +0000 en hourly 1 Ingest, enrich, and deduplicate Qualys vulnerability findings with Dynatrace https://www.dynatrace.com/news/blog/ingest-enrich-and-deduplicate-qualys-vulnerability-findings-with-dynatrace/ https://www.dynatrace.com/news/blog/ingest-enrich-and-deduplicate-qualys-vulnerability-findings-with-dynatrace/#respond Wed, 25 Feb 2026 17:38:53 +0000 https://www.dynatrace.com/news/?p=73150 Dynatrace and Qualys

Dynatrace integrates with Qualys to help DevSecOps teams reduce alert fatigue by unifying and deduplicating vulnerability findings, contextualizing findings with runtime entities, and offering smarter prioritization, automation, and remediation.

The post Ingest, enrich, and deduplicate Qualys vulnerability findings with Dynatrace appeared first on Dynatrace news.

]]>
Dynatrace and Qualys

What is Qualys host scanning?

Qualys is a leading provider of vulnerability management solutions. Qualys Enterprise TruRisk platform offers a range of products, including Vulnerability Management, Detection, & Response (VMDR), which helps detect and prioritize vulnerabilities for remediation on hosts.

Host monitoring has been a best practice in security hygiene for decades and is required by various compliance standards. If your organization is already applying all the best practices for host scanning, you may still be wondering how to improve the prioritization of detected vulnerabilities.

Challenges in managing host vulnerabilities

Imagine you periodically run scans of hosts in your environments: production hosts, development hosts, etc. Each scan discovers hundreds or even thousands of vulnerabilities. Your goal is to minimize the risk by fixing the most critical vulnerabilities first.

Even with a simple strategy like this, your DevSecOps teams might still struggle to handle all the vulnerabilities. Your MTTR (Mean Time to Remediation) is increasing, and your management is not happy about it.

In addition, while focusing on critical vulnerabilities, are you sure you’re prioritizing the top risk for your organization? That approach is a good start; however, some top-risk vulnerabilities might not be critical in severity; they’re the ones that directly impact your critical production applications and services. Even if it is a high-severity vulnerability, you may want to address it before a critical vulnerability because it affects your production environment.

What can you do? Is there a way to further improve vulnerability prioritization?

The answer is yes; you need to consider additional runtime context and focus on production risk in addition to severity.

You may want to have a robust deduplication mechanism in place and visibility into the top risks. And you might also benefit from tracking the fixes and posture drifts, increasing security coverage, and reducing the number of risks over time.

Dynatrace as a runtime security platform

The Dynatrace platform offers native Runtime Vulnerability Analytics that detect vulnerabilities in your running applications and services, helping keep your application’s security risk low. This complements the host scanning and provides a complete picture of the security risks.

As an observability platform, Dynatrace also monitors the infrastructure on which your apps and services run. Hosts are one such infrastructure entity. Dynatrace knows whether a host is connected to the internet, how much traffic flows through it, whether production applications are running on that host, and how those applications are connected to other hosts and services in your organization.

With Dynatrace OpenPipeline® as the data ingest engine and Grail® as the unified data lakehouse, it is possible to ingest security findings from third-party products to bring security context to operational personas.

DevSecOps teams can simultaneously benefit from ingested and contextualized security findings using Dynatrace as a security platform, gaining ultimate visibility into all risks in one place, prioritizing based on production risks, and improving their security posture.

Qualys integration in work

Dynatrace integrates with Qualys to connect host vulnerability findings with runtime application context, allowing smarter vulnerability prioritization and better visibility into your security risks from the perspective of your runtime environment.

Here is how this integration works, and how it allows you to achieve your goals in several simple steps:

Step 1: Ingest and unify

Dynatrace delivers this integration as an extension that allows granular control over the data flow between Qualys and the Dynatrace platform.

Leveraging OpenPipeline, Qualys vulnerability findings and activity logs are pushed to Dynatrace and stored in Grail, where they’re mapped to semantic conventions that make them available in a unified schema for further analysis.

Qualys integration architecture diagram
Figure 1. Qualys integration architecture diagram

Step 2: Deduplicate and visualize

As soon as Qualys vulnerability findings are in Grail, you can view them in the Vulnerabilities app as individual findings or, using deduplication logic, as a focused list of unique findings. In this way, hundreds of findings reported repeatedly by each executed scan are deduplicated and become tens of vulnerabilities instead.

Here’s what it might look like before deduplication:

Vulnerability findings before deduplication
Figure 2. Vulnerability findings before deduplication

And here is what it looks like after applying the deduplication filter:

Vulnerability findings after deduplication
Image 3. Vulnerability findings after deduplication

The Qualys integration also includes several ready-made dashboards that help you deduplicate and display vulnerability findings in a summarized view.

Vulnerability findings dashboard
Figure 4. Vulnerability findings dashboard

Step 3: Enrich and prioritize

The next step is to use the Dynatrace runtime context to further prioritize the vulnerabilities.

In this sample dashboard, which is also shipped with the integration, we first filter the ingested vulnerability findings for monitored hosts and then add the production application-level filter.

This filtering approach focuses on runtime impact and helps reduce the number of vulnerabilities to address.

Runtime contextualization
Figure 5. Runtime contextualization

Step 4: Communicate and remediate

With Dynatrace native automation capabilities represented in the Workflows app, you can operationalize the vulnerability findings by notifying relevant stakeholders and creating work tickets for remediation.

Runtime contextualization
Figure 6. Runtime contextualization

Step 5: Track improvement

Whether remediation is applied or new vulnerabilities are identified, you can easily monitor changes across scans to see which vulnerabilities are new, unresolved, or fixed.

Here is a dashboard we provide with the integration that helps achieve this goal:

Scan comparison
Figure 7. Scan comparison
New vulnerabilities and scanned hosts
Figure 8. New vulnerabilities and scanned hosts

Step 6: Increase security coverage

Finally, Dynatrace also helps you to understand whether you’ve covered all important hosts in your environment with vulnerability scans. This security observability is fueled by monitored host entities and Qualys ingested findings.

Here is a snippet from the security coverage dashboard shipped with the integration:

Host security coverage view
Figure 9. Host security coverage view

What’s next

The Dynatrace platform helps reduce noise from vulnerability scanning and provides runtime insights to efficiently prioritize remediation efforts.

Follow our updates and news about additional integrations and learn about which products from your security stack we already cover.

If you don’t find support for your product or tool, feel free to contact us in our Community channel.

Get started

To learn more about the Qualys integration and how to set it up, read our documentation for ingesting Qualys vulnerability findings, scanning events, and auditing logs.

Install Qualys to prioritize production risks and reduce alert overload.

The post Ingest, enrich, and deduplicate Qualys vulnerability findings with Dynatrace appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/ingest-enrich-and-deduplicate-qualys-vulnerability-findings-with-dynatrace/feed/ 0
Strengthen production security: Bridge SDLC best practices with runtime validation https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/ https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/#respond Fri, 09 Jan 2026 16:16:45 +0000 https://www.dynatrace.com/news/?p=72390 Dynatrace bridges SDLC best practices with runtime validation

Modern software systems face constant security threats. While integrating security measures throughout the software development lifecycle (SDLC) helps reduce risks, some vulnerabilities may still go undetected. Combining SDLC best practices with runtime validation helps organizations detect and remediate risks in production environments, ensuring robust, actionable protection while reducing noise and saving teams time by focusing only on the issues that matter most.

The post Strengthen production security: Bridge SDLC best practices with runtime validation appeared first on Dynatrace news.

]]>
Dynatrace bridges SDLC best practices with runtime validation

Recognize the unavoidable need for runtime security

No security strategy can guarantee absolute protection. Modern software complexity and dynamic threats mean some risks will evade detection (Figure 1). According to Dynatrace analysis, a significant portion of Fortune 500 companies remain vulnerable to known vulnerabilities, such as Spring4Shell.

Funnel of security issues and risks from development to production
Figure 1. Funnel of security issues and risks from development to production.

Left-shifted tools often lack runtime context, making it hard to prioritize vulnerabilities by real-world impact. Runtime security bridges this gap by continuously monitoring production environments, detecting and mitigating threats in real time. This approach helps organizations adapt to emerging risks instead of relying on pre-deployment checks.

Dynatrace addresses this challenge by adding runtime context to left-shifted security findings, enabling environment-aware vulnerability prioritization. Dynatrace Application Security integrates seamlessly with third-party tools to ingest and enrich vulnerability data with runtime context. This context-rich prioritization reduces cognitive overload for teams across the SDLC.

The value of defense-in-depth in SDLC

A defense-in-depth approach layers multiple security controls across the SDLC to build resilient applications that can withstand sophisticated attacks. Rather than relying on a single security measure, defense-in-depth supports the strategy that if one layer misses a vulnerability, another will catch it.

This approach gains added relevance as modern development practices accelerate release cycles, often introducing new risks at every stage. By embedding security from the earliest phases of development through to production monitoring, teams can proactively identify, mitigate, and respond to threats before they escalate. Figure 2 illustrates this multi-layered approach, mapping out key capabilities across four critical SDLC phases: Development, Build, Deploy, and Observe (encompassing the commonly referred-to phases of runtime and monitoring).

High-level abstraction of activities across the software development lifecycle
Figure 2. High-level abstraction of activities across the software development lifecycle.

Each phase contributes unique controls and processes to a strong overall security posture. This layered approach is essential for protecting sensitive data, maintaining customer trust and meeting regulatory requirements in an increasingly hostile cyber environment.

To understand how this works in practice, let’s look at an example of a cloud-native microservices application.

End-to-end scenario: How the Astronomy Shop application leverages runtime context

Consider  Astronomy Shop, an online retailer demo application built on containerized microservices such as frontend, product, cart, checkout, payment, order, and search — all deployed on Kubernetes. Astronomy Shop’s teams implement defense-in-depth across the SDLC phases to secure their application.

By leveraging runtime context, they validate and prioritize risks in production, ensuring that the most critical security issues are addressed first. Below is a walkthrough of how Astronomy Shop uses tools and Dynatrace capabilities throughout the SDLC to enhance security.

Effective security starts at the foundation: during development. This phase sets the tone for the entire security lifecycle.

Development phase: Build security from the ground up

Scenario: Developers commit code for services like product, cart, and checkout. Security scanning runs early, and threat modeling identifies sensitive paths (e.g., checkout and payment). Findings are triaged later using the runtime context to prioritize risks.

Sample tools:

  • SonarQube for code quality and static application security testing (SAST), GitHub Advanced Security for dependency monitoring and software composition analysis (SCA).

The Dynatrace role:

  • Ingests security findings from development tools via OpenPipeline’s security events ingest endpoint.
  • Maps findings to the Semantic Dictionary in Grail™ for unified prioritization, analysis, and automation.
  • Highlights critical and high alerts and deprioritizes non-executed code vulnerabilities while prioritizing medium issues exposed to sensitive data. This helps developers focus on vulnerabilities that pose real risks in production.

After development, the build phase is positioned to catch vulnerabilities before deployment.

Build phase: Strengthening security through automation and testing

Scenario: Astronomy Shop teams build and push container images to AWS ECR. Automated image scanning tools like AWS Inspector and Snyk Container assess vulnerabilities. Findings are enriched with runtime context to identify which issues truly impact production.

Sample tools:

  • AWS Inspector for image scanning and Snyk for container scanning.
  • Recommended approach: Artifact/container image scanning for OS and package vulnerabilities.

The Dynatrace role:

  • Extends observability to the build phase for governance and security hygiene control.
  • Adds runtime context to container scans, so developers know which vulnerabilities to prioritize. This simplifies decision making and reduces cognitive load.
  • Automates security gates and workflows with tools like Site Reliability Guardian to ensure no critical vulnerabilities affect production.

And now, we move on to deployment, the critical moment when applications face real-world threats.

Deploy phase: Safeguard production with real-time oversight

Scenario: The Astronomy Shop team deploys services to Kubernetes using Helm or GitOps. Admission policies and baseline checks run, while cloud controls enforce guardrails and flag misconfigurations.

Sample tools:

  • Kyverno for workload and cluster policies, AWS Security Hub for cloud security posture management (CSPM).

The Dynatrace role:

  • Monitors deployment success and audits deployment operations by ingesting SDLC events.
  • Enriches KSPM and cloud misconfiguration findings with runtime context to prioritize critical issues.
  • Detects and addresses configuration issues with Dynatrace KSPM, ensuring continuous monitoring in Kubernetes and cloud environments.

Once deployed, applications should be actively monitored to detect and address emerging threats and potential signs of compromise.

Observe phase: Monitor production for threats

Scenario: The Astronomy Shop application is deployed to production and actively monitored. A new vulnerability is discovered in a library, and Dynatrace detects and locates the issue in real time. Malicious actors attempt to exploit the vulnerability, but the application remains secure due to proactive patching.

Sample tools:

The Dynatrace role:

  • Unifies third-party runtime detections and security signals into a single view for efficient processing.
  • Provides deep runtime observability through OneAgent, extending visibility to process health, cloud, and infrastructure.
  • Enables runtime security capabilities like RVA (Runtime Vulnerability Analytics), Security Posture Management (SPM), and Runtime Application Protection (RAP), serving as the final defense layer against threats.

Figure 3 highlights how Dynatrace integrates seamlessly across the SDLC, enhancing security with runtime context and enabling teams to prioritize and address the vulnerabilities that matter most.

Dynatrace coverage of activities across the software development lifecycle
Figure 3. Dynatrace coverage of activities across the software development lifecycle.

Let’s examine practical scenarios where Dynatrace enhances left-shifted security findings with runtime context, enabling environment-aware prioritization.

Practical scenarios: Elevate security with runtime context

  1. Prioritize SAST findings in code
    Static scanners often detect thousands of vulnerabilities, many of which are irrelevant in production. Runtime context enables teams to prioritize vulnerabilities based on actual risk. For instance, critical severity vulnerabilities in non-executed code could be deprioritized, while medium-severity vulnerabilities exposed to the internet and near sensitive data become high priorities.
  2. Prioritize container scanner findings
    Container scans often flag numerous vulnerabilities. Runtime context helps determine whether these issues truly impact production. For example, a critical vulnerability in a library that is never executed in production can be deprioritized, while containers not deployed in production can be addressed later.
  3. Prioritize KSPM findings on clusters
    Post-deployment, runtime context helps identify which security issues in workload cluster components or configurations impact production services. Critical vulnerabilities with no direct impact on production can be deprioritized, letting teams focus on what matters most.
  4. Prioritize cloud alerts and compliance findings
    Continuous assessment of cloud environments and prioritization of misconfigurations with the application insights reduces the noise from cloud alerts and help to remediate the most important issues first.

Ready to strengthen your security in production?

Explore how Dynatrace can integrate seamlessly into your DevSecOps processes providing application-level insights to security findings across the SDLC for smarter prioritization.

Sign up for a free trial and experience how real-time runtime context makes your organization more secure.

The post Strengthen production security: Bridge SDLC best practices with runtime validation appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/strengthen-production-security-bridge-sdlc-best-practices-with-runtime-validation/feed/ 0
Ingest and enrich security findings delivered by Amazon EventBridge with Dynatrace https://www.dynatrace.com/news/blog/ingest-and-enrich-amazon-eventbridge-security-findings/ https://www.dynatrace.com/news/blog/ingest-and-enrich-amazon-eventbridge-security-findings/#respond Wed, 15 Jan 2025 19:00:11 +0000 https://www.dynatrace.com/news/?p=67246 Dynatrace and Amazon EventBridge

Dynatrace integrates with Amazon EventBridge to break the silos between DevSecOps teams by unifying security findings along the Software Development Lifecycle (SDLC) and enriching them with runtime context. Powered by OpenPipeline™, Dynatrace allows you to ingest, visualize, prioritize, and automate security findings, helping to reduce noise from alerts and provide focused remediation to the issues […]

The post Ingest and enrich security findings delivered by Amazon EventBridge with Dynatrace appeared first on Dynatrace news.

]]>
Dynatrace and Amazon EventBridge

Dynatrace integrates with Amazon EventBridge to break the silos between DevSecOps teams by unifying security findings along the Software Development Lifecycle (SDLC) and enriching them with runtime context. Powered by OpenPipeline™, Dynatrace allows you to ingest, visualize, prioritize, and automate security findings, helping to reduce noise from alerts and provide focused remediation to the issues that matter to your critical production environments.

The complexity of multicloud environments

In complex multicloud environments, security findings are often siloed across build-time and runtime tooling, as well as spread across various environments. Thus, getting a holistic view of your security posture and risks is challenging. The consequences include:

  • Time spent navigating various platforms to collect data.
  • Difficulty prioritizing findings from disparate tools.
  • Security coverage gaps.
  • Excessive manual effort is required to notify stakeholders of critical findings.
  • Remediation takes a long time.

Moreover, with the number of security findings generated, your DevSecOps teams might become overwhelmed and miss important issues that directly impact your production services and applications. A good example is a critical severity vulnerability discovered in a build-time artifact, such as a container image that isn’t deployed and doesn’t impact your runtime. Your DevSecOps teams shouldn’t be distracted by such findings and should instead focus on vulnerabilities in your production application that are exposed to the internet and present a real risk.

The Dynatrace solution

Dynatrace addresses these issues by providing unified security events ingest and analysis of security findings across cloud environments. The ingested findings are mapped to the monitored runtime entities, which allows you to assess the risks better and reprioritize remediation of the critical findings.

Security findings can be pushed to Dynatrace, as with Amazon EventBridge, or pulled from a third-party tool by a dedicated Dynatrace integration.

With built-in support for various products and security-finding standards, Dynatrace provides visibility into security posture from multiple stages of your SDLC. This allows you to orchestrate the findings effectively, drive faster remediation, discover security coverage gaps, optimize tooling usage, and maximize your ROI.

AWS Eventbridge and Dynatrace diagram

Ingest AWS EventBridge findings into Dynatrace

Dynatrace partners with AWS and serves as a destination for Amazon EventBridge rules. Depending on the use case, findings and logs can be forwarded to the dedicated OpenPipeline endpoints and ingested into GrailTM.

Dynatrace supports security findings forwarded via Amazon EventBridge in the following scenarios:

  • Ingested as raw events or in a supported generic standard data format, such as OCSF or ASFF.
  • Forwarded as findings from the AWS Security Hub, including vulnerability, detection, and compliance events.
  • Forwarded as container findings from the Amazon ECR (basic and enhanced scanning).

Dynatrace maps the ingested events to Semantic Dictionary conventions for the supported products and data formats. You can consume the events uniformly for visualization and analysis in Dashboards and Notebooks and automation use cases in Workflows.

For example, you can ingest Amazon ECR container image vulnerability findings into Dynatrace using Amazon EventBridge. Dynatrace provides a CloudFormation template and detailed instructions as part of the setup.Please read our documentation for individual integrations, Ingest Amazon ECR vulnerability findings and scan events, Ingest AWS Security Hub security findings, and our blog post, Enrich AWS ECR vulnerability findings with runtime context, for additional details on the integration setup and supported use cases.

Get started

Explore the latest Dynatrace security apps and integrations to unlock deeper observability, automation, and AI-driven insights for your cloud environment.

Also, check out Amazon ECR monitoring & observability

Try it today

Leverage a seamless, out-of-the-box experience to optimize performance, reduce costs, and drive cloud-native innovation.

Contact your Dynatrace representative or visit our AWS integration page to start your free trial and see the difference intelligent cloud monitoring can make.

The post Ingest and enrich security findings delivered by Amazon EventBridge with Dynatrace appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/ingest-and-enrich-amazon-eventbridge-security-findings/feed/ 0
Enrich Tenable vulnerability findings with Dynatrace runtime context https://www.dynatrace.com/news/blog/enrich-tenable-vulnerability-findings-with-dynatrace-runtime-context/ https://www.dynatrace.com/news/blog/enrich-tenable-vulnerability-findings-with-dynatrace-runtime-context/#respond Tue, 14 Jan 2025 19:17:20 +0000 https://www.dynatrace.com/news/?p=67210 Dynatrace tenable

Dynatrace integrates with Tenable to provide a single pane of glass for security findings across various environments and products, allowing unified analysis, prioritization, and orchestration of findings. With the enriched runtime context, you can focus on critical issues that impact your production apps and help reduce noise for the DevSecOps teams that remediate those issues. […]

The post Enrich Tenable vulnerability findings with Dynatrace runtime context appeared first on Dynatrace news.

]]>
Dynatrace tenable

Dynatrace integrates with Tenable to provide a single pane of glass for security findings across various environments and products, allowing unified analysis, prioritization, and orchestration of findings. With the enriched runtime context, you can focus on critical issues that impact your production apps and help reduce noise for the DevSecOps teams that remediate those issues.

Managing vulnerabilities in a fragmented world

In today’s complex digital landscape, managing vulnerabilities effectively is crucial for maintaining robust security. However, the challenge often lies in the fragmentation of vulnerability data across different systems and tools.

Dynatrace provides deep insights into application runtime, offering a detailed view of how applications perform and where potential vulnerabilities might lie. On the other hand, Tenable focuses on infrastructure, conducting comprehensive scans of hosts, web applications, and compliance checks.

This division can lead to alert noise from critical security findings in infrastructure, which might not always be relevant to your production environment and applications. Understanding and integrating these insights is key to effectively prioritizing and addressing the most critical vulnerabilities.

Enhance security with the Dynatrace and Tenable integration

Managing vulnerabilities effectively is crucial for maintaining robust security. The integration of Dynatrace with Tenable Vulnerability Management and the Tenable One platform brings a comprehensive approach to vulnerability management and user activity monitoring.

By integrating Dynatrace with Tenable, you can:

  • Prioritize vulnerability findings with runtime context: Gain deeper insights into how vulnerabilities impact your applications in real time, allowing for more informed decision-making.
  • Discover security product coverage gaps: Identify areas where your security products might not be providing adequate coverage, ensuring that no vulnerabilities are overlooked.
  • Automate notifications and ticket creation for new findings: Streamline your response to new vulnerabilities with automated workflows.
  • Monitor and detect suspicious user activity: Analyze and detect suspicious user activity within the Tenable platform.

This integration enhances your ability to manage vulnerabilities and ensures that your security efforts are aligned with your production environment and applications.

Tenable extension with Dynatrace diagram

Integrating with Tenable

Dynatrace delivers this integration as an extension that allows granular control over the data flow between Tenable and the Dynatrace platform.

Leveraging OpenPipelineTM, Tenable vulnerability findings and activity logs are pushed to Dynatrace and stored in Grail TM where they’re mapped to semantic conventions that make them available in a unified schema for further analysis.

With this integration, we also provide additional artifacts to help you get started with security data visualization and automation use cases:

  • Sample dashboard for vulnerability findings: Surface all the vulnerability findings across various products. The dashboard connects the findings to monitored host entities for an impact view of your runtime exposures.Sample dashboard for vulnerability findings in Dynatrace screenshot
  • Sample dashboard for product scan coverage: Visualize and discover coverage gaps in your environment. The dashboard provides the host entity scan coverage to ensure comprehensive security assessments.Sample dashboard for product scan coverage in Dynatrace screenshot
  • Sample workflow for Slack notifications: Receive instant alerts in Slack for new critical vulnerability findings, keeping your team informed and responsive.
    Sample workflow for Slack notifications in Dynatrace screenshot
  • Sample workflow for Jira ticket creation: Automatically create Jira tickets for new critical vulnerabilities, ensuring they’re tracked and addressed promptly.Sample workflow for Jira ticket creation in Dynatrace screenshot

What’s next

Starting with asset scans from Tenable Vulnerability Management, Dynatrace gradually extends the support for additional vulnerability and misconfiguration scan types from Tenable.

Ready to explore the Dynatrace Tenable integration for yourself? Download the app from Dynatrace Hub.

For more detail, please dive into our documentation about ingesting Tenable vulnerability findings, scanning events, and auditing logs.

The post Enrich Tenable vulnerability findings with Dynatrace runtime context appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/enrich-tenable-vulnerability-findings-with-dynatrace-runtime-context/feed/ 0
What is software composition analysis? https://www.dynatrace.com/news/blog/what-is-software-composition-analysis/ https://www.dynatrace.com/news/blog/what-is-software-composition-analysis/#respond Thu, 21 Nov 2024 07:46:26 +0000 https://www.dynatrace.com/news/?p=51527 Critical IT operations at risk: The blame game and siloed tools take a toll

The growing popularity of open source software presents new risks associated with vulnerable libraries. In response, organizations have adopted additional security tools, such as software composition analysis, that scan code libraries for vulnerabilities. These tools enable organizations to mitigate risk earlier in the software development lifecycle (SDLC). Traditionally, companies tracked these vulnerabilities manually or sifted […]

The post What is software composition analysis? appeared first on Dynatrace news.

]]>
Critical IT operations at risk: The blame game and siloed tools take a toll

The growing popularity of open source software presents new risks associated with vulnerable libraries. In response, organizations have adopted additional security tools, such as software composition analysis, that scan code libraries for vulnerabilities. These tools enable organizations to mitigate risk earlier in the software development lifecycle (SDLC).

Traditionally, companies tracked these vulnerabilities manually or sifted through volumes of code. Both approaches resulted in lost time and resources. To handle the increasing complexity of open source software, software composition analysis (SCA) has become an important tool. SCA scans software dependencies for security vulnerabilities with speed and reliability.

What is software composition analysis?

Software composition analysis is an application security methodology that tracks and analyzes open source software components. Fundamentally, SCA tools provide insight into open source license limitations and possible vulnerabilities in your projects. These tools help organizations stay abreast of critical tasks, including security, license compliance, and code quality, to minimize risk.

Software composition analysis provides three core capabilities:

  1. Build a software bill of materials (SBOM) to establish a detailed inventory of your open source software packages.
  2. Verify license compliance requirements by determining what open source software you’re using and where it originated.
  3. Discover detailed information about key vulnerabilities in your source code and provide applicable remediation suggestions.

How does software composition analysis work?

SCA tools work by running scans on a code base and creating a vulnerability analysis. The analysis outputs an SBOM that lists software components and their respective licenses. In addition, the scan inspects files to find vulnerable third-party libraries and provides insight into open source dependencies. The technology then compares the SBOM with other vulnerability databases to pinpoint critical vulnerabilities. Finally, an SCA tool offers remediation suggestions to resolve harmful vulnerabilities. As part of the process, SCA provides a full analysis of open source project health metrics.

For example, an organization that needs to establish a comprehensive security and compliance baseline can use software composition analysis to attain baseline license compliance and reveal security vulnerabilities. As teams further develop their code, they can use SCA to maintain license compliances and ensure consistent security.

Why is software composition analysis important?

Software composition analysis is an essential practice for IT professionals tasked with securing complex software ecosystems. Modern software development relies heavily on open source components and third-party libraries, which bring efficiency and robustness to the development process. However, they also introduce unique security, compliance, and risk management challenges.

  1. Identifying vulnerabilities:  

Open source components often have inherent vulnerabilities due to their wide usage and public availability of their source code. This makes them attractive targets for bad actors. Without SCA, organizations risk unknowingly deploying software with vulnerabilities and exposing their systems. SCA tools provide automated scans to identify known vulnerabilities in third-party components.

  1. Ensuring license compliance:  

Understanding the legal implications of open source software is critical. Many open source licenses come with obligations that organizations must adhere to—like attribution requirements or restrictions on commercial use. Non-compliance can lead to legal disputes, fines, or even the need to re-engineer software. SCA tools help by automatically flagging license issues, ensuring organizations remain compliant.

  1. Managing supply chain risks:  

Using external dependencies in software increases the likelihood of inheriting risks from upstream sources. Compromised dependencies can ripple through an organization’s entire software stack. SCA offers visibility into an SBOM, enabling teams to monitor which components are in use and quickly address risks when vulnerabilities are discovered.

By embedding SCA into their development and DevSecOps practices, IT professionals can proactively mitigate risks, maintain compliance, and safeguard their software supply chain. SCA isn’t just a tool—it’s a vital part of protecting modern software systems in an increasingly interconnected world.

The benefits of software composition analysis

Software composition analysis (SCA) offers invaluable benefits to developers and IT professionals committed to creating secure, high-quality software.

Enhanced security

One of SCA’s primary advantages is its ability to enhance software application security. SCA tools automatically scan your codebase to identify open source components and check them against known vulnerability databases.

License compliance

Open source components often come with specific licensing requirements that, if not adhered to, can lead to legal and financial repercussions. SCA tools help ensure compliance by analyzing the licenses of all components within your application, providing insights into potential intellectual property risks.

Improved development efficiency

By integrating SCA into the development lifecycle, teams can automate the vulnerability detection and license compliance process, freeing up valuable resources. This allows developers to focus more on building features and less on manual checks or patching insecure components.

Risk mitigation and quality assurance

SCA contributes to the overall quality assurance of software products. Organizations can ensure their applications are secure and reliable by effectively managing the risks associated with open source components.

The challenges of software composition analysis

Despite its advantages, SCA presents several challenges that must be addressed to utilize its full potential effectively.

  1. Managing the volume of open source components

The exponential growth of open source components in software development has led to a significant challenge in cataloging and managing these components within applications. With thousands of new open source libraries being added daily, SCA tools must possess robust indexing and update capabilities to ensure that they provide accurate and up-to-date information.

  1. Understanding license compliance

Open source software often comes with complex licensing terms, and noncompliance can lead to legal issues or intellectual property conflicts. Developers and IT professionals must carefully analyze and comply with these licenses, yet navigating the multitude of open source licenses remains daunting. SCA tools must be comprehensive and adept at identifying potential compliance risks.

  1. Identifying vulnerabilities

A critical function of SCA is the detection of security vulnerabilities within open source components. However, the sheer volume of potential vulnerabilities makes it challenging to prioritize which issues need immediate attention. False positives can divert resources away from actual threats, necessitating an efficient system for triaging alerts.

  1. Integration with CI/CD pipelines

For SCA to be effective, seamless integration into CI/CD pipelines is needed. The process requires careful planning and execution to ensure that SCA tools provide real-time insights without hindering development velocity.

How to implement SCA in your development pipeline

Understanding SCA

Software composition analysis is a methodical approach to managing open source components within a codebase. It identifies vulnerabilities and licensing issues, providing developers with a comprehensive overview of their software’s security posture.

Key steps in implementing SCA

  1. Integration into CI/CD pipelines: This allows for real-time monitoring and identification of vulnerabilities as new code is committed.
  2. Automated scanning and reporting: These tools analyze the codebase for known vulnerabilities against databases and immediately alert developers to potential risks.
  3. Policy management and governance: SCA tools often provide governance features that allow teams to enforce dependency management policies, ensuring compliance with organizational standards and legal requirements.
  4. Continuous monitoring and updates: The dynamics of software development mean that vulnerabilities can appear at any time. Continuous monitoring and regular updates to the SCA tool’s vulnerability database guarantee that your security measures stay ahead of emerging threats.

How security can “shift left” in a DevSecOps lifecycle

One of SCA’s major benefits is that security pros can implement it into the initial stages of the SDLC. Teams can test projects for vulnerabilities in the early stages of development before those issues reach the build stage. This saves overall production costs and valuable resources.

Moreover, IT pros can use SCA to gain a better understanding of the open source software the organization uses and to track licenses. Accordingly, SCA tools can streamline the license management process and enforce security and license policies across the different stages of the SDLC.

Finally, SCA tools bridge the gap between detection and remediation by showing the location of vulnerabilities, assessing their impact, and suggesting remediation actions.

Software composition analysis (SCA) tools can shift security left in the DevSecOps lifecycle
SCA tools can shift security left in the DevSecOps lifecycle.

But software composition analysis tools alone are not enough

Despite their benefits, SCA tools don’t cover the entire security surface area. For one, SCA tools primarily focus on pre-production environments. This means you’re unable to scan for vulnerabilities exposed in production.

Additionally, although software composition analysis provides remediation suggestions for critical vulnerabilities, it does not prioritize them. As a result, IT pros are left to determine which issue to address first based on the current vulnerabilities and risk priority order. With limited time and resources, it can be difficult for security teams to prioritize vulnerabilities without deeper analysis.

Lastly, SCA tools don’t provide information about which pending issues are the most critical to your business assets. They also provide no context surrounding a vulnerability’s point of origin.

How to pair SCA with runtime application security

Although software composition analysis tools are limited, you can enhance their value by pairing them with another layer of security at runtime.

The Dynatrace Software Intelligence Platform analyzes the full impact and risks of vulnerabilities, in context, at runtime. The Dynatrace Application Security module not only delivers remediation suggestions but also eliminates false positives, prioritizing which critical issues to address first. Dynatrace OneAgent automatically discovers vulnerabilities in both production and pre-production environments, capturing the entire range of possible issues.

By incorporating key contextual information surrounding software vulnerabilities into the Davis Security Score, Dynatrace allows you to filter and prioritize issues to determine which ones your team must remediate immediately. Dynatrace Application Security eliminates blind spots and proactively identifies critical production risks earlier in the process, all to ensure your organization’s SDLC runs seamlessly.

Software composition analysis FAQ

  1. What is the difference between SCA and SAST? 

While both improve software security, SCA analyzes third-party and open source dependencies to find vulnerabilities and licensing information. On the other hand, SAST examines your proprietary code to detect flaws such as insecure coding practices or logic errors.

  1. What are the benefits of using SCA tools?  

SCA tools provide several benefits, including:

  • Automatically detecting open source vulnerabilities
  • Ensuring compliance with licensing obligations
  • Speeding up the identification of security risks in software
  • Offering continuous monitoring for newly reported vulnerabilities
  1. What industries require SCA?  

Any industry using open source software can benefit from SCA. However, industries like finance, healthcare, and government, which rely on software for highly sensitive processes, prioritize SCA to reduce security risks.

  1. How often should I run SCA scans?  

SCA scans should be integrated throughout the software development lifecycle. Regular scans during development, testing, and maintenance phases are critical to identifying new risks as they emerge.

  1. Can SCA help with compliance requirements?  

Yes, SCA helps organizations comply with legal standards and regulations, such as GDPR or intellectual property laws, by validating that open source component licenses align with business requirements.

  1. What is the difference between SCA and DAST? 

While SCA examines your software’s dependencies for vulnerabilities, Dynamic Application Security Testing (DAST) tests your application dynamically in a runtime environment to find security weaknesses like injection attacks or misconfigurations.

  1. What is an SCA vulnerability? 

An SCA vulnerability is a recognized weakness in third-party or open source components that attackers could exploit.

  1. What is “composition” in software testing? 

Composition refers to understanding and managing all dependencies (libraries, frameworks, packages) your software relies on. This involves identifying their origin, versions, and known risks.

  1. What is the purpose of SCA? 

The purpose of SCA is security, compliance, and efficiency. It ensures that vulnerabilities in dependencies are mitigated, license risks are addressed, and the software supply chain is safe.

  1. How to do a SCA analysis? 

SCA is typically done using specialized tools. These tools automate scanning your dependencies, mapping them to known vulnerabilities, and providing actionable insights for remediation.

To learn more about how Dynatrace helps eliminate runtime vulnerabilities at all points in production, join us for the on-demand webinar, Intelligent Automation for DevSecOps.

The post What is software composition analysis? appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/what-is-software-composition-analysis/feed/ 0
Break the silos: Enrich vulnerability findings with runtime context https://www.dynatrace.com/news/blog/enrich-vulnerability-findings-with-runtime-context/ https://www.dynatrace.com/news/blog/enrich-vulnerability-findings-with-runtime-context/#respond Thu, 08 Aug 2024 18:56:42 +0000 https://www.dynatrace.com/news/?p=65130 exposure management vs. vulnerability management; security and performance

Dynatrace delivers cross-container-registry security findings, visibility, orchestration, and prioritization.

The post Break the silos: Enrich vulnerability findings with runtime context appeared first on Dynatrace news.

]]>
exposure management vs. vulnerability management; security and performance

Dynatrace, powered by OpenPipeline™, offers a single pane of glass that consolidates container security findings from your existing DevSecOps tools, providing a comprehensive runtime context-based prioritization. It helps unveil blind spots by identifying and addressing coverage gaps throughout your Software Development Lifecycle (SDLC). With contextual operationalization, you can prioritize, visualize, and automate the response to container findings, all within the context of runtime operations while reducing alert noise in the SDLC. Moreover, seamless integration is achieved through out-of-the-box solutions that connect, transform, and map your findings data into a unified format using the Dynatrace Semantic Dictionary, ensuring a smooth and efficient security workflow.

The challenge we’re tackling arises from multicloud environments, where container images are dispersed across different registries and scanned by various vulnerability scanners, if at all. This leads to container security findings scattered across multiple products, complicating achieving unified visibility. The consequences include time spent navigating various platforms to collect data, difficulty prioritizing findings from disparate tools, coverage gaps with containers deployed unscanned, and excessive manual effort required to notify stakeholders and generate tickets.

Addressing this issue is crucial for cloud architects, who aim to establish a robust container scanning process within the SDLC, ensuring timely action on findings and prioritization of critical vulnerabilities. Cloud architects also seek to minimize manual efforts in managing each finding. Meanwhile, developers need prompt notifications about new critical vulnerabilities affecting containers that they can trust and take action on without being overloaded by false positives, which lead to alert fatigue and risk critical alerts being ignored. Developers should handle as few tickets as possible, focusing on those that yield the maximum return on investment (ROI).

Why Dynatrace?

Container security in DevSecOps typically focuses on the build phase, where scanners flag numerous critical vulnerabilities without considering runtime context, often resulting in false alarms. Dynatrace revolutionizes this process by utilizing its insights into active containers and their operational significance. This allows you to prioritize genuine threats impacting live containers. Additionally, Dynatrace observability data for running containers, enriched with security insights, offers a comprehensive view for more effective issue resolution. In essence, Dynatrace refines container security management by integrating runtime context, thus elevating the prioritization and handling of vulnerabilities.

Generic ingest security endpoint

Dynatrace introduces a generic ingest security endpoint, a versatile feature that enables data ingestion directly from any third-party security tool.

This capability opens up a range of use cases, such as:

  • Security findings visualization on custom dashboards tailored within Dynatrace.
  • In-depth analysis of security findings using tools like Notebooks and Security Investigator.
  • Automated orchestration of security findings through Dynatrace Workflows, enhancing efficiency and response times.
  • Contextualization of third-party security findings with Dynatrace runtime entities, offering a more integrated and coherent security management experience.

With the generic ingest security endpoint, you can ingest any data in an unstructured format. However, to truly gain the benefits of uniform prioritization, the ideal scenario is to have the data in a unified format. To this end, we’re also releasing Dynatrace Semantic Dictionary conventions for vulnerability findings.

The Dynatrace Semantic Dictionary for vulnerability findings is a key feature in Dynatrace that enables a consistent and uniform analysis of security data. Dynatrace uses this format in supported third-party integrations, but this same format can also be used to map data from custom integrations.

It allows for uniform prioritization of container vulnerability findings across different tools, which can be conveniently managed and visualized through Dynatrace sample dashboards.

Container findings dashboard screenshot in Dynatrace screenshot

Additionally, this format supports automated notification of vulnerability findings across security tools, utilizing Dynatrace sample workflows to enhance efficiency.

Slack notification workflow in Dynatrace screenshot

Lastly, the generic ingest security endpoint provides a comprehensive understanding of the security findings coverage within your runtime environment, ensuring that all potential vulnerabilities are accounted for and addressed. This unified approach ensures that security management is systematic and effective, catering to the complex needs of modern containerized environments.

Dynatrace supported integrations

Dynatrace supported security data ingest integrations streamline the setup process and ensure automatic Semantic Dictionary (SD) mappings, providing a seamless integration experience.

With the first integrations in place, the foundations are there to build additional native integrations into the Dynatrace Platform to support additional container registries and generic security standards. This will expand our capability to provide contextual information to observability and security events, irrespective of where they originate. So, look for future blog announcements on this topic.

What’s next

  • Watch the data-driven DevSecOps automation webinar, where we present and discuss the benefits of Dynatrace runtime context in operationalizing third-party security findings.
  • To discover which products, tools, and standards we support, please visit the Dynatrace Hub.
  • Explore the security data ingest capabilities and view the step-by-step setup guides for the supported integrations in Dynatrace Documentation.
  • For additional out-of-the-box integration requests, please contact your Dynatrace account manager or submit a request in the Dynatrace Community.
View the recording of our recent data-driven DevSecOps automation webinar.

The post Break the silos: Enrich vulnerability findings with runtime context appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/enrich-vulnerability-findings-with-runtime-context/feed/ 0
2024 CISO Report: The state of application security https://www.dynatrace.com/news/blog/2024-ciso-report-application-security/ https://www.dynatrace.com/news/blog/2024-ciso-report-application-security/#respond Tue, 02 Jul 2024 13:00:26 +0000 https://www.dynatrace.com/news/?p=64526 The state of application security 2024

A lack of understanding of security posture between security leaders (including CISOs) and top executives (C-suite) is putting organizations at greater risk of cyber threats.

The post 2024 CISO Report: The state of application security appeared first on Dynatrace news.

]]>
The state of application security 2024

DevSecOps teams struggle to align with top executives on implementing key security measures and practices. This communication gap leaves companies blind to security risks, especially as AI-powered cyber-attacks become more common. Organizations are failing to fight cyberattacks properly because their teams cannot effectively communicate and collaborate.

In this year’s CISO report, “The state of application security in 2024”, Dynatrace investigated these communication gaps to discover how a combined focus on complete system visibility and security can improve teamwork and decrease vulnerability to cyber threats.

Cybersecurity is a board-level issue

This report touches on the fact that cybersecurity has become a critical C-suite and boardroom concern. Data breaches can cripple organizations, leading to hefty fines, shattered trust, and lost market share. New regulations hold leaders personally responsible for cybersecurity preparedness.

Ignoring cybersecurity is no longer an option. While executives are involved in cybersecurity discussions, their focus often centers on meeting regulations and well-known threats like phishing or ransomware. This leaves a gap in understanding the hidden dangers, like weaknesses in application security, which can have a significant impact on day-to-day operations.

In this year’s CISO report, dive into exploring CISOs and the challenges they face in educating leadership about cybersecurity risks. The report reveals how a combined observability and security approach can be their key to engaging the C-suite and ultimately strengthening the organization’s overall cybersecurity posture.

Security leaders must replace technical jargon with precise messages about business risk

In today’s digital landscape, relentless attackers hunt for weaknesses to steal data. While C-suite awareness is rising, CISOs need better ways to communicate cyber threats and build a shared security culture. Many organizations are falling short of bringing security to the forefront of boardroom discussions. For example, only 65% of organizations regularly require CISOs to report to the CEO and board on their cybersecurity risk and compliance posture. 

While C-suite leaders are increasingly interested in cybersecurity, a technical knowledge gap often creates a disconnect. 83% of CISOs say their board of directors and CEO need to understand their security posture better so they can assess business risk and compliance requirements. 

Executives’ priorities may differ from the IT team’s and CISOs, leading to inconsistencies. To bridge this gap, CISOs need to elevate the cybersecurity conversation. Instead of focusing on technical details, they should translate threats into business risks the C-suite can understand. 70% of C-suite executives say security teams often talk in technical terms without providing business context and believe the CISO is responsible for bridging the gap.

Application security is an Achilles’ heel

Cloud applications are a major target for cyber attackers, with 72% of organizations suffering a related security incident in the past two years. This alarming trend has propelled application security to the forefront of risk management for both IT and business leaders.

CISOs haven’t identified a dependable method to providing the board with clear information and insight into their organization’s application security risk posture and weaknesses. In fact, the 2024 CISO Report found that 87% of CISOs say application security is a blind spot at the CEO and board level.

This leaves executives in the dark about potential threats, making it hard for them to make informed decisions to protect the company from disruptions, financial losses, and damaged reputation. 82% of CISOs say they urgently need to increase the visibility of their CEO and board into application security risk to enable more informed decisions to strengthen defenses.

The SolarWinds and MOVEit attacks brought to light a major weakness in the security industry: dependence on third-party software. Many organizations are now rethinking how they manage cyber risk from third-party vendors.

In fact, 50% of CISOs have not yet brought third-party software bills of materials (SBOMs) into their organization’s risk management practices. 

Just knowing a third-party vulnerability exists isn’t enough. Security teams need to move fast to understand the following:

  • How widespread is the issue in our systems?
  • How serious is the business risk?
  • Has it been exploited, and if so, what damage has it caused?

Additionally, it’s vital to share the learned insight with C-suite leaders and board members.

Automation across the DevSecOps lifecycle is central to risk management

As technology races forward, organizationss are turning to automation throughout the software development process (DevOps) to minimize security risks and meet regulations. According to the 2024 CISO Report, 71% of CISOs say DevSecOps automation is critical to ensuring reasonable measures have been taken to minimize application security risk.

To truly speed up innovation, companies need robust DevSecOps automation. But, only 11% of CISOs say their organization has mature DevSecOps automation practices.

DevSecOps automation streamlines development and security checks, catching vulnerabilities early and reducing human error. However, many organizations are still in the early stages, hindered by fragmented processes. Breaking down these silos is key to unlocking the full potential of DevSecOps automation.

Traditional tools and practices have limited value in the cloud-native, AI-driven threat landscape

Cloud complexity is breaking traditional security tools. Log-based security information and event management (SIEM) and extended detection and response (XDR) just cannot handle today’s dynamic cloud environments. This leaves security teams blind, unable to provide the data-driven insights CEOs and boards need to understand their cyber risk. 

The rise of AI is a double-edged sword. It fuels innovation for developers, but also arms attackers with tools to craft faster, more potent exploits. There is a 52% risk of cybercriminals using AI to create new vulnerability exploits faster and execute them on a wider scale. To stay ahead in this dynamic threat landscape, organizations urgently need to modernize their security practices.

79% of CISOs say vulnerability management and threat detection, investigation, and response can no longer be siloed processes. It’s vital now more than ever to have a single system that automates DevSecOps, uses AI to analyze massive data sets, and gives teams the end-to-end visibility they need to keep applications and data safe.

The 2024 CISO Report: How Dynatrace unites security and business leaders

Dynatrace® Application Security, built into the Dynatrace® platform, keeps your cloud-native applications, containers, and Kubernetes deployments safe. Here’s how:

  • Developers: Dynatrace automatically detects vulnerabilities in running applications, so teams can fix real problems and not waste time on false alarms.
  • Security teams: The platform continuously scans for threats and automatically blocks attacks in real-time, giving teams peace of mind.
  • C-suite: By combining observability and security data, the platform eliminates blind spots and provides confidence that applications are secure.

This report is based on a global survey of 1,300 CISOs and ten interviews with CEOs and CFOs in enterprises with over 1,000 employees. It was commissioned by Dynatrace and conducted by Coleman Parkes between March and April 2024. 

The post 2024 CISO Report: The state of application security appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/2024-ciso-report-application-security/feed/ 0
RSA guide 2024: AI and security are top concerns for organizations in every industry https://www.dynatrace.com/news/blog/rsa-guide-2024/ https://www.dynatrace.com/news/blog/rsa-guide-2024/#respond Thu, 02 May 2024 18:18:48 +0000 https://www.dynatrace.com/news/?p=63893 RSA guide, DevSecOps transformation and vulnerability management

AI is top of mind for security teams across every industry. As more organizations adopt generative AI and cloud-native technologies, IT teams confront more challenges with securing their high-performing cloud applications in the face of expanding attack surfaces. According to McKinsey’s State of AI in 2023 report, 40% of respondents said their organizations plan to […]

The post RSA guide 2024: AI and security are top concerns for organizations in every industry appeared first on Dynatrace news.

]]>
RSA guide, DevSecOps transformation and vulnerability management

AI is top of mind for security teams across every industry. As more organizations adopt generative AI and cloud-native technologies, IT teams confront more challenges with securing their high-performing cloud applications in the face of expanding attack surfaces. According to McKinsey’s State of AI in 2023 report, 40% of respondents said their organizations plan to increase their overall AI investment because of advancements in generative AI. But only 21% said their organizations have established policies governing employees’ use of generative AI technologies. Moreover, in addition to managing cloud spend and resource utilization, organizations must also now consider the cost and carbon impact of developing and using generative AI models.

Additionally, blind spots in cloud architecture are making it increasingly difficult for organizations to balance application performance with a robust security posture. To ensure optimal performance and security of cloud applications, organizations need a comprehensive view of their entire AI stack and cloud environment with a strong application security approach.

At this year’s RSA conference, taking place in San Francisco from May 6-9, presenters will explore ideas such as redefining security in the age of AI. Attendees will seek answers to two crucial questions: ‘How secure are we?’ and ‘How compliant are we?’, viewing these concerns through the lens of AI-powered solutions.

Our RSA 2024 news guide explores the ways AI and security are converging with observability and how this affects application security, vulnerability management, and threat detection. If you’re attending the conference, stop by the Dynatrace booth in South Expo space 561, and our Platinum Lounge in North Expo space 5157.

AI and security need to go hand-in-hand

Generative AI is becoming increasingly popular in organizations across nearly every industry. With the ability to generate new content—such as images, text, audio, and other data—based on patterns and examples taken from existing data, organizations are rushing to capitalize on the AI model. However, security remains a concern despite benefits such as faster development and improved productivity.

As organizations train generative AI systems with critical data, they must be aware of the security and compliance risks. In fact, according to the recent Dynatrace survey, “The state of AI 2024,” 95% of technology leaders are concerned that using generative AI to create code could result in data leakage and improper or illegal use of intellectual property. Therefore, these organizations need an in-depth strategy for handling data that AI models ingest, so teams can build AI platforms with security in mind. Check out the resources below for more information.

Generative AI thumbnail Generative AI poised to have impact by automating software development, report says – blog

According to ESG research, generative AI will change software development activities from quality assurance to CI/CD pipeline configuration.

Tech Transforms podcast image Tech Transforms podcast: It’s time to get familiar with generative AI – blog

Generative AI can unlock boundless innovation. In this blog, Carolyn Ford recaps her discussion with Tracy Bannon about AI in the workplace.

Abstract image representing AI innovation and digital transformation trends What is generative AI? – blog

Generative AI is an artificial intelligence model that can generate new content—text, images, audio, code—based on existing data.

The state of AI thumbnail The state of AI in 2024: Overcoming adoption challenges to unlock organizational success – blog

While AI offers many benefits, there are challenges and risks that organizations need to manage. Learn more about the state of AI in 2024.

Generative AI thumbnail Generative AI in IT operations – report

Read the study to discover how artificial intelligence (AI) can help IT Ops teams accelerate processes, enable digital transformation, and reduce costs.

Managing cloud application security risks to maximize cloud-native benefits

Organizations continue to embrace the cloud as the pace of digital transformation accelerates. Whether multicloud or hybrid, public or private, cloud-native architecture offers flexibility and agility to help organizations deliver software faster. But these benefits also become risks when it comes to cloud security.

Modern clouds are extensive and dynamic, which creates unprecedented complexity that can increase vulnerability to cyberattacks. And organizational silos, lack of end-to-end visibility, and lack of DevSecOps automation render many organizations ill-equipped to handle these risks. Recent research found that 76% of CISOs cite the limitations of security tools for real-time identification of risks in dynamic cloud-native architectures as a key challenge.

Cloud application security is crucial to every organization. As organizations introduce generative AI and continue to use open source code libraries, APIs, microservices, and more to innovate faster, the risk of attack compounds with more entry points for bad actors access critical data. One data breach or zero-day attack can have lasting implications, from revenue loss to reputation harm.

Organizations building out their cloud security strategy must prioritize an end-to-end view of their cloud, applications, microservices, and more to keep their data secure. Check out the following resources to learn more about managing cloud application security.

The state of application security in 2024 The state of application security in 2024 – report

Read the report to see how a unified observability and security strategy can help CISOs engage the wider C suite to improve the organization’s risk posture.

The state of observability in 2024 What is DevSecOps? And what you need to do it well – blog

DevSecOps connects three different disciplines: development, security, and operations. Learn how security improves DevOps.

Dynatrace Extensions 2.0; Dynatrace Perform 2024; AI data analysis Best practices for building a strong DevSecOps maturity model – blog

How can businesses effectively implement best practices to align with the evolving DevSecOps maturity model? Here’s what you need to know.

Plan, execute, and modernize a cloud migration strategy with Dynatrace What is cloud application security? – blog

Cloud application security is a combo of policies and processes that aim to reduce the risk of exposing cloud-based applications to threats.

Dynatrace Hyper-V extension Modern cloud application security done right – on-demand webinar

Watch our webinar about modern cloud application security done right.

hybrid cloud network Hybrid cloud infrastructure explained: Weighing the pros, cons, and complexities blog

While hybrid cloud infrastructure increases flexibility, it also introduces complexity. Learn its benefits—and challenges—and how to tame it.

Runtime Vulnerability Analysis Dynatrace Runtime Vulnerability Analysis now covers the entire application stack – blog

Dynatrace adds Go vulnerability analysis on top of Java, .NET, Node.js, and PHP vulnerability analysis. Automatic runtime vulnerability detection and AI-powered risk assessment further enable DevSecOps automation.

Converging security and observability

Maintaining software security is becoming increasingly difficult as the rising complexity of cloud-native environments and generative AI create more risk for undetected vulnerabilities to infiltrate applications. Despite this risk, organizations face mounting pressure to innovate faster and on a larger scale. However, the 2024 CISO report indicates traditional log-based security information and event management (SIEM) and extended detection and response (XDR) solutions have limited value in the cloud-native, AI-driven threat landscape. Indeed, more than 75% of CISOs cite blind spots and limitations of SIEM and XDR for automating responses and addressing risks in real time.

As a solution, organizations are converging observability and security data, giving DevSecOps teams end-to-end visibility into application security issues for real-time answers at scale.

Observability is critical for monitoring application performance, infrastructure, and user behavior within hybrid, microservices-based environments. Likewise, with observability of systems that run AI models, organizations can predict and control costs, performance, and data reliability.

To ensure application security in these AI-enabled, hybrid cloud environments, organizations must integrate security into an observability framework. Monitoring potential security threats, such as unauthorized access, malware infections, or data exfiltration, is critical, especially as workloads are distributed across multiple environments.

Together, observability and security data make teams more effective in identifying and responding to critical security incidents as quickly as possible, resulting in a better security posture. Check out the following resources to learn more.

Observability vs Monitoring Dynatrace accelerates business transformation with new AI observability solution – blog

AI adoption is imperative to remain competitive, but its benefits aren’t straightforward. AI observability accelerates AI benefits.

Database observability AI for Observability: An Explainer – video

In this video, Dynatrace explains why AI is critical to observability.

observability for relational databases Dynatrace for AI Observability: OpenAI, TensorFlow and more – observability clinic

In this Observability Clinic, learn how to use Dynatrace to monitor the usage of AI APIs (such as OpenAI, TensorFlow, or others), identify costs, and diagnose and optimize performance, and costs.

Causal AI use cases for modern observability; exploratory data analytics Security by design enhanced by unified observability and security – blog

Business spend management company Soldo uses unified observability and security to implement efficient security-by-design and DevSecOps practices.

The importance of secure and compliant workloads

Given the complexity of today’s multicloud and hybrid cloud environments, leveraging observability and security data becomes paramount for understanding an organization’s security posture. This understanding is essential for effectively assessing business risk and compliance requirements, particularly given the ever-changing regulations and dynamic nature of cloud infrastructures. Regulatory compliance is growing in importance as cybercriminals leverage AI to create new exploits faster, while development teams must use these same capabilities to accelerate software delivery with less manual oversight.

As compliance is often a moving target, organizations are increasingly turning to automation across their DevOps, security, and compliance teams. This automation minimizes risk and maintains regulatory compliance effectively. In fact, 83% of respondents to the 2024 CISO report say DevSecOps automation will be essential to their ability to stay on top of emerging regulations.

Automation empowers organizations to proactively manage risks such as misconfigurations and compliance violations, automating remediation and managing the exposure risk of vulnerabilities introduced by AI. RSA attendees need the right tools to determine their level of security and compliance.

To effectively prevent exploits and compliance violations, understanding the organization’s attack surface is crucial—the sum of all potential entry points for unauthorized access, spanning hardware, software, and human factors. While absolute security is unattainable, acknowledging the expansiveness of the attack surface is the initial step toward fortification. Dive into the following resources to learn more.

Charts thumbnail Attack surface checklist for VMware environments – checklist

Our attack surface reduction checklist will guide your organization in identifying and mitigating vulnerabilities in your digital assets.

What is a service mesh? Achieving audit-readiness for security standards compliance in modern IT environments – guide

This resource outlines of some of the more common security standards, their associated pain points, and ways for CISOs, CIOs, and their Security and Operations teams to comply with these standards to maintain secure private, hybrid, and public cloud environments.

The post RSA guide 2024: AI and security are top concerns for organizations in every industry appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/rsa-guide-2024/feed/ 0
How observability, application security, and AI enhance DevOps and platform engineering maturity https://www.dynatrace.com/news/blog/observability-security-ai-enhance-devops-platform-engineering/ https://www.dynatrace.com/news/blog/observability-security-ai-enhance-devops-platform-engineering/#respond Thu, 18 Apr 2024 15:23:15 +0000 https://www.dynatrace.com/news/?p=63708 Data privacy by design, CrowdStrike

DevOps and platform engineering are essential disciplines that provide immense value in the realm of cloud-native technology and software delivery. However, these practices cannot stand alone. Rather, they must be bolstered by additional technological investments to ensure reliability, security, and efficiency. One of these key investments includes observability. Observability of applications and infrastructure serves as […]

The post How observability, application security, and AI enhance DevOps and platform engineering maturity appeared first on Dynatrace news.

]]>
Data privacy by design, CrowdStrike

DevOps and platform engineering are essential disciplines that provide immense value in the realm of cloud-native technology and software delivery. However, these practices cannot stand alone. Rather, they must be bolstered by additional technological investments to ensure reliability, security, and efficiency. One of these key investments includes observability.

Observability of applications and infrastructure serves as a critical foundation for DevOps and platform engineering, offering a comprehensive view into system performance and behavior. It goes beyond traditional monitoring—metrics, logs, and traces—to encompass topology mapping, code-level details, and user experience metrics that provide real-time insights. This real-time awareness enables teams to rapidly detect and resolve issues: both indispensable capabilities for maintaining the agility and reliability that are central to DevOps and platform engineering processes.

Moreover, observability is the launchpad for maturing DevOps and platform engineering postures. Recent research found that 71% of organizations actively use observability data and insights to drive automation decisions and improvements in DevOps workflows. The technology has also enabled 78% of organizations to automate release validation and 74% of organizations to identify bottlenecks and automate delivery pipelines.

Observability and DevSecOps: Shifting left

Observability empowers teams to embrace a shift-left approach. The deep visibility and insights that observability provides allow teams to take proactive measures early in the software development life cycle (SDLC).

Shifting left is an approach that includes software quality, performance, and security testing as a part of the SDLC. These practices ensure optimal software functioning and the quick resolution of issues before they proliferate. This practice has become integral to DevSecOps, which fosters a culture of shared responsibility where all stakeholders play a role in maintaining the integrity of the software and infrastructure.

Without observability, a DevSecOps approach becomes increasingly difficult to execute. A lack of insights and visibility into a digital environment leads to inefficient management and resolution of vulnerabilities, attacks, and threats. Conversely, with observability providing a clear explanation of the root cause or origin of security issues, teams can immediately begin addressing issues. Ultimately, observability-powered insights preserve resources and enable DevSecOps at scale.

Observability and platform engineering: Unlock DevOps efficiency

Platform engineering teams also benefit immensely from observability. Beyond simply monitoring infrastructure health and diagnosing issues, observability can assist platform engineers by providing key insights for capacity management, performance optimization, compliance, and other critical aspects of platform maintenance and provisioning.

For example, an observability solution can track and analyze usage data to help engineers understand how and when to scale resources based on system demand. Incorporating observability into software delivery practices enables platform engineering and DevSecOps teams alike to execute high-importance tasks and responsibilities with confidence.

However, observability remains only one piece of the puzzle when it comes to ensuring the success of both DevSecOps and platform engineering.

The role of AI in DevSecOps

When integrated into DevSecOps, artificial intelligence (AI) helps teams transform data into an actionable asset for automating workflows across development, security, and operations. Combining causal AI with machine learning-based algorithms analyzes vast datasets in real-time and provides practitioners with precise answers driven by root cause analysis.

This capability is monumental for DevSecOps teams. AI helps provide in-depth context around system issues, anomalies, and other events instead of merely identifying them. Without this level of context, datasets become exponentially difficult to analyze and use for any effective or efficient DevSecOps processes. Causal AI also bolsters DevSecOps by allowing for early anomaly and vulnerability detection, rapid issue resolution, and system performance optimization.

Informed by past performances, predictive AI paired with observability forecasts future system needs and offers predictive insights. This fosters a proactive approach to system health and maintenance. These capabilities enable technical teams to minimize disruptions, cyberattacks, and downtime by identifying potential issues before they escalate.

AI strengthens the “Sec” in DevSecOps by not only offering continuous real-time insights into system vulnerabilities but also providing intelligence and answers regarding future potential vulnerabilities.

The role of AI in platform engineering

For platform engineers, AI creates an environment where its capabilities converge harmoniously with observability and security.

AI-driven insights optimize resource allocation, bolster internal developer platform scalability, and introduce autonomous operations for platform engineers. Autonomous operations can adapt to changing circumstances within an environment and automatically self-adjust and execute necessary workflows. For example, AI enables intelligent resource allocation for the optimal scaling of platform infrastructure without the need for any human intervention.

Automated rollbacks or rollouts based on observability data also become a reality with AI.  These automated actions enhance system reliability and overall platform resilience. The introduction of AI in platform engineering marks a new horizon for the discipline, enhancing its efficiency, efficacy, and security like never before.

Observability, security, and AI: Better together

Together, the synergy of observability, security, and AI redefines DevOps and platform engineering. These three capabilities are a recipe for accelerating software delivery and fortifying tech stacks and applications against emerging security challenges. This combination is essential for organizations that are navigating the complex terrain of modern software development and infrastructure management.

Observability, security, and AI play a crucial role in strengthening DevSecOps and platform engineering. Each component offers myriad benefits, including accelerating software delivery, enhancing software resilience, reducing manual tasks, improving developer productivity and satisfaction, and more.

Dynatrace offers a unified solution containing each of these key ingredients for DevSecOps and platform engineering success. With end-to-end observability powered by hypermodal AI and built-in security analytics and security protection, the Dynatrace platform empowers organizations with the capabilities they need to unlock agility, efficiency, and scale.

Discover more about observability in DevOps and platform engineering maturity in the free 2024 DevOps Automation Pulse report.

The post How observability, application security, and AI enhance DevOps and platform engineering maturity appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/observability-security-ai-enhance-devops-platform-engineering/feed/ 0
Boost DevOps maturity with observability and a data lakehouse https://www.dynatrace.com/news/blog/boost-devops-maturity-with-a-data-lakehouse/ https://www.dynatrace.com/news/blog/boost-devops-maturity-with-a-data-lakehouse/#respond Fri, 09 Jun 2023 08:03:35 +0000 https://www.dynatrace.com/news/?p=58154 DevOps infinity loop for DevOps maturity

In a world driven by macroeconomic uncertainty, businesses increasingly turn to data-driven decision-making to stay agile. That’s especially true of the DevOps teams who must drive digital-fueled sustainable growth. They’re unleashing the power of cloud-based analytics on large data sets to unlock the insights they and the business need to make smarter decisions. From a […]

The post Boost DevOps maturity with observability and a data lakehouse appeared first on Dynatrace news.

]]>
DevOps infinity loop for DevOps maturity

In a world driven by macroeconomic uncertainty, businesses increasingly turn to data-driven decision-making to stay agile.

That’s especially true of the DevOps teams who must drive digital-fueled sustainable growth. They’re unleashing the power of cloud-based analytics on large data sets to unlock the insights they and the business need to make smarter decisions. From a technical perspective, however, cloud-based analytics can be challenging. Data volumes are growing all the time, making it harder to orchestrate, process, and analyze to turn information into insight. Cost and capacity constraints for managing this data are becoming a significant burden to overcome.

All of these factors challenge DevOps maturity. Teams need a technology boost to deal with managing cloud-native data volumes, such as using a data lakehouse for centralizing, managing, and analyzing data.

Data scale and silos present challenges to DevOps maturity

DevOps teams often run into problems trying to drive better data-driven decisions with observability and security data. That’s because of the heterogeneity of the data their environments generate and the limitations of the systems they rely on to analyze this information. This data complexity is actually thwarting the capacity of many organizations to mature in their DevOps practices.

What is DevOps maturity?

DevOps maturity is a model that measures the completeness and effectiveness of an organization’s processes for software development, delivery, operations, and monitoring. Many organizations, including the global advisory and technology services provider, ICF, describe DevOps maturity using a DevOps maturity model framework. Organizations generally measure DevOps using a scale ranging from no DevOps practices at all to continuous delivery with full automation. When extended to include application security practices, DevOps becomes DevSecOps and includes security-focused criteria, such as security by design and making security a critical release criterion.

Increasing an organization’s DevOps maturity is a key goal as teams adopt more cloud-native technologies, which simultaneously makes their environments more scalable and feature-rich but also more complex.

Cloud complexity leads to data silos

Silos

Most organizations are battling cloud complexity. Research has found that 99% of organizations have embraced a multicloud architecture. On top of these cloud platforms, they’re using an array of observability and security tools to deliver insight and control—seven on average. This results in siloed data that is stored in different formats, adding further complexity. What’s more, 55% of organizations admit they’re forced to make tradeoffs among quality, security, and user experience to meet the need for rapid transformation.

This challenge is exacerbated by the high cardinality of data generated by cloud-native, Kubernetes-based apps. The sheer number of permutations can break traditional databases.

Many teams look to huge cloud-based data lakes, repositories that store data in its natural or raw format, to help teams centralize disparate data. Others adopt a data lake, which enables teams to keep as much raw data as they want to at a relatively low cost until analysts find a use for it.

When it comes to extracting insight, however, teams need to transfer data to a warehouse technology so technologies can aggregate and prepare it for analysis. Various teams usually end up transferring the data again to another warehouse platform, so they can run queries related to their specific business requirements. All these steps and stages slow down processes, are error-prone, and introduce additional security risks.

When data storage strategies become problematic to DevOps maturity

Data warehouse-based approaches add cost and time to analytics projects.

With a data warehouse, teams may need to manually define tens of thousands of tables to prepare data for querying. The data warehouse approach also requires a multitude of indexes and schemas to retrieve and structure the data and define the queries that teams will ask of it. That’s a lot of effort.

Any user who wants to ask a new question for the first time will need to start from scratch to redefine all those tables and build new indexes and schemas, which creates a lot of manual effort. This can add hours or days to the process of querying data, meaning insights are at risk of being stale or are of limited value by the time teams surface them.

The more cloud platforms, data warehouses, and data lakes an organization maintains to support cloud operations and analytics, the more money they will need to spend. In fact, the storage space required for the indexes used to support data retrieval and analysis may end up costing more than the data storage itself.

Teams will incur further costs if they need technologies to track where their data is and to monitor data handling for compliance purposes. Frequently moving data from place to place may also create inconsistencies and formatting issues, which could affect the value and accuracy of any resulting analysis.

Combining data lakes and data warehouses

How a data lakehouse boosts DevOps maturity

A data lakehouse approach combines the capabilities of a data warehouse and a data lake to solve the challenges associated with each architecture, thanks to its enormous scalability and massively parallel processing capabilities. With a data lakehouse approach to data retention, organizations can cope with high-cardinality data in a time- and cost-effective manner, maintaining full granularity and extra-long data retention to support instant, precise, and contextual predictive analytics.

But to realize this vision, a data lakehouse must be schemaless, indexless, and lossless.

  • Schema-free means users don’t need to predetermine the questions they want to ask of data, so new queries can be raised instantly as the business need arises.
  • Indexless means teams have rapid access to data without the storage cost and resources needed to maintain massive indexes.
  • Lossless means technical and business teams can query the data with its full context in place, such as interdependencies between cloud-based entities, to surface more precise answers to questions.

Unifying observability data to promote DevOps maturity

Let’s consider the key types of observability data that any lakehouse must be capable of ingesting to support the analytics needs of a modern digital business.

three pillars of observability

Logs

Logs are the highest volume and often most detailed data that organizations capture for analytics projects or querying. As a result, logs provide vital insights to verify new code deployments for quality and security, identify the root causes of performance issues in infrastructure and applications, investigate malicious activity such as a cyberattack, and support various ways of optimizing digital services.

However, logs without context very often become more noise teams have to sift through to find what matters.

Metrics

Metrics are the quantitative measurements of application performance or user experience that teams can calculate or aggregate over time to feed into observability-driven analytics.

The challenge is that aggregating metrics in traditional data warehouse environments can create a loss of fidelity and make it more difficult for analysts to understand the relevance of data.

There’s also a potential scalability challenge with metrics in the context of microservices architectures. As digital services environments become increasingly distributed and are broken into smaller pieces, the sheer scale and volume of the relationships among data from different sources is too much for traditional metrics databases to capture. Only a data lakehouse can handle such high-cardinality data without losing fidelity.

Traces

Traces are the data source that reveals the end-to-end path a transaction takes across applications, services, and infrastructure. With access to the traces across all services in their hybrid and multicloud technology stack, developers can better understand the dependencies they contain and more effectively debug applications in production.

Cloud-native architectures built on Kubernetes, however, greatly increase the length of traces and the number of spans they contain, as there are more hops and additional tiers, such as service meshes, to consider. Organizations can architect a data lakehouse such that teams can better track these lengthy, distributed traces without losing data fidelity or context.

Accelerate DevOps maturity by going beyond metrics, logs and traces

While metrics, logs, and traces can tell you what happened, they can’t always tell you why. For that, you need additional insight and context to make analytics more precise.

If DevOps teams can build a real-time topology map of their digital services environment and feed this data into a data lakehouse alongside metrics, logs, and traces, it can provide critical context about the dynamic relationships between application components across all tiers. With context from the Dynatrace observability and security analytics platform on data in the Grail data lakehouse, DevOps teams have centralized situational awareness that enables them to raise queries about what’s happening in their multicloud environments. With this access, teams can better understand how to optimize systems more effectively, which in turn helps them automate DevOps processes. Such access also helps DevSecOps teams to build security into the software delivery lifecycle and quickly detect, investigate, and remediate the impact of security incidents.

Observability data can also provide insights into user session data, which teams can use to gain a better understanding of how customers interact with application interfaces. This insight helps teams to identify how an issue is affecting users and pinpoints what optimizations the system needs and where.

As digital services environments become more complex and data volumes explode, observability is certainly becoming more challenging. However, it’s also never been more critical. With a data lakehouse-based approach, DevOps teams can finally turn petabytes of high-fidelity data into actionable intelligence without breaking the bank or becoming burnt out in the effort.

To learn more about the Dynatrace Grail data lakehouse and how it can help accelerate DevOps, join us for the on-demand webinar, Get to know Dynatrace: Grail edition.

The post Boost DevOps maturity with observability and a data lakehouse appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/boost-devops-maturity-with-a-data-lakehouse/feed/ 0
What is DevSecOps? And what you need to do it well https://www.dynatrace.com/news/blog/what-is-devsecops/ https://www.dynatrace.com/news/blog/what-is-devsecops/#respond Thu, 19 Jan 2023 09:34:38 +0000 https://www.dynatrace.com/news/?p=42306 DevSecOps, What is DevSecOps

DevSecOps is the seamless integration of security throughout the software development and deployment lifecycle. Like DevOps, DevSecOps is as much about culture and shared responsibility as it is about any specific technology or techniques. Also, like DevOps, the goal of DevSecOps is to release secure software faster, and detect and respond to security flaws (like vulnerabilities) […]

The post What is DevSecOps? And what you need to do it well appeared first on Dynatrace news.

]]>
DevSecOps, What is DevSecOps

DevSecOps is the seamless integration of security throughout the software development and deployment lifecycle. Like DevOps, DevSecOps is as much about culture and shared responsibility as it is about any specific technology or techniques. Also, like DevOps, the goal of DevSecOps is to release secure software faster, and detect and respond to security flaws (like vulnerabilities) faster and more efficiently.

That’s a lot to digest. In the sections below, I’ll unpack each of those thoughts so you can better understand how your organization can move towards a fuller embrace of DevSecOps.

What is DevSecOps?

DevSecOps is a tactical trifecta that connects three disciplines: development, security, and operations. The goal is to seamlessly integrate security into your continuous integration and continuous delivery (CI/CD) pipeline in both pre-production (dev/test/staging) and production (ops) environments. Let’s take a look at each discipline and the role it plays in delivering better, more secure software faster.

DevSecOps

Development

Development teams create and iterate on new software applications. This includes:

  • Custom, built-in-house apps designed for a single, specific purpose
  • API-driven connections that bridge the gap between legacy systems and new services
  • Apps that leverage open-source code to accelerate the development process

Modern development practices rely on agile models that prioritize continuous improvement versus sequential, waterfall-type steps. If developers work in isolation without considering operations and security, new applications or features may introduce operational issues or security vulnerabilities that can be expensive and time-consuming to address.

Operations

Operations refers to the processes of managing software functionality throughout its delivery and use life cycle, including:

  • Monitoring system performance
  • Repairing defects
  • Testing after updates and changes
  • Tuning the software release system

DevOps has gained ground in recent years as a way to combine key operational principles with development cycles, recognizing that these two processes must coexist. Siloed post-development operations can make it easier to identify and address potential problems, but this approach requires developers to circle back and solve software issues before they can move forward with new development. This creates a complex road map instead of a streamlined software workflow.

Implementing operations parallel to software development processes allows organizations to reduce deployment time and increase overall efficiency.

Security

Security refers to all the tools and techniques needed to design and build software that resists attack, and to detect and respond to defects (or actual intrusions) as quickly as possible.

Historically, application security has been addressed after development is completed, and by a separate team of people — separate from both the development team and the operations team. This siloed approach slowed down the development process and the reaction time.

Also, security tools themselves have historically been siloed. Each application security test looked only at that application, and often only at the source code of that application. This made it hard for anyone to have an organization-wide view of security issues, or to understand any of the software risks in the context of the production environment.

By making application security part of a unified DevSecOps process, from initial design to eventual implementation, organizations can align the three most important components of software creation and delivery.

How DevSecOps differs from the “waterfall” approach

Traditional software development is often called the waterfall approach because each stage of the process — design, development, testing, and final approval — is separate and one stage can start only when the previous one is completed.

In most organizations, waterfall has largely been replaced by Agile methodology, which separates a project into sprints. But security tests are typically delayed until the end of the sprint—waterfall style! This delay forces developers to shift gears and backtrack their thinking to remediate security problems. This “context switching” is error-prone and time-consuming.

DevSecOps, on the other hand, enables security testing to occur seamlessly and automatically in the same general timeframe that other development and testing are happening. For example, developers can run security tests in the development stage in near-real-time to prevent wasting time context switching. They can also run security tests in the production phase in near-real time so they can immediately discover all instances of a vulnerability running in production soon after the vulnerability is announced.

DevSecOps vs. DevOps

DevOps is a methodology that brings together development, operations, and security teams to shorten the software development lifecycle.

DevSecOps takes this further by integrating security into the DevOps process from the start. It ensures that security is not an afterthought but a top priority throughout the entire software development process.

Here are some critical differences between DevSecOps and DevOps:

  • DevSecOps involves a broader range of stakeholders, including security teams.
  • DevSecOps requires a more rigorous approach to security testing and scanning.
  • DevSecOps requires a stronger focus on compliance with security regulations.
DevOps vs. DevSecOps
DevOps vs. DevSecOps

Benefits of DevSecOps

DevSecOps can improve the overall security of software with benefits such as: 

  • Increased security: By integrating security into the DevOps process, DevSecOps can help to prevent security vulnerabilities from being introduced into production systems.
  • Reduced risk: Reduce the risk of security and data breaches.
  • Improved compliance: Automate processes that will help enforce compliance with security regulations.
  • Improved efficiency: Improve the efficiency of the software development process by automating security checks and scans.
  • Improved compliance: Help organizations to comply with security regulations.
  • Increased collaboration: Improve collaboration between development, operations, and security teams, through a shared sense of responsibility
  • Faster time to market: Speed up the software development process by automating security checks and scans.
  • Improved quality: Improve software quality by catching security vulnerabilities early in the development process.
  • Improved risk management: Help organizations identify and address security risks more effectively.
  • Increased customer satisfaction: Increase customer satisfaction by delivering secure and reliable software.
  • Reduced costs: Reduce the costs associated with security and data breaches.
  • Improved visibility: Help organizations gain visibility into their security posture to quickly identify and address security risks.

Challenges in implementing DevSecOps

Implementing DevSecOps has some challenges.

The first challenge involves people and culture. You might find it necessary to retrain the people on your DevOps teams so they understand security best practices and know how to operate your new security tooling. In terms of culture, your teams need to truly adopt the mindset that they’re responsible for the security of the software they build and deploy, just as much as they’re responsible for feature, function, and usability.

A second challenge is finding the right security tooling and integrating it into your DevOps workflow. The more automated your DevSecOps tooling is, and the more integrated it is with your CI/CD pipeline, the less training and culture-shifting you need to do.

In many cases, however, choosing a more automated version of the security tools you have been using for years is not the right answer. Why? Because your development environment has likely changed drastically over the past few years. The typical modern software application is comprised of 70% open source software. Unfortunately, accurately detecting vulnerabilities in open source software is not something traditional security tools were designed to do.

Similarly, modern cloud-native applications run in containers that may spin up and down very quickly. Traditional security tools designed for production environments—even those that now advertise themselves as “cloud security” tools—can’t accurately assess the risks of applications running in containers.

Want to learn more about DevOps?

Streamline the way IT operates and enterprises grow with observability and AIOps. Read our DevOps eBook – A Beginners Guide to DevOps Basics

Top traits of successful DevSecOps practices

If the goals of DevSecOps are 1) to release better software faster, and 2) to detect and respond to software flaws in production faster and more efficiently, what are the capabilities you should cultivate to achieve them? What key performance indicators (KPIs) should you use to measure the quality of your DevSecOps initiatives?

Here are the most important characteristics of a strong DevSecOps program:

1. Security awareness and ownership

Everyone involved with software development and operations should be aware of security fundamentals and have a sense of ownership in the results. The philosophy “security is everyone’s responsibility” should be a part of your organization’s DevSecOps culture.

2. Automated operation

To align with the high degree of automation present in most CI/CD tool chains, your DevSecOps security tooling needs to run with complete automation — no manual steps, no configurations, no custom scripts. It needs to provide information about the security of your application even when your developers might want to avoid running a security test for fear that it would slow them down.

3. Fast results

Your security tooling needs to produce results in near-real-time because speed is a high priority for modern DevOps teams.

4. Wide scope

Your security tooling should function across all types of compute environments including containers, Kubernetes, serverless, PaaS, hybrid clouds, and multiclouds. No blind spots. No silos.

Also, your security tooling needs to provide information about all types of applications — including applications that are mostly based on open-source software, as well as applications that you purchased from a third party, for which you have no source code at all.

5. Shift-left and shift-right

Much has been written about the benefits of conducting security assessments early in the software development lifecycle (“shift left”), before vulnerabilities find their way into production. However, DevSecOps also needs to extend to production environments (“shift right”) for four reasons:

  • Production is where most attacks happen.
  • Scanning source code can’t give you the same rich insights you can get by observing the application when it is running in production.
  • Some applications you run in production may not have run through your dev environment, so they never had a chance to be scanned by security tools in your dev environment.
  • To detect new zero-day vulnerabilities, you need to monitor existing applications in your production environment.

6. Accuracy

Automation is important, but you also need accuracy and quality. In our recent CISO survey, 77% of respondents said most security alerts and vulnerabilities they receive from their current security tools are false positives that don’t require action, because they’re not actual exposures.

To achieve DevSecOps efficiency, you need security tests that eliminate false positives and false negatives, and provide useful information to your remediation team.

7. Developer acceptance

Everything about your DevSecOps program needs to be accepted by the people who will be developing the software, running the tests, scanning for vulnerabilities, and remediating the security issues that are found.

Implementing DevSecOps Best Practices

The seamless integration of development, security, and operations has become critical. To achieve this harmonious balance, adopt these DevSecOps best practices to foster a culture of collaboration, continuous improvement, and heightened security awareness.

  1. Automated Security Testing:

Automated security testing is the backbone of DevSecOps. Regular security scans, such as vulnerability assessments, penetration testing, and security code reviews, should seamlessly integrate into the development pipeline. Automated tools identify vulnerabilities and help prioritize them based on severity, enabling development teams to promptly address critical issues.

  1. Continuous Monitoring and Feedback:

DevSecOps emphasizes continuous monitoring of deployed applications. Real-time monitoring helps identify and mitigate security threats in production, allowing for immediate response and mitigation. Teams should leverage SIEM systems and APM tools to gain holistic insights into application behavior.

  1. Infrastructure as Code (IaC) Security:

As infrastructure becomes more code-driven, IaC security becomes crucial. Implementing security practices within infrastructure code helps maintain consistent security configurations and reduces the risk of misconfigurations that could lead to breaches. Regularly audit and validate your infrastructure code for adherence to security standards.

  1. Collaboration and Training:

DevSecOps thrives on collaboration between development, security, and operations teams. Foster a culture of open communication and knowledge sharing. Additionally, provide regular security awareness training to developers, helping them understand the latest threats and mitigation techniques.

  1. Immutable Infrastructure:

Consider adopting immutable infrastructure practices where deployed components are treated as disposable entities. When detected, vulnerabilities can be addressed by replacing the entire component with an updated version. This approach reduces the attack surface and simplifies patch management.

Automation for DevSecOps

Automation lies at the heart of DevSecOps, acting as a force multiplier for development and security teams. It accelerates the deployment pipeline, reduces manual errors, and enforces consistent security controls throughout the development lifecycle. DevSecOps and automation are two key components of a secure software development process. Automation can help to improve the efficiency and effectiveness of security checks and scans and can help to prevent security vulnerabilities from being introduced into production systems.

A platform for all stages of DevSecOps

To respond to the need for application security that spans both production (shift-right) and pre-production (shift-left), many organizations are choosing to leverage the security information that is available from their existing application performance monitoring platform.

With the Dynatrace Software Intelligence Platform’s Application Security module, the same OneAgent that provides deep observability for application performance also provides deep observability for security issues. The Dynatrace OneAgent provides rich information, such as which libraries are called, how they’re used, whether a process is exposed to the internet and whether an application or service interacts with sensitive “crown jewel” type data. This is much richer information than traditional security scanners or behavioral anomaly tools can deliver. By combining security with contextual awareness and observability, Dynatrace Application Security delivers the accuracy and precision teams need to achieve their DevSecOps goals.

What is DevSecOps? It’s the seamless integration of security testing and protection throughout the software development and deployment lifecycle. With real-time security intelligence across pre-production and production environments, and with AI-driven recommendations and automation that can help manage every stage of the DevOps workflow, your teams can produce better, higher-performing, more secure software faster and with less effort.

The post What is DevSecOps? And what you need to do it well appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/what-is-devsecops/feed/ 0
DevOps observability: A guide for DevOps and DevSecOps teams https://www.dynatrace.com/news/blog/devops-observability-guide-for-devops-and-devsecops/ https://www.dynatrace.com/news/blog/devops-observability-guide-for-devops-and-devsecops/#respond Wed, 18 Jan 2023 18:03:46 +0000 https://www.dynatrace.com/news/?p=55775 The benefits of unified observability and security for BizDevSecOps use cases

DevOps observability delivers answers that enable DevOps and DevSecOps teams to automate and innovate at speed while increasing quality, reliability, and application security. Learn how organizations can use DevOps observability to deliver better software faster.

The post DevOps observability: A guide for DevOps and DevSecOps teams appeared first on Dynatrace news.

]]>
The benefits of unified observability and security for BizDevSecOps use cases

As organizations accelerate innovation to keep pace with digital transformation, DevOps observability is becoming a critical key to success for DevOps and DevSecOps teams. However, getting reliable answers from observability data so teams can automate more processes to ensure speed, quality, and reliability can be challenging.

Indeed, the pressure to digitally transform is increasing. According to recent Dynatrace research, organizations expect to make software updates 58% more frequently in the coming year. This drive for speed has a cost: 22% of leaders admit they’re under so much pressure to innovate faster that they must sacrifice code quality.

DevOps and DevSecOps practices help organizations release software faster and more frequently, paving the way for digital transformation. In fact, 98% of DevOps leaders say that extending DevOps to more applications is key for digital transformation and customer experience, and 41% of applications will be fully DevOps enabled by 2023.

However, DevOps teams are still held back by siloed and frequently conflicting data insights. In addition, 27% of IT and DevOps teams’ time is invested in manual CI/CD tasks such as detecting code quality issues, which reduces time spent on innovation.

This DevOps observability guide explores the benefits of automatic and intelligent observability for DevOps and DevSecOps complexity. From site reliability engineering to service-level objectives and DevSecOps, these resources focus on how organizations are using these best practices to innovate at speed without sacrificing quality, reliability, or security.

DevOps and SRE: Methodologies that are transforming software development with the help of DevOps observability

DevOps is a software delivery methodology that comprises flexible practices and processes to create and deliver applications and services, ultimately closing the gap between software development and IT operations. Rather than a technology, DevOps is a tactical approach to application development.

Site reliability engineering (SRE) is a software operations methodology that enables organizations to create highly reliable and scalable applications. SRE applies software engineering principles to operations and infrastructure processes. This methodology aims to improve software system reliability using several key categories such as availability, performance, latency, efficiency, capacity, and incident response. Site reliability engineers, or SREs, lead these efforts.

DevOps and SRE are fundamentally transforming software development today. With DevOps observability, they can also complement one another. While DevOps primarily centers on software development and delivery, SRE typically applies DevOps principles to enhance operational processes. Organizations that already use DevOps practices may find it beneficial to also incorporate SRE principles. Organizations that are new to both practices will want to adopt a strategy that incorporates both.

what is software composition analysis DevOps, DevSecOps infinity loop, Eliminate silos, improve cross-team collaboration, and release better software faster with DevOps monitoring – product page

DevOps is a tactical approach to creating and delivering software designed to close the gap between development and IT operations. Leveraging observability, AI, and automation on a single platform helps Dev and Ops teams collaborate more efficiently, accelerate CI/CD pipelines, and improve code quality.

DevOps, What is DevOps What is DevOps? Unpacking the purpose and importance of an IT cultural revolution – blog

Combining operations and development to deliver continuous software improvement can reduce complexity and improve application output. Learn more about DevOps and best practices to achieve it at scale.

Gene Kim Gene Kim offers an expert view on DevOps and explains how to maximize success – blog

Gene Kim joined us at Perform 2021, where he offered his own unique take and insight into DevOps from a career spanning 22 years.

Part 1: How Dynatrace and GitHub help you deliver better software faster SRE vs. DevOps: The differences—and similarities – blog

DevOps is focused on optimizing software development and delivery, and SRE is focused on operations processes. Both practices live by the same overarching tenets. Here we’ll cover the purpose of each and explore how they interact.

Bringing business together with DevOps metrics from Dynatrace What is SRE (site reliability engineering)? And what do site reliability engineers do? – blog

Modern software development requires bridging the increasing demands of Development and Operations without conflict. Site Reliability Engineering is a growing discipline and role that fills in the gaps between Dev and Ops.

CI/CD and SLOs: Processes that help automate the SDLC with DevOps observability

Continuous integration and continuous delivery (CI/CD) is an essential DevOps practice that helps organizations balance speed and reliability when innovating. While continuous integration streamlines the internal process of developing a new application, continuous delivery guarantees that the code is ready to deploy.

Additionally, DevOps teams can automate their CI/CD pipelines to accelerate the various stages of the software development lifecycle (SDLC). While DevOps teams are frequently less stressed due to the structure and predictability of CI/CD, customers can be sure that they’ll always have the latest and most up-to-date features. A CI/CD practice can offer a high level of scalability to organizations looking to innovate quickly and efficiently.

Service-level objectives (SLOs) are another critical tool that DevOps teams use to automate software development processes and deliver innovation faster. SLOs represent the health of a particular service. They enable organizations to set and measure specific metrics for agreed-upon service levels, ensuring that users receive the high-quality experience they expect. SLOs can also allow organizations to align the business with DevOps and SRE teams along common business and technical goals. Finally, when automated using DevOps observability, SLOs can help SREs proactively optimize services and enable progressive delivery processes that balance rapid software deployment with risk mitigation strategies.

Dynatrace employee Continuous integration and continuous delivery (CI/CD): How it enhances DevOps and continuous deployment – blog

Here’s what you need to know about CI/CD practices, how they relate to each other, and how they benefit DevOps teams as they optimize and automate more processes to achieve ever-faster time to value for customers.

Dynatrace employee What is continuous delivery and what are best practices for implementing it? – blog

Continuous delivery and the automation that comes with it can take your software delivery practices to the next level. Read more.

Guide to event-driven SRE-inspired DevOps Guide to event-driven SRE-inspired DevOps for leveling up your existing CI/CD strategy – blog

In this blog, we dig into a core capability of Keptn: SLI/SLO-based Evaluations for Quality Gates as well as Auto-Remediation for DevOps.

What are SLOs? Lessons learned from enterprise service-level objectives management What are SLOs? How service-level objectives work with SLIs to deliver on SLAs – blog

What are SLOs? Here’s a guide to service-level objectives, how they work, and how they help DevOps teams automate and deliver better software.

How to start with SLOs to align business, DevOps, and SREs How to start with SLOs to align business, DevOps, and SREs – blog

In this blog, Dynatrace DevOps activist Andreas Grabner walks through an example of how to use SLOs to align business, DevOps, and SREs.

Automating SLOs helps SREs go fast: Dynatrace at SLOconf Automating SLOs helps SREs go fast: Dynatrace at SLOconf – blog

At Nobl9’s SLOconf, Dynatrace “SLOgicians” anchored 5 sessions demonstrating benefits and best practices for developing and implementing (SLOs).

Using SLOs to become the optimization athlete with Dynatrace Using SLOs to become the optimization athlete with Dynatrace – blog

Much like in sport, we cannot become the best without well-defined goals. This blog will walk you through how to create objectives for your organization by optimizing the system, creating production SLOs, continuously improving services performance, and more.

How to automate canary release decisions with Dynatrace How to automate canary release decisions with Dynatrace – blog

Progressive delivery enables speeding up while managing the risk of software deployments and configuration changes. One of the aspects of progressive delivery is using new zero-downtime deployment strategies such as Canary, Blue-Green, or Feature Flags. This blog discusses how to automate Canary release decisions with Dynatrace.

DevSecOps: Integrating security into DevOps with DevOps observability

Like DevOps, DevSecOps is a software delivery methodology that incorporates security testing and protection into each stage of the SDLC. Its main goal is to proactively address security concerns throughout the DevOps process, especially in the earliest stages—an approach that is also referred to as “shift-left security” or “security as code.” DevSecOps also allows organizations to release higher-quality software at a faster pace and identify vulnerabilities before they reach production.

DevSecOps builds on DevOps practices by ensuring that security concerns never fall through the cracks. Integrating security into the DevOps workflow helps organizations improve their application security posture, enabling them to better protect their users and business from cyberattacks and data breaches. For instance, advanced DevOps observability tools that incorporate DevSecOps capabilities can spot and address dangerous zero-day vulnerabilities, such as Log4Shell. These capabilities prevent malicious actors from executing commands on certain Java processes that are accessible to the outside world. By automating DevSecOps release validation through quality gates, organizations can even ensure that their releases are secure by default.

DevSecOps, What is DevSecOps What is DevSecOps? And what you need to do it well – blog

Like DevOps, DevSecOps is as much about culture and shared responsibility as it is about any specific technology or techniques. This blog unpacks DevSecOps in detail, delving into its benefits, challenges, and how to implement a successful DevSecOps strategy.

security as code ‘Security as code’ demands proactive DevSecOps – blog

Learn what “security as code” is, how to build a “security as code” culture, and why organizations must adopt a proactive DevSecOps stance.

Dynatrace expands strategic partnership with Atlassian to accelerate DevOps initiatives with observability and AIOps across the full software development lifecycle DevOps vs DevSecOps: Why integrate security and DevOps? – blog

If security concerns are driving you to review your approach to development, you’re likely weighing DevOps vs DevSecOps. This blog explains the difference and how to incorporate security practices into your software delivery workflows to protect your users and your business.

vulnerability management Automated DevSecOps release validation ensures security by default – blog

In modern cloud-native environments, application teams that are responsible for innovation face a dilemma: How are they to comply with ever-increasing security requirements while managing fast release cycles for hundreds of microservices? Without an automated approach to security enforcement, this can drastically slow down your team’s ability to safely release new application functionality. Read this blog to learn more.

Identify and minimize production risk of Log4Shell Identify and minimize production risk of Log4Shell – blog

The Log4Shell vulnerability allows an attacker to instruct the vulnerable system to download, and subsequently execute, a malicious command. Asad Ali explains the vulnerability and shares three main priorities for fixing affected environments.

DevSecOps tools and processes

Adopting DevOps and DevSecOps practices takes good planning and cultural change. But there are several tools and processes that can help organizations accomplish this goal. DevOps observability is one such capability. When it comes to DevOps metrics, the Four Keys from Google’s DevOps Research and Assessment (DORA) team are a great place to start. These key performance indicators can help any DevOps team achieve a higher performance standard while improving code quality.

Meanwhile, chaos engineering allows DevOps teams to proactively test applications for unstable behavior by subjecting them to controlled, simulated crises, including malicious events such as a cyberattack. A cloud automation solution that enables tool-agnostic automation across the SDLC can help organizations orchestrate application life cycles in complex, multicloud environments. This automation alleviates the challenges that DevOps and SRE teams often face when extending the life cycle with new methodologies, such as DevSecOps, or new technologies, such as IT service management (ITSM) tools.

9 key DevOps metrics for success 9 key DevOps metrics for success – blog

Congratulations! You have set up a DevOps practice. Now, with the hard work done and metrics in place, you can sit back, relax, and witness the seamless collaboration between your Dev and Ops teams. If only it were that easy. This blog outlines nine key DevOps metrics will help you meet your goals.

From AIOps tools to an AIOps platform: what it takes to automate AI operations What is chaos engineering? – blog

Testing for mishaps you can predict is essential. But with the complexity that comes with digital transformation, teams need to make sure applications can withstand the “chaos” of production. This blog explains how chaos engineering answers this need so that organizations can deliver robust, resilient cloud-native applications that can stand up under any conditions.

Dynatrace launches DevSecOps partner integrations for context-aware adaptive automation Dynatrace enables tool-agnostic automation for your application lifecycle – blog

By following the DevOps mantra of shifting left, the new lifecycle orchestration capability of Dynatrace Cloud Automation allows you to fully automate tasks that lead to a validated release and those that need to be executed after validation. Read this blog to learn more.

The post DevOps observability: A guide for DevOps and DevSecOps teams appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/devops-observability-guide-for-devops-and-devsecops/feed/ 0
Best practices for building a strong DevSecOps maturity model https://www.dynatrace.com/news/blog/devsecops-maturity-model-best-practices/ https://www.dynatrace.com/news/blog/devsecops-maturity-model-best-practices/#respond Mon, 19 Sep 2022 19:03:55 +0000 https://www.dynatrace.com/news/?p=53304 DevSecOps, vulnerability management, DevSecOps automation, application security

With the DevSecOps maturity model as guidance, organizations are better positioned to counteract cyberthreats and software quality risks whether they manifest in development or in live applications.

The post Best practices for building a strong DevSecOps maturity model appeared first on Dynatrace news.

]]>
DevSecOps, vulnerability management, DevSecOps automation, application security

As organizations adopt DevOps methodologies that integrate security practices, or DevSecOps, standards boards create guidelines, such as the OWASP DevSecOps maturity model. Such standards provide a framework that can help organizations get started on their DevSecOps journeys. But because every organization is unique, and modern multicloud environments are so complex, such standards can also be limiting. Every DevSecOps maturity model has its own special requirements.

But whatever framework you use, there are some common best practices to embrace—and struggles to avoid.

What is DevSecOps and what is a DevSecOps maturity model?

DevSecOps brings development, operations, and security teams together in the software development lifecycle (SDLC). This approach enables teams to focus on speed and agility in software development without compromising security. A DevSecOps approach advances the maturity of DevOps practices by incorporating security considerations into every stage of the process, from development to deployment. There are a few key best practices to keep in mind that formulate the perfect DevSecOps maturity model.

With a robust DevSecOps maturity model, organizations are better positioned to counteract cyber threats and software quality risks whether they manifest in development or in live applications. A strong DevSecOps maturity model helps organizations “shift left” to address software risks in development and “shift right” with problems in production.

What are the best practices that form the DevSecOps maturity model?

DevSecOps best practices provide guidelines to help organizations achieve efficient and secure application design, development, implementation, and management. The ability of organizations to effectively implement these best practices throughout the entire SDLC is known as DevSecOps maturity.

Some DevSecOps best practices include the following:

  • Security by design. DevSecOps practices build on DevOps, ensuring that security concerns are top of mind as developers build code. Integrating security into every step of the software development lifecycle can help organizations improve their overall application security, so they can better protect against cyber-attacks and minimize software quality risks.
  • Release validation. Answer-driven release validation transforms security from a detached, often manual process to an automated release process that provides continuous feedback to the DevSecOps team. Introducing release validations into your continuous delivery pipeline allows for automated analysis of the quality of your new software versions and planned releases. These checks not only automatically detect vulnerabilities; they also automatically assess risk and user impact thereby avoiding false positives and helping teams to focus on what matters most.
  • The education of employees about security awareness. Organizations should train DevOps teams to understand security best practices and how to operate any new tooling implementations. Developers need to be aware of any third-party libraries they’re utilizing, and possible security concerns that can occur. Teams must truly take responsibility for software security, just as much responsibility as they take for features, function, and usability.

DevSecOps best practices help align DevOps and security efforts by making security part of the conversation at every stage of application development and management. Incorporating security reduces the risk of post-deployment security issues and provides increased visibility into potential challenges as they emerge.

The DevSecOps maturity industry standard

As DevSecOps methodology becomes more pervasive within organizations and industries, there is a push to create more universally adopted maturity industry standards. While there is no required standard for DevSecOps maturity, most frameworks enlist a multistage approach that provides a pathway to success.

The OWASP DevSecOps maturity model divides maturity into four levels, each with its own approach to operations. Level 1 is the basic understanding of security practices, level 2 is the adoption of basic security practices, level 3 is the high adoption of security practices, and level 4 is the advanced deployment of security practices at scale. Although this is a good model to start with, it misses key aspects such as monitoring, observability, and release validation – all of which are very important in DevSecOps.

Why organizations struggle to implement DevSecOps best practices

Despite the benefits of DevSecOps best practices, many companies have difficulty implementing them at scale. In fact, survey data indicates that only around 30% of organizations consider their DevSecOps practices mature. Common causes of this functional frustration include the following:

  • Silos. Siloed data and operations can frustrate maturity efforts. If development, security, and operations teams can’t easily connect using shared processes and information, it’s nearly impossible for DevOps and security teams to actively mature.
  • Cultural issues. Many organizations also face cultural challenges that hamper DevSecOps practice implementation. If development teams have always operated in isolation, for example, creating security by design through integrating operations or security workflows is challenging, especially when staff is comfortable with their existing processes.
  • Disparate toolsets. Having more tools does not always translate into better results. Even when DevSecOps efforts are aligned, multiple toolsets can frustrate efforts at collaboration. When a development team uses one tool, the security team uses another, and the operations team uses a third, teams tend to spend more time switching apps than building a single robust framework.
  • Fragmented data. Disparate and fragmented data naturally frustrates maturity efforts. This data makes it nearly impossible for teams to share information and ensure they have up-to-date data sets.

Where a strong DevSecOps maturity model can benefit organizations

A strong DevSecOps maturity model provides several benefits for organizations, including the following:

  • Faster innovation. By combining development, security, and operations, companies can reduce the time required to build and deploy new applications while reducing the risk of security issues after deployment. The result is an improved ability to innovate. Teams can experiment with new approaches or components and quickly make changes as needed.
  • Better-quality software builds. Improved visibility means that teams can build better software and can shift left or right as needed. In practice, this means that teams can take on critical tasks that require their expertise while automating data-heavy security practices to streamline development.
  • Reduced time to issue identification. Better observability reduces the time to issue identification and remediation. In turn, the risk of potential downtime when applications launch is also reduced.
  • More strategic work. Automating key processes allows teams to reduce manual tasks and focus on strategic efforts to help deliver on long-term business objectives.
  • Improved resource management. Combining development, security, and operations enables organizations to identify where they’re spending money on repetitive tasks and where they can save resources with automation.

How to mature their DevSecOps models with continuous observability and AIOps

As environments become more complex, DevSecOps maturity often becomes a moving target. Conventional approaches to application security can’t keep pace with cloud-native environments that use agile methodologies and API-driven architectures, microservices, containers, and serverless functions. Just as companies get one issue under control, another blind spot emerges, challenging IT teams and potentially derailing development and operations efforts.

With Dynatrace Application Security, organizations can discover and address what is happening across their development and operation pipelines in runtime, automatically with continuous observability, effectively making the move seamless from adolescent frameworks to mature DevSecOps functions. Dynatrace combines the automation, AI, and enterprise-scale of the Dynatrace Software Intelligence platform with continuous runtime application vulnerability detection capabilities to deliver application security that enables DevSecOps teams to release software quickly and securely. Dynatrace Application Security provides organizations’ IT teams more time to focus on what truly matters: implementing DevSecOps best practices at scale to significantly improve efficiency and reduce security risk.

This eBook presents six essential DevSecOps best practices that provide a blueprint to help teams optimize DevSecOps automation, efficiency, and application security.

The post Best practices for building a strong DevSecOps maturity model appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/devsecops-maturity-model-best-practices/feed/ 0
Dynatrace Runtime Vulnerability Analysis now covers the entire application stack https://www.dynatrace.com/news/blog/dynatrace-extends-appsec-to-go/ https://www.dynatrace.com/news/blog/dynatrace-extends-appsec-to-go/#respond Thu, 11 Aug 2022 12:00:06 +0000 https://www.dynatrace.com/news/?p=52655 Business analytics graphic

Dynatrace adds Go vulnerability analysis on top of Java, .NET, Node.js, and PHP vulnerability analysis. Coverage extends to language runtimes such as Java Virtual Machine (JVM), Node.js runtime, and .NET CLR. This helps SecOps, DevOps, and operations teams to collaborate more effectively. Automatic vulnerability detection at runtime and AI-powered risk assessment further enable DevSecOps automation.

The post Dynatrace Runtime Vulnerability Analysis now covers the entire application stack appeared first on Dynatrace news.

]]>
Business analytics graphic

In addition to modern application stacks introducing new levels of speed and complexity, they also create new security challenges. And the distinction between applications and cloud platforms is blurring.

Missing holistic vulnerability analysis creates risk

Every layer of an application stack contributes to the security posture of an application and can potentially contain vulnerabilities. The number of entry points through which attackers can infiltrate your company’s environment is always expanding. SecOps teams are confronting increasingly complex threats and alert storms. And while effective DevSecOps approaches require collaboration and automation, teams still often work alone in silos.

This is because many organizations lack a holistic view and analysis across all layers of their application ecosystem to minimize the attack surface and protect the weakest links. DevOps teams, SREs (site reliability engineers), platform teams, and SecOps teams aren’t always working from a common source of truth:

  • SAST tools (static application security testing) provide scanning code for vulnerabilities.
  • Vulnerability scanners detect vulnerabilities in, for example, language runtimes.
    This siloed approach renders holistic risk assessment impossible and can lead to ineffective issue prioritization and blind spots.

Dynatrace uniquely provides full-stack Runtime Vulnerability Analysis

With new enhancements, Dynatrace Application Security now provides Runtime Vulnerability Analysis across the entire application stack in cloud-native environments. Uniquely, Dynatrace not only identifies vulnerabilities across all layers, it also analyzes them automatically. This provides actionable out-of-the-box insights to CISOs and SecOps teams that can be used to assess risk, prioritize, and collaboratively remediate threats with other teams.

With the flip of a switch and zero configuration, Dynatrace gives you:

  • Full visibility into all vulnerabilities at runtime via automatic instrumentation
  • AI-powered risk assessment based on observability data provided by the Davis® Security Advisor
  • DevSecOps collaboration for faster remediation across all layers
Third party vulnerabilities Dynatrace screenshot
Fig 1. Dynatrace aggregates vulnerability data in real time and recommends actions to improve the security of your environment based on the number of detected vulnerabilities and their severity, context, asset exposure, and business impact.

Dynatrace adds AI-powered vulnerability analysis for Go

Dynatrace extends its Runtime Vulnerability Analysis to Go on top of Java, .NET, Node.js and PHP. Go is one of the key technologies powering cloud-native applications and its adoption is increasing rapidly. Even Kubernetes and its core services—a key driver in modern cloud transformation—are written in Go.

Runtime Vulnerability Analysis is provided across the entire software development lifecycle, from pre-production to production for every operating environment, including dynamic multiclouds and Kubernetes clusters. The Dynatrace Davis AI engine aggregates vulnerability data in real time and recommends actions to improve the security of your Go applications.

Vulnerability Analysis for language runtimes completes the picture

Runtimes like Java Virtual Machine (JVM) and .NET CLR, or Node.js runtimes are responsible for converting bytecode into machine-specific code. Insights into this layer and the respective vulnerabilities are crucial, especially in containerized environments where every container has its own runtime.

Dynatrace customers get full visibility into language runtime vulnerabilities. This helps accelerate remediation by leveraging observability data to automatically provide an inventory of all deployed versions.

Automatic vulnerability analysis for Kubernetes platform versions

In cloud-native application stacks, everything is code. Just securing applications and libraries isn’t enough. You need to go deeper into the stack—into the infrastructure itself. This is why Dynatrace announced automatic vulnerability detection to the Kubernetes platform last year. As for the other components, Dynatrace Application Security detects vulnerable Kubernetes versions automatically and tracks the evolution of these security problems in real time.

How to get started

Runtime Vulnerability Analysis for Go and language runtimes will be available within the next 90 days.

If you’re already a Dynatrace customer and want to start using the Application Security module today, just select Application Security from the menu in the Dynatrace web UI.

If you’re not using Dynatrace yet, it’s easy to get started in under 5 minutes with the Dynatrace free trial.

For more information, visit our website. To learn more, see Application Security in Dynatrace Documentation.

The post Dynatrace Runtime Vulnerability Analysis now covers the entire application stack appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-extends-appsec-to-go/feed/ 0
The top eight DevSecOps trends in 2022 https://www.dynatrace.com/news/blog/top-eight-devsecops-trends/ https://www.dynatrace.com/news/blog/top-eight-devsecops-trends/#respond Wed, 23 Feb 2022 21:01:27 +0000 https://www.dynatrace.com/news/?p=48879 DevSecOps cycle

From Infrastructure as Code to GitOps and serverless architecture, the top DevSecOps trends in 2022 will continue to enable teams to automate, streamline their CI/CD pipelines, and make time for innovation.

The post The top eight DevSecOps trends in 2022 appeared first on Dynatrace news.

]]>
DevSecOps cycle

As businesses take steps to innovate faster, software development quality—and application security—have moved front and center. This is fueling key DevSecOps trends in 2022.

In order for software development teams to balance speed with quality during the software development cycle (SDLC), development, security, and operations teams (or DevSecOps teams) need to ensure that their practices align with modern cloud environments. That can be difficult when the business climate can prioritize speed.

Indeed, according to one survey, DevOps practices have led to 60% of developers releasing code twice as quickly. But increased speed creates a tradeoff: According to another study, nearly half of organizations consciously deploy vulnerable code because of time pressure.

DevSecOps teams can address this unsettling tradeoff by automating processes throughout the SDLC, centralizing application configuration with a shared set of tools, and using observability platforms to gain visibility into code-quality lapses, security gaps, and other software development issues.

Incorporating DevSecOps practices can bring security, compliance, and development discipline to organizations seeking to move faster without sacrificing code quality: According to one survey, 96% of respondents said their organization would benefit from automating security and compliance processes, a key principle of DevSecOps.

DevSecOps adoption is on the rise, though still emerging as a best practice for developing secure, high-quality code. According to GitLab’s 2021 Global DevSecOps Survey, 36% of respondents develop software using DevSecOps, compared with only 27% in 2020.

As DevSecOps practices gather steam in 2022, there are several concurrent technology trends that will likely further DevSecOps adoption. These DevSecOps trends will also aid teams as they integrate security and compliance into processes without slowing innovation or creating additional work for already time-strapped teams.

1. Increased adoption of Infrastructure as code (IaC)

IaC, or software intelligence as code, codifies and manages IT infrastructure in software, rather than in hardware. As a result, developers and operations teams can automatically manage, monitor, and provision IT resources through software code rather than manually configure one device after another. Infrastructure as code is also known as software-defined infrastructure, or software intelligence as code.

According to a Gartner report, “By 2023, 60% of organizations will use infrastructure automation tools as part of their DevOps toolchains, improving application deployment efficiency by 25%.”

Codified infrastructure accelerates DevSecOps practices and adoption. Enshrining infrastructure in code provides a foundation for automation and testing—both of which are crucial for DevSecOps. It does so by creating repeatable, automated software-driven processes.

IaC benefits teams by enabling the same deployment to be replicated infinitely by executing the code multiple times, so it frees DevSecOps’ teams time to work on other projects. The amount of effort and time saved is magnified depending on how many times the infrastructure needs to be replicated.

Another key benefit of IaC that can accelerate DevSecOps adoption is reducing human error. A key component of DevSecOps to enshrine process in code—to ensure that the process is executed correctly despite the myriad complexities that arise during the delivery of software. With IaC enable DeSecOps teams to institutionalize these processes in code, ensuring repeatable, secure, automated, and efficient processes.

2. Mounting attacks via vulnerable third-party code

As cyberattacks continue to escalate, organizations may find themselves vulnerable via third-party code or code libraries that they have incorporated into their proprietary software. In December of 2021, for example, Log4Shell highlighted the importance of organizations to monitor code in development and production but also the code of their partners and customers.

Log4Shell enables an attacker to use remote code execution to engage with software that uses the Java logging library Log4j versions 2.0 and 2.14.1. In December 2021, many organizations were forced to take devices and applications offline to prevent malicious attackers from gaining access to networks and sensitive data. In the ensuing days and weeks, many DevSecOps teams needed to identify the presence of Log4J throughout the development cycle (from development to runtime).

“Wise developers don’t reinvent the wheel: they use existing libraries and/or frameworks,” wrote Nicolas Fränkel in the article You’re running untrusted code! “From a security point of view, it means users of such third-party code should carefully audit it. We should look for flaws: both bugs and vulnerabilities.”

The next major security vulnerability may share similar properties with Log4Shell. As a result, organizations should enlist observability platforms to scrutinize their IT landscapes and identify at-risk code.

3. AIOps for root-cause analysis becomes critical

As cloud complexity grows, managing these environments with manual processes becomes impossible to sustain. For DevSecOps teams to regain control, it’s increasingly important to enlist automation to capture observability data and harness AIOps (AIOps applies AI to IT operations).

By analyzing data on activity in real-time, teams can unlock the insights developers need to accelerate innovation.

As Forbes noted, AIOps is “moving from marketing hype to a useful tool being adopted across the enterprise.” Broader business deployment stems from increasingly sophisticated AI algorithms and the growing speed at which AI can discover new data relationships. The ability to identify the root cause of IT issues in real-time—and in some cases to provide automated remediation—has become critical for DevSecOps teams.

This real-time analysis is key as teams integrate security verification to test code in development and continually identify new security vulnerabilities in production.

4. Weighing ML-based observability vs. AIOps

Not all software intelligence is created equal. Another trend is weighing machine learning (ML)-based  approaches to observability vs. AIOps-enabled capabilities.

With ML-based approaches, data needs to be trained to understand normal behavior and what is anomalous. Teams need to verify the data modeling, which siphons time and effort from DevSecOps teams trying to accomplish strategic work.

AIOps, conversely, is an approach to software operations that combines AI algorithms with data analytics to automate key tasks and suggest precise answers to common IT issues, such as unexpected downtime or unauthorized data access. Unlike ML-based approaches, AIOps doesn’t require training of data. With AIOps, algorithms observe events in context. That precision and autonomy reduce the burden on IT teams in two ways: they can offload routine monitoring and management tasks, which enables them to focus on more mission-critical concerns.

Moreover, ML-based approaches merely identifies relationships between a problem and suggested solutions, whereas AIOps provides precise answers to precisely identified problems.

5. GitOps becomes the new normal

GitOps is a framework of practices that manage infrastructure and application configurations using Git, an open-source version control system. As a result, Git becomes the single source of truth and control mechanism for creating, updating, and deleting system architecture dynamically. Because GitOps enables automation, it advances the principles of Infrastructure as Code.

GitOps uses pull requests to verify and automatically deploy system infrastructure modifications. Centralizing as many of these configurations in one place as possible allows teams to harness greater control.

As more organizations move to continuous integration and continuous delivery (CI/CD), they have more opportunities to implement GitOps. This approach enables teams to apply automation to their testing, delivery, deployment, and governance. GitOps also streamlines infrastructure tasks and workflows.

6. Kubernetes infrastructure evolves

Central to these DevSecOps trends and any digital transformation journey is Kubernetes. Kubernetes is an open-source platform that orchestrates the management, deployment and scaling of containers (a unit of software that packages code and all its dependencies).

With this package of components, an application can quickly and reliably move from one computing environment, such as testing, to another. Kubernetes empowers organizations to be more productive as they develop applications.

Kubernetes containers enable multiple teams to work on different facets of a project simultaneously. With containers, teams can manage resources, fix bugs more quickly, and shorten work cycles.

Kubernetes has changed the way organizations develop applications. It also enables developers to be responsive to changing customer requirements while enlisting shared resources on various cloud platforms. Adopting Kubernetes can result in a massive boost to efficiency and makes building, testing, and deploying easier in DevSecOps pipelines.

7. Serverless architecture expands

Serverless computing is an application building and hosting model based in the cloud that enables companies to consume resources on-demand. Serverless architecture becomes compelling for teams that want to build, manage, and scale applications without managing all the underlying infrastructure. With a serverless model, a cloud provider manages the infrastructure and provides tools for building applications modularly.

Delegating the task of infrastructure management to a cloud provider enables organizations to scale dynamically.  Going serverless can also be more cost-effective than managing infrastructure on-premises. Organizations pay only for the resources they use. Because cloud providers host the infrastructure, serverless computing also improves disaster recovery and IT system resilience.

8. Microservices gain ground over monolithic app development

Microservices go hand-in-hand with serverless computing. Instead of developing monolithic applications, which are time-consuming and costly to develop and test, teams can break into independent units, enabling flexibility. As a result, teams can eliminate the confines of traditional application development.

By breaking services into modular pieces, organizations can benefit from more flexible, incremental development to suit business units’ needs. And when problems arise, microservices enable developers to work on the problem in a contained way rather than disrupt the entire application. This kind of modular application development helps DevSecOps teams stay agile and flexible while also attending to code quality and security.

Ultimately, 2022 will be a year of accelerated DevSecOps adoption and process maturation. It’s almost a matter of survival for companies making efforts to digitally transform. To navigate these DevSecOps trends and innovate faster without sacrificing security and product quality, teams need modern, automated platforms to reduce friction in the software development lifecycle, enable collaboration between teams, and automate processes that ensure quality control.

Learn more about DevSecOps and how Dynatrace can help you get there from the ebook, Cloud application security: The next generation.

The post The top eight DevSecOps trends in 2022 appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/top-eight-devsecops-trends/feed/ 0
Advance DevSecOps practices with a vulnerability management strategy https://www.dynatrace.com/news/blog/advance-devsecops-practices-with-a-vulnerability-management-strategy/ https://www.dynatrace.com/news/blog/advance-devsecops-practices-with-a-vulnerability-management-strategy/#respond Tue, 01 Feb 2022 21:24:44 +0000 https://www.dynatrace.com/news/?p=48367 AIOps capabilities, DevOps orchestration, DevSecOps practices

Adding a vulnerability management strategy to your DevSecOps practices can be key to handling threats like Log4Shell.

The post Advance DevSecOps practices with a vulnerability management strategy appeared first on Dynatrace news.

]]>
AIOps capabilities, DevOps orchestration, DevSecOps practices

As organizations struggle to combat vulnerabilities in their IT environments, they need real-time data on performance problems and security issues. At the annual conference Dynatrace Perform 2022, the theme is “Empowering the game changers.” In the Advancing DevOps and DevSecOps track, sessions aim to help security pros, developers, and engineers as they brace for new threats that are costly and time-consuming to address.

In this preview video for Dynatrace Perform 2022, I talk to Ajay Gandhi, VP of product marketing at Dynatrace, about how adding a vulnerability management strategy to your DevSecOps practices can be key to handling threats posed by vulnerabilities.



Dynatrace Perform 2022 preview video

Consider the Log4Shell vulnerability, which emerged in December 2021 and is estimated to have affected hundreds of millions of systems worldwide. The vulnerability is located in Log4j 2, an open-source Apache Java software used to run logging services in a host of front-end and backend applications. Log4j 2 can grant access to internal networks, and if exploited, makes networks, applications, and devices susceptible to data theft and malware attacks. Because the Log4j 2 library is used so pervasively, it has had a dramatic impact on business.

By integrating runtime vulnerability management into DevSecOps practices, teams can immediately detect and remediate exploitable vulnerabilities like Log4Shell in their environments.

Why DevSecOps practices benefit from vulnerability management

Without a centralized approach to vulnerability management, DevSecOps teams waste time figuring out how a vulnerability affects the production environment and which systems are affected.

A real-time observability platform with code-level application insights can automatically identify vulnerabilities in runtime and production environments. Moreover, modern observability capabilities provide context about activity in an IT environment so teams know what is most critical to address first. As a result, IT teams can quickly prioritize remediation efforts, which can make the difference between a successful and an unsuccessful attack.

“The requirements for vulnerability management have evolved, and Log4Shell has crystallized that,” says Gandhi. “You need more context to be effective in addressing vulnerabilities quickly, precisely, and at scale and being able to prioritize which apps and which code segments need to be addressed first.”

Observability is the game-changer. “What we found is that by combining observability context (which apps are affected and infrastructure monitoring) with security intelligence, Dynatrace AI can prioritize what to focus on first, second, and third and automatically generate a risk assessment. Teams can then identify all affected apps in their environment in real-time.”

A key DevSecOps practice in regard to vulnerability management is not only “shifting left” (moving testing early in the development cycle to identify vulnerabilities) but also “shifting right” (continuously testing software in production to ensure security and quality). As DevSecOps practices mature, teams can benefit from observability that spans the software development cycle to identify vulnerabilities in development and in production.

The post Advance DevSecOps practices with a vulnerability management strategy appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/advance-devsecops-practices-with-a-vulnerability-management-strategy/feed/ 0
Dynatrace Adds Security Gates to Advance DevSecOps Adoption https://devops.com/dynatrace-adds-security-gates-to-advance-devsecops-adoption/ Wed, 10 Nov 2021 12:36:13 +0000 https://www.dynatrace.com/news/?post_type=news-coverage&p=47370 The post Dynatrace Adds Security Gates to Advance DevSecOps Adoption appeared first on Dynatrace news.

]]>
The post Dynatrace Adds Security Gates to Advance DevSecOps Adoption appeared first on Dynatrace news.

]]>
DevOps vs DevSecOps: Why integrate security and DevOps? https://www.dynatrace.com/news/blog/devops-vs-devsecops/ https://www.dynatrace.com/news/blog/devops-vs-devsecops/#respond Mon, 22 Mar 2021 19:37:39 +0000 https://www.dynatrace.com/news/?p=43315 Dynatrace expands strategic partnership with Atlassian to accelerate DevOps initiatives with observability and AIOps across the full software development lifecycle

In an age when people freely share even their most sensitive personal data on many online apps and services, we have grown to expect businesses will protect this information during any engagement or transaction. Yet as software environments become more complex, there are more ways than ever for malicious actors to exploit vulnerabilities, even in […]

The post DevOps vs DevSecOps: Why integrate security and DevOps? appeared first on Dynatrace news.

]]>
Dynatrace expands strategic partnership with Atlassian to accelerate DevOps initiatives with observability and AIOps across the full software development lifecycle

In an age when people freely share even their most sensitive personal data on many online apps and services, we have grown to expect businesses will protect this information during any engagement or transaction. Yet as software environments become more complex, there are more ways than ever for malicious actors to exploit vulnerabilities, even in the application development and delivery pipeline.

If security concerns are driving you to review your approach to development, you’re likely weighing DevOps vs DevSecOps, and considering how to incorporate security practices into your software delivery workflows, to protect your users and your business.

What challenges to DevOps and security face?

Traditional application security measures are not living up to the challenges presented by dynamic and complex cloud-native architectures and rapid software release cycles. Security Boulevard reports that 95% of organizations say they’ve experienced at least one successful application exploit in the past year. One reason for this failure is traditional application security tools slow developers down. Sixty-six percent of companies say they “sometimes or occasionally” skip security scans to meet release deadlines, putting already vulnerable apps at greater risk.

Many organizations already employ DevOps, an approach to developing software that combines development and operations in a continuous cycle to build, test, release, and refine software in an efficient feedback loop.

Most often, security practices, like testing for and managing vulnerabilities, happen in a separate step, by a separate team, using separate tools–often at odds with the release schedule.

DevOps vs DevSecOps: What is the difference between DevOps and DevSecOps?

DevSecOps is the practice of integrating security into the DevOps workflow. Just as DevOps requires a lifestyle shift to integrate two teams at opposite ends of the delivery lifecycle, DevSecOps requires a similar mindset shift as teams integrate security tools and practices into this cadence.

How combining DevOps and security improves the entire SDLC

As you think about how to evolve your processes to include security as an equal, third party in your development-operations partnership, it will be helpful to understand these six key ways that adopting DevSecOps can boost your entire software delivery life cycle.

Want to learn more about DevOps?

Streamline the way IT operates and enterprises grow with observability and AIOps. Read our DevOps eBook – A Beginners Guide to DevOps Basics

1. Security happens during, not after development

Traditionally, application security testing sits as a discrete stage between development and operations. While DevOps practices have sped up this approach — develop, test and secure, operate — DevSecOps unites the three stages into one effort coordinated by a single team with access to the same data.

Rather than relying on post-development scans and assessments to find potential application security issues, DevSecOps integrates application security testing earlier in the development and operations workflow. This “shift left” approach to security enables developers to address issues before they reach production, which speeds up delivery and reduces risk.

2. Security can “shift left”—and “shift right”

While the ability to “shift left“, to address security in pre-production, helps improve efficiency during development, it is also vital that security practices “shift right“, by maintaining visibility into applications running in a production environment. Here’s why:

  1. Production is where most exploits take place. Applications are open to the internet and accessed by unknown entities, some of which may have malicious intent.
  1. Production is where off-the-shelf and home-grown applications run. These applications may not be subject to your usual pre-production testing regimen and may fall through the cracks.

Because application vulnerabilities can be addressed during development and evaluated in the run-time context of the production environment, the time and effort required to remediate those vulnerabilities is much less.

3. Security is by design, not tacked on

The most hardened applications are those for which security was a key consideration all along. DevSecOps practices ensure that applications do not rely on tacked-on protections by giving security staff a seat at the table and incorporating their input from the very beginning of app development and operations.

The result is security by design. Instead of discovering application vulnerabilities with post-release security solutions that slow software rollouts at best — and require recalls at worst — the DevSecOps approach makes security a native component of key application frameworks and functions.

4. Security is a shared responsibility

When considering DevOps vs DevSecOps, it becomes obvious that both look to integrate disparate processes using a combination of agility and automation. One contribution security can make to DevOps is to place emphasis on the idea that everyone is responsible for security.

DevOps teams’ relationships with security staff can range from apathetic to downright hostile if DevOps staff does not understand the importance of the security practices suggested or if they feel these practices obstruct their work. In a recent study by ESG, 27% of respondents admitted their application development and DevOps teams do not even work with their cybersecurity teams due to fear this will slow them down.

Truly implementing DevSecOps requires a cultural shift. Rather than simply joining three disparate disciplines under common management, DevSecOps expects every individual to exercise security best practices relevant to their role and to remain in a security-focused mindset. The result is a shared responsibility model that helps ensure a secure product.

5. Shared security intelligence breaks down silos

While DevOps looks to integrate once-disparate processes, DevSecOps looks to break down more of the long-established walls between organizational departments. These security “silos” — the data and applications that each department handles in its own specific way — create immediate inconveniences and signal deeper problems with observability and sharing of critical information.

DevSecOps efforts level the playing field by creating a framework of shared solutions, data, and security protocols that all teams leverage throughout the software delivery lifecycle. While use cases and customizations may vary for different processes, shared resources that integrate into a common workflow help to solve for silos at scale.

6. Integrated security enables automation

Both DevOps and DevSecOps prioritize simplifying processes through automation. For DevOps, automation streamlines design, testing, and deployment processes and increases the speed of application development.

Similarly, integrating application security earlier in the software development process enables teams to identify, resolve, and prevent application vulnerabilities early in pre-production, but also in production. This integrated approach makes it possible for teams to reliably automate vulnerability detection and security practices into a continuous delivery workflow.

How can an organization transition to DevSecOps?

While the progression from DevOps to DevSecOps is usually more about adapting processes than implementing infrastructure, the benefits of integrating security into the software delivery process are clear. No longer an afterthought, application security becomes a shared responsibility that’s driven by design, helping to break down silos and enabling developers to address security issues throughout the software development life cycle.

To make this integration possible, organizations need a single source of automatic software intelligence that can enable DevSecOps to deliver and run digital services securely with speed and confidence.

A single solution to facilitate the DevSecOps transition

The Dynatrace Software Intelligence Platform’s Application Security module, powered by the AI engine, Davis®, continuously watches entire production and pre-production environments to identify any changes and provide precise answers about the source, nature, and severity of any vulnerabilities as they arise in real-time.

Dynatrace automatically analyzes and prioritizes alerts and eliminates false positives, helping teams speed up their CI/CD pipelines, identify quality issues earlier in the software lifecycle, automate manual quality validation processes, and automatically detect, assess, and remediate open-source and third-party vulnerabilities. With this automatic, real-time software intelligence, teams can understand risks in context and focus on what matters.

The post DevOps vs DevSecOps: Why integrate security and DevOps? appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/devops-vs-devsecops/feed/ 0
Dynatrace enters the Cloud Application Security market https://www.dynatrace.com/news/press-release/dynatrace-enters-the-cloud-application-security-market/ Tue, 08 Dec 2020 11:55:55 +0000 https://www.dynatrace.com/news/?post_type=press-release&p=41546 WALTHAM, MA, December 8, 2020 – Software intelligence company Dynatrace (NYSE: DT) announced today its entry into the cloud application security market with the addition of a new module to its industry-leading Software Intelligence Platform. The Dynatrace® Application Security Module provides continuous runtime application self-protection (RASP) capabilities for applications in production as well as preproduction […]

The post Dynatrace enters the Cloud Application Security market appeared first on Dynatrace news.

]]>
WALTHAM, MA, December 8, 2020 – Software intelligence company Dynatrace (NYSE: DT) announced today its entry into the cloud application security market with the addition of a new module to its industry-leading Software Intelligence Platform. The Dynatrace® Application Security Module provides continuous runtime application self-protection (RASP) capabilities for applications in production as well as preproduction and is optimized for Kubernetes architectures and DevSecOps approaches. This module inherits the automation, AI, scalability, and enterprise-grade robustness of the Dynatrace® Software Intelligence Platform and extends it to modern cloud RASP use cases. Dynatrace customers can launch this module with the flip of a switch, empowering the world’s leading organizations currently using the Dynatrace platform to immediately increase security coverage and precision.

“Dynatrace Application Security delivers full runtime detection,” said Julien Bourteele, Chief Information Security Officer at Stelliant. “This makes us feel much safer because it ensures we don’t have blind spots and we’re not wasting time chasing false positives. This helps us innovate faster, and with more confidence.”

IDC predicts by 2022 90% of new enterprise applications worldwide will be developed as cloud-native, using agile methodologies and API-driven architectures that leverage microservices, containers, and serverless functions.1 Traditional approaches to application security can’t keep up in these constantly changing environments. Despite having invested in multiple tools to manage security threats, organizations continue to have blind spots and uncertainty about exposures and their impact on cloud-native applications. When vulnerabilities are detected, current approaches require manual processes that deliver imprecise risk and impact analysis and force teams to waste time chasing false positives. In addition, accelerated innovation and DevSecOps processes have shifted security testing “left”, placing more responsibility on developers to ensure code doesn’t have vulnerabilities. With no time for teams to manually analyze, assess, and manage risks based on sampled or scheduled scan results, even the most common and well-documented vulnerabilities can remain undetected and open for hackers to exploit.

Dynamic cloud-native environments have disrupted application security, creating what is estimated to become an $18B market over time. Dynatrace® Application Security is purpose-built for this opportunity and enables DevSecOps teams to innovate at the speed required by the business while simultaneously ensuring security. By combining automated RASP capabilities with core platform strengths, Dynatrace Application Security enables organizations to:

  • Precisely identify vulnerabilities in production and preproduction environments, including what they impact and their business priority, and eliminate false positives with real-time topology mapping delivered by Smartscape® and distributed tracing with code-level analysis from PurePath®.
  • Gain complete vulnerability coverage and never miss a code change or new deployment with automatic and continuous discovery and instrumentation, powered by OneAgent®.
  • Dramatically speed up risk and impact analysis, remediation, and collaboration with Davis® AI-assistance to automatically and continuously identify changes, prioritize alerts, and deliver precise answers about the source, nature, and severity of vulnerabilities.
  • Provide detailed, high-quality vulnerability information, and ensure access to the insights needed to fix potentially compromised code through built-in integration with Snyk Intel.

“With Dynatrace Application Security, our DevSecOps teams finally gain the 100% production run-time visibility they need to defend against vulnerabilities in our Kubernetes environment,” said Jürgen Plasser, Application Security Management at Raiffeisen Software GmbH. “Dynatrace’s real-time, topology-driven, and precise risk assessment allows us to focus our energy where it matters for the business, eliminating wasted time spent working through thousands of false positives.”

Built on a proven, webscale platform, the new Dynatrace® Application Security Module is available for Dynatrace platform customers today.

“We have been working on this platform extension with early adopting customers for some time now and are thrilled to bring our first set of capabilities to market,” said Bernd Greifeneder, Founder and Chief Technology Officer at Dynatrace. “Dynatrace Application Security provides organizations’ security leadership confidence that their production and preproduction environments are protected through continuous, automatic runtime analysis, while enabling DevSecOps teams to focus on what matters, understand vulnerabilities in context, and proactively resolve these to drive faster, more secure release cycles. Just as we redefined the performance monitoring and management market, leveraging the transformative impact of the modern cloud, we’re doing it again in the cloud application security market.”

Application Security joins Infrastructure Monitoring, Application and Microservices Monitoring, Digital Experience Monitoring, Business Analytics, and Cloud Automation as part of the Dynatrace® Software Intelligence Platform.

To learn more about how Dynatrace Application Security can help your organization, visit our blog or website.

1 IDC FutureScape: Worldwide Cloud 2020 Predictions, Doc # US44640719, October 2019

The post Dynatrace enters the Cloud Application Security market appeared first on Dynatrace news.

]]>