flâneur — a map of the web's best reading

State of DevSecOps | Datadog

datadoghq.com · 2,036 words · saved by 1 readers

Shipping secure code rapidly and at scale is a challenge across the software industry, as evidenced by continued news of high-profile data breaches and critical vulnerabilities. To address this challenge, organizations are increasingly adopting DevSecOps, a practice in which application developers work closely alongside operations and security teams throughout the development life cycle. DevSecOps looks at application security holistically, recognizing that code must be secure not only in how it’s written but also in how it’s deployed and run in production. We analyzed tens of thousands of applications and container images and thousands of cloud environments to assess the security posture of applications today and evaluate the adoption of best practices that are at the core of DevSecOps—infrastructure as code, automated cloud deployments, secure application development practices, and the usage of short-lived credentials in CI/CD pipelines. Our findings demonstrate that modern DevOps pr

Fact 1 Nearly all organizations have known exploitable vulnerabilities in deployed services Eighty-seven percent of organizations have at least one exploitable vulnerability , affecting 40% of all services . These vulnerabilities remain most prevalent in Java services at 59%, with .NET at 47% and Rust at 40%. Where vulnerabilities are known to be actively exploited, there's an increased chance that vulnerable services will be compromised. Tweet Share Keeping languages and runtime environments up to date is a primary way to prevent exploitable vulnerabilities in applications and services, and i

Explore this link on the map →

related reading