From a startup to a multinational corporation the software development industry is currently dominated by agile frameworks and product teams and as part of it DevOps strategies. It has been observed that during the implementation, security aspects are usually neglected or are at least not sufficient taken account of. It is often the case that standard safety requirements of the production environment are not utilized or applied to the build pipeline in the continuous integration environment with containerization or concrete docker. Therefore, the docker registry is often not secured which might result in the theft of the entire company’s source code.
The OWASP DevSecOps Maturity Model provides opportunities to harden DevOps strategies and shows how these can be prioritized.
With the help of DevOps strategies security can also be enhanced. For example, each component such as application libraries and operating system libraries in docker images can be tested for known vulnerabilities.
Attackers are intelligent and creative, equipped with new technologies and purpose. Under the guidance of the forward-looking DevSecOps Maturity Model, appropriate principles and measures are at hand implemented which counteract the attacks.
Go to https://dsomm.timo-pagel.de or clone this repository and run startDocker.bash
.
- matrix shows the dimensions, subdimensions and activities are described.
- Implementation Levels can be used to measure the current implementation level by clicking on the specific activities which have been performed.
- Ease and Value of Implementation is used for the maturity model development to see the ease and value of each activity to be able to compare it with activities within the subdimension and activities from other subdimensions.
- Dependenies shows the dependencies between activities
- Full Report prints all activities to be able to print it
In this video Timo Pagel describes different strategic approaches for your secure DevOps strategy. The use OWASP DSOMM in combination with OWASP SAMM is explained.
- Online: OWASP DevSecOps Maturity Model - Culture (German) 2020-08-25
- Video: Usage of the OWASP DevSecOps Maturity Model, OWASP Ottawa Chapter, 2020-08-17
- Continuous Application Security Testing for Enterprise, DevOps Meetup Hamburg, 2019-09-26
- DevSecOps Maturity Model, Open Security Summit, near London, 2018
- Security in DevOps-Strategies, 28.09.2017, Hamburg, Germany
- DevSecOps Maturity Model, 2017
- The dimension Test and Verifiacation is based on Christian Schneiders Security DevOps Maturity Model (SDOMM). Application tests and Infrastructure tests are added by Timo Pagel. Also, the sub-dimension Static depth has been evaluated by security experts at OWASP Stammtisch Hamburg.
- The sub-dimension Process has been added after a discussion with Francois Raynaud that reactive activities are missing.
- Enhancement of my basic translation is performed by Claud Camerino.
- Adding a manual on how to use DSOMM
- Integration of Incident Response
- DevSecOps Toolchain Categorization
- App Sec Maturity Models Mapping
- CAMS Categorization
- Addinng of evidence
This program is free software: you can redistribute it and/or modify it under the terms of the GPL 3 license. The OWASP DevSecOps Maturity Model and any contributions are Copyright © by Timo Pagel 2017-2020