---
title: DevOps and SecOps – the Impossible Conciliation?
description: How the organizations using DevOps approach have created a totally integrated framework into the Continuous Delivery Model
image: http://businessinsights.bitdefender.com/hs-fs/hub/341979/file-1076657267-jpg/Blog_pics/devops_secops.jpg
---

[![](https://businessinsights.bitdefender.com/hubfs/2021/09/logo-white.svg)](https://businessinsights.bitdefender.com/?hsLang=en-us)

[![CONTACT AN EXPERT](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/1d8885e9-1179-49b1-a5ec-9c75f5f670dd)

- [For Home](https://www.bitdefender.com/solutions/)
- [For Business](https://www.bitdefender.com/business/)
- [Resources](https://www.bitdefender.com/business/resource-library.html)
- [Webinars](https://www.bitdefender.com/business/webinars.html)

# [BUSINESS INSIGHTS](https://businessinsights.bitdefender.com/?hsLang=en-us)

[#Enterprise Security](https://businessinsights.bitdefender.com/topic/enterprise-security) [#Managed Service Providers](https://businessinsights.bitdefender.com/topic/managed-service-providers)

 By [**Horatiu Bandoiu**](https://businessinsights.bitdefender.com/author/horatiu-bandoiu) / Jun 23, 2014

# DevOps and SecOps – the Impossible Conciliation?

Share this [![Share on email](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/email-color.png)](mailto:?subject=Check%20out%20https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=email%20&body=Check%20out%20https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=email) [![Share on twitter](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/twitter-color.png)](https://twitter.com/intent/tweet?original_referer=https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=twitter&url=https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=twitter&source=tweetbutton&text=) [![Share on linkedin](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/linkedin-color.png)](http://www.linkedin.com/shareArticle?mini=true&url=https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=linkedin) [![Share on facebook](https://businessinsights.bitdefender.com/hubfs/2021/07/blog/facebook-color.png)](http://www.facebook.com/share.php?u=https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation&utm_medium=social&utm_source=facebook)

When dealing with greatness and great companies one should try to find out what it is that they are doing so outstandingly well, and what lessons are to be learned from them? What do Google, Amazon, Facebook, LinkedIn, Netflix, Intuit, Bank of America, GAP or Macy’s - just to name a few - have in common?

Apart from being very big enterprises and highly successful, they also share an **IT-related approach** that has become a cultural trait: they all embraced **DevOps** as a way of delivering their products/ services to the clients. As security practitioners, we have the duty to ask ourselves – **where does security fit into this DevOps philosophy?**

**Corporate Culture in a DevOps supported Organization**

**DevOps** as we understand it is a **revolution inside an organization**, a business approach that promotes the **collaboration between software developers** and **IT Operations professionals** to allow **faster delivery cycles** in the best interest of the clients.

**How is this achievable?** Here comes the “*cultural thing*” - the organizations using this approach have **eliminated the wall between the Software Developers and the IT Operations professionals** and support a **totally integrated framework**, from the moment of consolidating development requirements, up to the delivery moment, passing through development, testing, bug fixing and release. The objective – or the new development style we may say – is the **Continuous Delivery Model**, with top performers like Amazon, Google or Facebook reaching rates of code delivery of thousand instances per day.

The foundation for all this, as [defined](http://itrevolution.com/the-three-ways-principles-underpinning-devops/) by [Gene Kim](http://www.realgenekim.me/), one of the movement promoters, resides in 3 pillars:

**1. Systems Thinking** – seeing the entire forest, not just a few trees, looking at the entire value stream that must deliver to the clients the expected result, without barriers of teams and platforms.

**2. Shorten and Amplify Feedback Loops** – actually the large feedback loops corresponding to the classic SDLC approach are condensed to sub-processes and stages feedback loops, with people from development and IT operations working together to collect it, analyze it and react accordingly, as fast as possible.

**3. Continuous Experimentation and Learning** – a new way of looking at things, getting rid of silos and the blame passing culture, encouraging creativity, engagement and shared responsibility. One of the funny aspects that Gene was telling in a podcast is that the most interesting part is when development guys are awakened at 3 a.m. in the morning to fix a bug and they like it and can’t conceive otherwise because they and IT Ops work together to deliver the expected results to the clients.

![devops_secops](http://businessinsights.bitdefender.com/hs-fs/hub/341979/file-1076657267-jpg/Blog_pics/devops_secops.jpg)

An [interesting survey](https://puppetlabs.com/wp-content/uploads/2013/03/2013-state-of-devops-report.pdf) reported by Puppet Labs in 2013, described **DevOps adoption** and what it could bring to the new computing sphere, revealing that the **high performers are deploying code 30 times faster and have 50% fewer failures.**

All these are great numbers reflecting an impressive picture: we have faster development, rapid bug fixing, shortened cycles, and continuous delivery. But a question arises: **what about information security? What’s happening with it under this new paradigm?**

As an ISMS auditor, I have had the chance to see a few software development companies and what struck me was the almost impossible “*marriage*” between development and security – the latter being perceived as slowing down the systems, good only for compliance. But in the DevOps approaches, InfoSec can be integrated too from the beginning of the value chain and this irreconcilable gap can be narrowed.

**Any DevOps implementation is supported by an integrated system of tools like:**

** - Software-defined infrastructure** – either virtualized in the datacenter or an entire Platform-as-a Service package from one of the providers;

** - Continuous monitoring** – for infrastructures but also security monitoring – they are essential for the **testing**, for **shortening feedback cycles** and for **early detection** of any malfunctioning and security incidents;

**** - **Version management and change management platforms** – essential for maintaining the **business logic** and for preparing the delivery, but also for **rapid identification** of failures and incidents;

**** - **Configuration management** – that helps the IT Ops and the InfoSec Ops deliver what is needed by development, which is the unity of configuration between the development, testing and production. Server virtualization is a valid option that facilitates enormously this aspect.

**** - **Code inspection and review** – that can be ensured by **specialized tools** and **dedicated teams**. It is a practice that dramatically increases the quality of code and its security and a probable explanation for the 50% reduction of failure rates.

** - Benchmarking** – dashboards and metrics are an essential ally for maintaining the governance of the entire process.

**Security** is a component that can and has to be present along each of these processes, as security for virtualized environments and SDNs, security monitoring and secure practices for version management, configuration and change management, code inspection and testing.

As for the classic approach based on large cycles – **compliance audit**, **penetration testing** and **vulnerability management** – they are a part of our lives that will remain as a **supplementary check and assurance**.

 [![Wondering how we approach this? Download this: “AWS & the use of Gaming strategies: imitation and reality”](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/341979/a144ed62-d02f-4a22-9ea7-fee490abedaf.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/341979/a144ed62-d02f-4a22-9ea7-fee490abedaf)

### Explore More Topics

- [Enterprise Security (743)](https://businessinsights.bitdefender.com/topic/enterprise-security)
- [Threat Research (201)](https://businessinsights.bitdefender.com/topic/threat-research)
- [Cloud Security (174)](https://businessinsights.bitdefender.com/topic/cloud-security)
- [SMB Security (170)](https://businessinsights.bitdefender.com/topic/smb-security)
- [Ransomware (166)](https://businessinsights.bitdefender.com/topic/ransomware)
- [Privacy and Data Protection (137)](https://businessinsights.bitdefender.com/topic/privacy-and-data-protection)
- [Cybersecurity Awareness (134)](https://businessinsights.bitdefender.com/topic/cybersecurity-awareness)
- [Endpoint Protection & Management (126)](https://businessinsights.bitdefender.com/topic/endpoint-protection-management)
- [Endpoint Detection and Response (124)](https://businessinsights.bitdefender.com/topic/endpoint-detection-and-response)
- [Managed Detection and Response (119)](https://businessinsights.bitdefender.com/topic/managed-detection-and-response)
- [Virtualization & Data Center Security (82)](https://businessinsights.bitdefender.com/topic/virtualization-data-center-security)
- [Threat Intelligence (76)](https://businessinsights.bitdefender.com/topic/threat-intelligence)
- [IT Compliance & Regulations (71)](https://businessinsights.bitdefender.com/topic/it-compliance-regulations)
- [Bitdefender Threat Debrief (55)](https://businessinsights.bitdefender.com/topic/bitdefender-threat-debrief)
- [Managed Service Providers (53)](https://businessinsights.bitdefender.com/topic/managed-service-providers)
- [#Featured (52)](https://businessinsights.bitdefender.com/topic/featured)
- [Advanced Persistent Threats (46)](https://businessinsights.bitdefender.com/topic/advanced-persistent-threats)
- [Events (38)](https://businessinsights.bitdefender.com/topic/events)
- [Independent Testing (18)](https://businessinsights.bitdefender.com/topic/independent-testing)
- [Cybersecurity Advisory Services (9)](https://businessinsights.bitdefender.com/topic/cybersecurity-advisory-services)
- [Podcast (3)](https://businessinsights.bitdefender.com/topic/podcast)
- [top (2)](https://businessinsights.bitdefender.com/topic/top)

See all topics

### Subscribe to Blog Updates

## Read more about this topic

<https://businessinsights.bitdefender.com/isps-can-and-should-protect-users-against-ddos-attacks?hsLang=en-us>

### [ISPs Can and Should Protect Users Against DDoS Attacks](https://businessinsights.bitdefender.com/isps-can-and-should-protect-users-against-ddos-attacks?hsLang=en-us)

<https://businessinsights.bitdefender.com/the-link-between-iot-botnets-and-the-isps-unpreparedness?hsLang=en-us>

### [The Link Between IoT Botnets and the ' 'ISP's Unpreparedness](https://businessinsights.bitdefender.com/the-link-between-iot-botnets-and-the-isps-unpreparedness?hsLang=en-us)

<https://businessinsights.bitdefender.com/the-security-of-legacy-devices-should-not-be-the-bane-of-isps?hsLang=en-us>

### [The Security of Legacy Devices Should Not Be the Bane of ISPs](https://businessinsights.bitdefender.com/the-security-of-legacy-devices-should-not-be-the-bane-of-isps?hsLang=en-us)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2685110570-png/Bitdefender-Mar2015-Theme/Images/avatar_img_footer.png)

![bitdefender](https://businessinsights.bitdefender.com/hs-fs/file-2676149282-png/Bitdefender-Mar2015-Theme/Images/logo_white_footer.png)

- [![https://twitter.com/Bitdefender_Ent](https://businessinsights.bitdefender.com/hs-fs/file-2658233851-png/Bitdefender-Mar2015-Theme/Images/ft_soc_tw.png?width=33&name=ft_soc_tw.png)](https://twitter.com/Bitdefender_Ent)
- [![Linkedin-icon-300x300](https://businessinsights.bitdefender.com/hs-fs/hubfs/Bitdefender-Mar2015-Theme/Images/Linkedin-icon-300x300.png?width=33&name=Linkedin-icon-300x300.png)](https://www.linkedin.com/company/bitdefender-gravityzone-enterprise-security)
- [![](https://businessinsights.bitdefender.com/hs-fs/file-2676149307-png/Bitdefender-Mar2015-Theme/Images/ft_soc_yt.png)](https://www.youtube.com/user/BitdefenderSecurity)

- [Legal Terms](https://www.bitdefender.com/legal/)
- [Privacy Policy](https://www.bitdefender.com/site/view/legal-privacy-policy-for-bitdefender-websites.html)
- [EULA](https://www.bitdefender.com/site/view/legal-eula.html)
- [Contact Us](https://www.bitdefender.com/business/contact.html)

Copyright © 1997-2023 Bitdefender All rights reserved.

![](https://px.spiceworks.com/px/5rec)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Horatiu Bandoiu",
    "url" : "https://businessinsights.bitdefender.com/author/horatiu-bandoiu"
  },
  "datePublished" : "2014-06-23T16:20:00.000Z",
  "headline" : "DevOps and SecOps – the Impossible Conciliation?",
  "image" : [ "//businessinsights.bitdefender.com/hs-fs/hub/341979/file-1076657267-jpg/Blog_pics/devops_secops.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://businessinsights.bitdefender.com/devops-secops-impossible-conciliation",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://businessinsights.bitdefender.com/hubfs/Bitdefender_Logo_Transparent-2.png"
    },
    "name" : "Bitdefender"
  }
}
```