{"id":34342,"date":"2019-10-15T15:45:23","date_gmt":"2019-10-15T14:45:23","guid":{"rendered":"https:\/\/www.intelligentcio.com\/eu\/?p=34342"},"modified":"2019-10-15T15:45:26","modified_gmt":"2019-10-15T14:45:26","slug":"synopsys-study-highlights-impact-of-devops-on-software-security","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/10\/15\/synopsys-study-highlights-impact-of-devops-on-software-security\/","title":{"rendered":"Synopsys study highlights impact of DevOps on software security"},"content":{"rendered":"\n<p>Synopsys has released\u00a0BSIMM10, the latest version of the Building Security In Maturity Model (BSIMM), designed to help organisations plan, execute, mature and measure their software security initiatives (SSIs). <\/p>\n\n\n\n<p>Synopsys has used the BSIMM nearly 450 times across 185 firms over the\npast decade and this 10th iteration reflects software security activities\nobserved across 122 firms. <\/p>\n\n\n\n<p>BSIMM10 also highlights the impact of DevOps on software security\ninitiatives, the emergence of a new wave of engineering-driven security efforts\nand how firms progress through three phases of software security maturity. <\/p>\n\n\n\n<p>\u201cSince 2008, the BSIMM has served as an effective tool\nfor understanding how organisations of all shapes and sizes, including some of\nthe most advanced security teams in the world, are executing their software\nsecurity strategies,\u201d said Jim Routh, Head of Enterprise Information Risk\nManagement at MassMutual.&nbsp;<\/p>\n\n\n\n<p>\u201cThe current BSIMM data reflects how many organisations are adapting their approaches to address the new dynamics of modern development and deployment practices, such as shorter release cycles, increased use of automation and software-defined infrastructure.\u201d<\/p>\n\n\n\n<p>BSIMM10 describes the work of 7,900 software security professionals\nwhose efforts guide and maximise the security efforts of nearly 470,000\ndevelopers working on more than 173,000 applications. <\/p>\n\n\n\n<p>BSIMM10 represents firms in industry verticals including financial\nservices, high tech, independent software vendors (ISVs), cloud, healthcare,\nInternet of Things (IoT), insurance and retail. <\/p>\n\n\n\n<p>Key findings from the BSIMM10 study:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>DevOps\u2019 impact on software security: <\/strong>The BSIMM data shows that the DevOps movement and the adoption of continuous integration and continuous delivery (CI\/CD) tooling are affecting the way that firms approach software security. This is seen in the BSIMM\u2019s addition of three new activities that reflect how firms are actively working to automate security activities to match the speed at which their business delivers functionality to market. BSIMM10 also includes updated descriptions and examples of existing activities to reflect how they are being implemented as part of modern DevOps organisations.<\/li><li><strong>The new wave of engineering-driven security culture: <\/strong>BSIMM10 is the first study to formally reflect changes in SSI culture, observed in a new wave of engineering-led software security efforts originating bottom-up in development and operations teams rather than top-down from a centralised software security group. In some organisations, an engineering-led security culture has overcome its struggle to establish and grow meaningful software security efforts. This new wave of engineering-driven security culture is emerging in response to both the demands of modern software delivery practices such as Agile and DevOps and undesirable friction with existing SSIs.<\/li><li><strong>Firms use the BSIMM to navigate their software security journey: <\/strong>BSIMM10<strong> <\/strong>is the first edition to define three phases of SSI maturity &#8211; emerging, maturing, optimising &#8211; and describe how different firms typically progress through them. The BSIMM data show that organisations improve demonstrably over time and many achieve a level of maturity where they focus on the depth, breadth and scale of the activities they\u2019re conducting rather than always striving for more activities.<\/li><\/ul>\n\n\n\n<p>\u201cLeading an effective software security initiative is challenging and the dramatic technological and organisational shifts brought on by DevOps and CI\/CD are not making that task easier,\u201d said Sammy Migues, Principal Scientist at Synopsys. <\/p>\n\n\n\n<p>\u201cAs a tool that constantly evolves to reflect the experiences of hundreds of software security groups around the world, the BSIMM and its community are invaluable resources, whether you\u2019re just beginning your journey, looking to optimise your program or grappling with new challenges.\u201d<\/p>\n\n\n\n<p>The BSIMM includes data collected from firms that have established real SSIs, quantifying the occurrence of 119 activities to show the common ground shared by many initiatives as well as the variations that make each initiative unique. <\/p>\n\n\n\n<p>The BSIMM data show that high-maturity initiatives are well-rounded, carrying out numerous activities in all 12 of the practices described by the model. Organisations can use the BSIMM to compare initiatives and determine which additional activities might be useful to support their overall strategies. <\/p>\n\n\n\n<p>To download the report, visit  <a href=\"https:\/\/www.bsimm.com\/\">bsimm.com\/<\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Synopsys has released\u00a0BSIMM10, the latest version of the Building Security In Maturity Model (BSIMM), designed to help organisations plan, execute, mature and measure their software security initiatives (SSIs). Synopsys has used the BSIMM nearly 450 times across 185 firms over the past decade and this 10th iteration reflects software security activities observed across 122 firms. [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":34345,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,6617,29,93],"tags":[1272,13596,13597,13598,7415],"class_list":["post-34342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-software","category-top-stories","tag-devops","tag-head-of-enterprise-information-risk-management-at-massmutual","tag-jim-routh","tag-ssi","tag-synopsys"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=34342"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34342\/revisions"}],"predecessor-version":[{"id":34344,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/34342\/revisions\/34344"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/34345"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=34342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=34342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=34342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}