• About
  • Subscribe
  • Contact
Friday, May 9, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Business Applications & Databases

Use platform engineering to scale app security practices

Manjunath Bhat by Manjunath Bhat
July 10, 2023
Photo by Pixabay: https://www.pexels.com/photo/three-people-sitting-beside-table-416405/

Photo by Pixabay: https://www.pexels.com/photo/three-people-sitting-beside-table-416405/

Scaling DevSecOps practices across product teams is critical but difficult to achieve. Software engineering leaders leading platform teams should integrate pertinent security tools as part of internal developer platforms to deliver secure software at scale.

See Gartner research for a sample listing of tools – Cool Vendors in Platform Engineering for Scaling Application Security Practices and How to Select DevSecOps Tools for Secure Software Delivery.

A platform approach to supporting DevSecOps workflows reduces the potential attack surface while still enabling development teams to deliver at scale.

Instead of having individual product teams implement security tools and practices at their own discretion, platform teams must provide “secure paved roads.” This ensures consistency and reduces the cognitive load of implementing security controls. The idea is to make the secure path the default path to production.

There are two prerequisite actions to making the secure path, the default path:

First, secure the software supply chain

Second, adopt a platform approach to application security

See Figure 1 for a reference model that shows how security capabilities can be integrated with IDPs.

Figure 1

Why integrate security tools as part of IDPs

Supply-chain levels for software artefacts, or SLSA (pronounced “salsa”) is a security framework – a checklist of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure.

One of the guiding principles of SLSA is to minimise the number of trusted platforms used for software development and execution. This is because platforms expand the attack surface for software supply chain attacks. Therefore, minimising the number of platforms decreases the attack surface.

As we saw in the case of SolarWinds, software development pipelines can be a prime target for supply chain attacks. Hardening platforms so they can be trusted involves significant effort and expensive manual work. Therefore, concentrating trust in fewer tools and platforms reduces cost, effort and risk. This is why we recommend IDPs and also integrating security workflows as part of IDPs.

Concentrate trust in shared infrastructure. For example, instead of each team within an organisation maintaining their own build platform, use a shared build platform.

- Source: Guiding Principles, SLSA

Gartner survey data reveals a missed opportunity

Platform teams focus on improving developer experience, developer productivity, software quality and delivery speed. According to Gartner’s 2022 Software Engineering Leaders Role Survey, only 25% of respondents cited “reduced security risks’’ as one of the top three goals for platform engineering and only 6% ranked it as the topmost goal. See Figure 2.

Using platform engineering to scale application security practices across the organisation is often an underappreciated and missed opportunity.

Figure 2

First published on Gartner Blog Network

Related:  Poor CS&S engagement has an economic cost
Tags: application securityDevSecOpsGartnerplatform engineeringSLSA
Manjunath Bhat

Manjunath Bhat

Manjunath (Manju) Bhat is a Sr. Director Analyst within I&O responsible for managing the research agenda for DevOps. He advises clients on a range of DevOps-related initiatives that include site reliability engineering (SRE), chaos engineering, programmable infrastructure, DevSecOps, DevOps toolchains and agile best practices. Bhat sees the shift from project to product-based operating models alongside a transition to cloud-native architectures as two tectonic shifts affecting DevOps. In addition, his coverage extends to SaaS Management platforms, unified endpoint management tools and workplace analytics with a focus on securing the digital workplace.

No Result
View All Result

Recent Posts

  • ARTHALAND chooses OutSystems to advance real estate sustainability
  • Experts warn against AI-powered deepfake impersonation scams
  • Dropbox updates universal search and knowledge management product
  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe