Welcome!

Adobe Flex Authors: Matthew Lobas, PR.com Newswire, Shelly Palmer, Kevin Benedict

Related Topics: @CloudExpo, Microservices Expo, Linux Containers, @DevOpsSummit

@CloudExpo: Article

Islands Are Wasteful in #DevSecOps | @DevOpsSummit @CAinc #DevOps #DX

DevSecOps is about breaking down silos and waste along the software development lifecycle

DevSecOps - a trend around transformation in process, people and technology - is about breaking down silos and waste along the software development lifecycle and using agile methodologies, automation and insights to help get apps to market faster. This leads to higher quality apps, greater trust in organizations, less organizational friction, and ultimately a five-star customer experience.

These apps are the new competitive currency in this digital economy and they're powered by data. Without data or data-based interactions, these apps would be of little value to the user and would be just static one-dimensional bulletin boards. Imagine a banking app, for example, that does not give you data about your account or let you take some action. How much value is this bringing to the user?

IT's dirty little secret
Most companies, with the exception of recently born-in-the-cloud "unicorns," know that critical data resides in many different systems-of-record that have persevered through infrastructure refresh cycles or have been added via mergers and acquisitions. A dirty IT secret is that systems-of-record rarely go away as new ones are added, so coexistence is the unspoken reality. The apps you are speeding to market are - or should be - capable of interacting with many legacy code bases.

This legacy code base reality has implications for your organization, processes and tools as you apply DevOps principles. Here are three imperatives for every IT leader managing multiple code bases to build the right foundation for their Modern Software Factory.

  1. Break down your infrastructure-based operational silos. Every organization has specialized individuals who have specific knowledge of certain code bases and infrastructure types. Do your best to break down those reporting silos and infrastructure-based management fiefdoms. For example, have your Windows, Linux, Unix, AS-400, mainframe and even cloud system admins report to the same managers. Don't isolate your "legacy" Dev or Ops teams on an island as the data that resides on those "legacy" platforms is vital to your current and future apps. This practice will speed decision-making and reduce organizational friction, while also helping to overcome retention and talent shortage issues.
  2. Make your DevOps processes and tools inclusive of all your code bases and infrastructure types. Having a separate set of AppDev or DevSecOps tools and processes for each type of infrastructure or code base is antithetical to the business outcomes you want to achieve. This also reinforces silos - in this case, hardware and operating system silos - rather than breaking them down. You can't afford different ALM, release automation, service virtualization, test data management, app security testing, privileged access management, automation, APM or infrastructure management toolchains. Not only is software license duplication expensive but so are the supporting costs to host, maintain, learn, manage and upgrade those tools. That is wasteful and inhibits your ability to fund innovation. Steer clear of vendors pushing point tools that reinforce islands of infrastructure and the lock-in that results. Always ask if that DevOps-enabling software works across your infrastructure.
  3. Use modern app architectures like APIs and Microservices. With APIs, developers can leverage data and build integrations between disparate systems faster and with fewer errors. With this approach, your APIs need to be adequately catalogued, which is more often than not an area developers glance over, to be used by teams across code base and infrastructure types. Microservices also allow for parallel development by enabling small autonomous teams to develop, deploy and scale their respective services independently. Monolithic architectures and hard-coded data paths should be a relic of the past.

There's a lot to learn about DevSecOps as it's a dynamic and evolving practice with many nuances. Flexible app architectures, heterogeneous tool chains and inclusive organizational structures can eliminate islands, unnecessary costs and friction as you advance on your DevSecOps journey.

More Stories By Cameron Van Orman

Cameron Van Orman is vice president for solution and product marketing and enterprise management at CA Technologies. He leads a team of 20 people who together devise strategy for the business unit and develop all aspects of product marketing. Cameron and his team also lead the way for early product adoption in enterprise management.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use of real time applications accelerate, legacy networks are no longer able to architecturally support cloud adoption and deliver the performance and security required by highly distributed enterprises. These outdated solutions have become more costly and complicated to implement, install, manage, and maintain.SD-WAN offers unlimited capabilities for accessing the benefits of the cloud and Internet. ...
Business professionals no longer wonder if they'll migrate to the cloud; it's now a matter of when. The cloud environment has proved to be a major force in transitioning to an agile business model that enables quick decisions and fast implementation that solidify customer relationships. And when the cloud is combined with the power of cognitive computing, it drives innovation and transformation that achieves astounding competitive advantage.
DXWorldEXPO LLC announced today that "IoT Now" was named media sponsor of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
SYS-CON Events announced today that Silicon India has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Published in Silicon Valley, Silicon India magazine is the premiere platform for CIOs to discuss their innovative enterprise solutions and allows IT vendors to learn about new solutions that can help grow their business.
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
SYS-CON Events announced today that CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5–7, 2018, at the Javits Center in New York City, NY. CrowdReviews.com is a transparent online platform for determining which products and services are the best based on the opinion of the crowd. The crowd consists of Internet users that have experienced products and services first-hand and have an interest in letting other potential buye...
Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT staff augmentation services for software technology providers. By providing clients with unparalleled niche technology expertise and industry experience, Chetu has become the premiere long-term, back-end software development partner for start-ups, SMBs, and Fortune 500 companies. Chetu is headquartered in Plantation, Florida, with thirteen offices throughout the U.S. and abroad.
The standardization of container runtimes and images has sparked the creation of an almost overwhelming number of new open source projects that build on and otherwise work with these specifications. Of course, there's Kubernetes, which orchestrates and manages collections of containers. It was one of the first and best-known examples of projects that make containers truly useful for production use. However, more recently, the container ecosystem has truly exploded. A service mesh like Istio addr...
SYS-CON Events announced today that DatacenterDynamics has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY. DatacenterDynamics is a brand of DCD Group, a global B2B media and publishing company that develops products to help senior professionals in the world's most ICT dependent organizations make risk-based infrastructure and capacity decisions.
Nicolas Fierro is CEO of MIMIR Blockchain Solutions. He is a programmer, technologist, and operations dev who has worked with Ethereum and blockchain since 2014. His knowledge in blockchain dates to when he performed dev ops services to the Ethereum Foundation as one the privileged few developers to work with the original core team in Switzerland.