Council Post: Four Best Practices For Aligning The Work Of Security And Engineering Teams

  • 📰 ForbesTech
  • ⏱ Reading Time:
  • 51 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 24%
  • Publisher: 59%

Technology Technology Headlines News

Technology Technology Latest News,Technology Technology Headlines

Today, cybersecurity initiatives face powerful and potentially disruptive forces.

How can software companies best address these rapidly shifting forces while complying with regulations? In short, align the work of security and development teams. What form that takes will vary from company to company, but here are a few best practices for ensuring an effective cross-organizational approach.Security isn’t just something to teach people. It has to be cultural, uniting IT and engineering organizations.

Carefully evaluate which part of your company is best suited to own the management of areas of potential exposure to risk, such as open source software and third-party components. For example, this may rest with a centralized team, with your engineering/DevSecOps teams, anPlan for some development time going to security, but also make this process as efficient as possible.

Unpredictable work, such as when a vulnerability is exposed in your code or in the code from a third party, will likely still be necessary. But having a clear plan, understood by security and engineering teams alike, will help your organization prioritize and address these issues.

The output of your security scans may include information crucial to multiple teams within your organization: legal, security, software development/engineering, product management and/or the OSPO. A software producer must have secure SDLC processes, a tightly integrated delivery pipeline and SBOM integration with the DevSecOps pipelines.

 

Thank you for your comment. Your comment will be published after being reviewed.
Please try again later.
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

 /  🏆 318. in TECHNOLOGY

Technology Technology Latest News, Technology Technology Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

Council Post: Lessons Learned From Breaches: Updating Your Incident Response PlanCybersecurity is a fast-moving field, and recent cases against CISOs offer learnings that encourage us to revisit our policy for improvements.
Source: ForbesTech - 🏆 318. / 59 Read more »

Council Post: How Machine Learning And AI Could Solve Drug ShortagesAlthough AI’s presence on the public stage has become more prevalent in just the past year, it has been used in the medical field for more than four decades.
Source: ForbesTech - 🏆 318. / 59 Read more »