DevSecOps: Why, Benefits and Culture Shift
29 November, 2022
Head of Engineering at Xero
Why DevSecOps?
The first factor is Speed - the rate at which code is pushed to repos and released into production. Continuously Integrate the code. Fast feedback loop
The second factor is Scale - the applications being developed must scale to the demands of the customers
The third factor is Safe - Adoption of security through the entire SDLC
The fourth factor is Simple - Must always strive for simple and efficient ways. Standardisation of tools
The fifth factor is Stewardship - Lesser hand-offs between teams and/or members
Business Benefits
1 - Early identification of security / operational risks
2 - Faster time to market
3 - Faster feedback loop
4 - Lower the cost of change/delivery
5 - Evidence of compliance
Principles On How We Can Build A DevSecOps Culture?
1 - Short and frequent development cycles
2 - Incorporate and automate security as much as possible from the very beginning
3 - Leverage technologies that help agility
4 - Wider collaboration with all the teams (InfoSec and all the teams)
5 - Frequent communication
6 - Lesser hand-offs
7 - Influence in the culture shift within wider Xero (inputs on how we can improve the DevSecOps maturity)
8 - Practice what you preach (Transformation through delivery)
Discover Plato
Scale your coaching effort for your engineering and product teams
Develop yourself to become a stronger engineering / product leader
Related stories
5 February
As a Leader, can you show your weaknesses to your team? Your vulnerability to your team? Not only can you, you must.

Kamal Raj Guptha R
Engineering Manager at Jeavio
5 February
Giving confusing direction to team is perilous. But giving clarity is so very important.

Kamal Raj Guptha R
Engineering Manager at Jeavio
20 January
As a Lead or Manager, one could naturally incline more towards being either people oriented or task oriented. Which is better? Do you know which side you lean more towards?

Kamal Raj Guptha R
Engineering Manager at Jeavio
4 January
I was hired at HUMAN in 2021 to manage a team that went from hybrid to completely remote working environment because of COVID.

Ahsan Habib
VP Software Engineering at human
10 December
Supporting principles on why being data led (not driven) helps with the story telling.
Vikash Chhaganlal
Head of Engineering at Xero