Successful DevSecOps implementation need maturity assessment, reference models (practices, processes and tools) and implementation guidance.
Various toolsets are available to suit different implementation scenarios. Mixed approach is also possible.
Maturity assessment indicating as-is state, gap and readiness enables enterprise to understand pre-requisites Enables targeted efforts towards SMART goals maximizing ROI with realistic timelines Reference model to enable DevSecOps establishment proven models with best practices options for better efficiency or cost appreciate variations across eco-systems with different needs Implement guidance across all aspects viz. people, process, tools implementation using variation of toolchains optimization of process via monitoring and customizations upgrades, replacement of tools and defining of roles and boundaries Recommended approach for DevSecOps to bring execution speed
Agility to meet the rapidly changing business needs due to technology evolution, consumer behavior and peer competitiveness.
Planning
threat modeling and analysis
Design
resilient microservices, secure API gateways, IAM
containerize, configuration validation, feature switches, traffic shaping, rollback etc.
Opslogging, monitoring, intrusion, DDoS, RCA & FMEA.
AWS services are preferred to individual self managed alternatives as they can scale in an enterprise eco-system and is patched and upgraded with less hassle.