{"id":98192,"date":"2024-10-08T07:48:32","date_gmt":"2024-10-08T07:48:32","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=98192"},"modified":"2026-04-10T17:45:26","modified_gmt":"2026-04-10T15:45:26","slug":"devsecops-what-devops-needs-to-be-when-it-grows-up","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/","title":{"rendered":"DevSecOps: What DevOps NEEDS to Be When It Grows Up"},"content":{"rendered":"<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">DevOps Security: Where Are We Now?<\/h2>\n\n\n\n<p>DevOps represents the fundamental cultural shift in software engineering towards performance: high performing teams, and high performance code.<\/p>\n\n\n\n<p><strong>In DevOps, security was never a primary consideration.<\/strong><\/p>\n\n\n\n<p><strong><a href=\"https:\/\/checkmarx.com\/learn\/devsecops\/devsecops\/\">DevSecOps<\/a> represents the reality that <a href=\"https:\/\/checkmarx.com\/glossary\/devops-security\/\">DevOps<\/a> must grow to encompass security. <\/strong>Eventually, performant code will mean secure code by default &#8211; but we&#8217;re not there yet. How do we get there?<\/p>\n\n\n\n<p>Let\u2019s start with where we are now. Earlier this year, Checkmarx ran a survey asking organizations about their current AppSec programs. One of our questions specifically asked: \u201cWhere are you on your DevSecOps journey?\u201d You can see the answers below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"396\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-1024x396.webp\" alt=\"Devops Security Maturity Survey results\" class=\"wp-image-98234\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-1024x396.webp 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-300x116.webp 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-768x297.webp 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-1536x593.webp 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-01-2048x791.webp 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><br>On the surface, this doesn\u2019t look too bad\u2026 until you consider the details. Based on our scaling, \u201cmedium\u201d only represents the \u201cdefinition and strategy\u201d phase. The actual process of integration and automation is where companies actually start \u201cdoing\u201d DevSecOps, and only 1 in 5 companies surveyed have reached that stage in some form.<\/p>\n\n\n\n<p>And let\u2019s be clear \u2013 integration and automation are the goals of DevSecOps. DevSecOps is about taking the needs and outcomes of application security and integrating them with the processes and culture of DevOps. In 10 years, there should be no difference between \u201cDevOps\u201d and \u201cDevSecOps.\u201d DevSecOps is just what DevOps needs to be when it grows up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">DevSecOps: The Path to Maturity<\/h2>\n\n\n\n<p>OK \u2013 how do we get there? If I were to create a rough sketch of DevSecOps maturity, it would look like this:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"519\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-1024x519.webp\" alt=\"DevSecOps maturity progress diagram \" class=\"wp-image-98236\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-1024x519.webp 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-300x152.webp 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-768x389.webp 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-1536x778.webp 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-02-2048x1037.webp 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><br>Let\u2019s start on the bottom. This is traditionally where <a href=\"https:\/\/checkmarx.com\">AppSec<\/a> finds vulnerabilities, and essentially throws them over the wall to developers and says \u201chere, fix these.\u201d I have some bad news for you, this is actually \u201cShift Left\u201d in action. Maybe that\u2019s flippant and a bit unfair; but it is the base level of maturity that puts organizations on the road to DevSecOps.<\/p>\n\n\n\n<p>The next level focuses on the developer experience. Here, AppSec teams and developers alike realize that \u201cShift Left\u201d isn\u2019t really working. Not because anyone is bad, uncaring, or unintelligent, but because it is only intended to be the first step. In that stage, AppSec got tools to find and triage vulnerabilities. Now developers need tools to manage those vulnerabilities themselves without breaking their workflow. The \u201cdeveloper experience\u201d stage of maturity focuses on IDE-integrations, remediation guidance, and other ways to keep developers focused without greatly disrupting their flow.<\/p>\n\n\n\n<p>But like \u201cShift Left\u201d, focusing on the developer experience eventually hits diminishing returns. Organizations will get stuck, and then they will need to begin to move towards the third step of maturity. This is where you take the foundational understandings of the first two steps, and work to define a DevSecOps culture.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">DevSecOps: Ending the Guesswork is Worth the Effort<\/h2>\n\n\n\n<p>Culture is hard to change, but luckily, DevOps people have done it before. If you go back to the early days of Agile and Scrum, teams would hold daily standups, and then go back to working exactly the way they had before. But, as modern DevOps organizations can confirm, it\u2019s worth the effort. For DevSecOps, it\u2019s also worth the effort: By making this transition, teams can finally end the guesswork of which vulnerabilities are critical and have to be dealt with right away, and which are just minor fixes that can wait.<\/p>\n\n\n\n<p>With Checkmarx\u2019 automatic prioritization, they already know. Developers can use their time more efficiently and substantially reduce alert-fatigue (since alert noise is cut by up to 90%). And with features such as AI Coding Assistant, guided- and auto-remediation, best-fix location, and Codebashing, Checkmarx also gives developers the tools and information needed to fix vulnerabilities fast.<\/p>\n\n\n\n<p>Here is an example of a Checkmarx customer journey, and you can see them go through the stages and the results:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"407\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-1024x407.webp\" alt=\"Mature Devops security remediation results highlight\" class=\"wp-image-98237\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-1024x407.webp 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-300x119.webp 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-768x305.webp 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-1536x610.webp 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Images-for-the-blog-03-2048x814.webp 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><br>This is a chart showing the number of vulnerabilities remediated by a Fortune 100 company, and it\u2019s a powerful representation of what things look like when teams integrate.<\/p>\n\n\n\n<p>If you\u2019re curious about the types of things this customer did to get from the left to right side of the graph above, here we\u2019ve got some examples ready based on where you are from a maturity standpoint:<\/p>\n\n\n\n<p><strong>Shift Left:<\/strong> If you just need to get something in place to start getting vulnerabilities over to developers, the easiest way is to integrate your AppSec tools with your feedback tool (be cautious here, you don\u2019t want to suddenly shunt 10,000 JIRA tickets over to the devs, so set some policies around it). <a href=\"https:\/\/checkmarx.com\/player-demo-in-ide-jira-integration\/\">Click here<\/a> to see a video showing how easy that integration is to do with Checkmarx.<\/p>\n\n\n\n<p><strong>Developer Experience:<\/strong> The easiest way to start improving your developer experience is by integrating with their IDE of choice. This is also simple to do with Checkmarx, and here is a video showing how: <a href=\"https:\/\/checkmarx.com\/player-demo-ide-integrating-with-checkmarx-one\/\">Watch Now!<\/a><\/p>\n\n\n<script src=\"https:\/\/player.vimeo.com\/api\/player.js\"><\/script>\n<script src=\"https:\/\/www.youtube.com\/iframe_api\"><\/script>\n<div class=\"aticle-video-wrapper\">\n        \n    <div class=\"aticle-video-box\">\n                    <iframe width=\"913\" height=\"514\" src=\"https:\/\/www.youtube.com\/embed\/kMsJx3sIDq0?enablejsapi=1\" class=\"youtube-player\" title=\"YouTube video player\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n                <\/div>\n        <\/div>\n<script>\n    \/\/ For youtube video only\n    var playerReady = false;\n    var player;\n\n    function onYouTubeIframeAPIReady() {\n        const iframe = document.querySelector('iframe.youtube-player');\n        if (!iframe) {\n            console.warn('Youtube player not found');\n            return;\n        }\n\n        player = new YT.Player(iframe, {\n            events: {\n                onReady: () => {\n                    playerReady = true;\n                }\n            }\n        });\n    }\n\n\n    document.addEventListener('DOMContentLoaded', () => {\n        let videoBtn = document.querySelector('.youtube-overlay-image-link');\n\n        if (!videoBtn) return;\n\n\n        videoBtn.addEventListener('click', (e) => {\n            e.preventDefault();\n            videoBtn.style.display = 'none';\n\n            if (!player || !playerReady) {\n                console.warn('The player isn\\'t ready yet');\n                return;\n            }\n\n            player.playVideo();\n\n        })\n    })\n<\/script>\n\n\n<p><strong>DevSecOps: <\/strong>We\u2019ll explore the keys to DevSecOps in detail in the next blog, particularly culture, automation, and speed, but we mentioned the importance of policy management in our first bullet point. While designing policy is difficult \u2013 it relies on great communication between development teams and security teams \u2013 creating and implementing policy with Checkmarx is easy. Here\u2019s a video showing how it\u2019s done: <a href=\"https:\/\/checkmarx.com\/player-demo-policy-management-with-checkmarx\/\">Watch Now!<\/a> <\/p>\n\n\n\n<p>This blog is just our first in a series on DevSecOps. Our next blog will focus on how to change culture, the need for automation, and the true meaning of \u201cspeed\u201d within the context of DevSecOps. In the meantime, the videos I just listed are only some a few of those you can check out over on YouTube showing how easy it is for platform engineers and developers to integrate and work with Checkmarx One. <a href=\"https:\/\/www.youtube.com\/playlist?list=PLutAeDk0sfciZw4UMMPkXBXVP8ZUlCef2\">Check them out here!<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>DevOps Security: Where Are We Now? DevOps represents the fundamental cultural shift in software engineering towards performance: high performing teams, and high performance code. In DevOps, security was never a primary consideration. DevSecOps represents the reality that DevOps must grow to encompass security. Eventually, performant code will mean secure code by default &#8211; but we&#8217;re [&hellip;]<\/p>\n","protected":false},"author":92,"featured_media":100096,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[84],"tags":[86,144,147],"class_list":["post-98192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-application-security","tag-devops","tag-devsecops"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DevOps Security: What DevOps NEEDS to Be When It Grows Up<\/title>\n<meta name=\"description\" content=\"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DevOps Security: What DevOps NEEDS to Be When It Grows Up\" \/>\n<meta property=\"og:description\" content=\"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2024-10-08T07:48:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-10T15:45:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1792\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Jonathan Singer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jonathan Singer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\"},\"author\":{\"name\":\"Jonathan Singer\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19\"},\"headline\":\"DevSecOps: What DevOps NEEDS to Be When It Grows Up\",\"datePublished\":\"2024-10-08T07:48:32+00:00\",\"dateModified\":\"2026-04-10T15:45:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\"},\"wordCount\":952,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp\",\"keywords\":[\"Application Security\",\"DevOps\",\"DevSecOps\"],\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\",\"name\":\"DevOps Security: What DevOps NEEDS to Be When It Grows Up\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp\",\"datePublished\":\"2024-10-08T07:48:32+00:00\",\"dateModified\":\"2026-04-10T15:45:26+00:00\",\"description\":\"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp\",\"width\":1792,\"height\":1024,\"caption\":\"Integrate SCA into DevSecOps\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19\",\"name\":\"Jonathan Singer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg\",\"caption\":\"Jonathan Singer\"},\"url\":\"https:\/\/checkmarx.com\/author\/jonathansinger\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DevOps Security: What DevOps NEEDS to Be When It Grows Up","description":"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/","og_locale":"en_US","og_type":"article","og_title":"DevOps Security: What DevOps NEEDS to Be When It Grows Up","og_description":"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.","og_url":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2024-10-08T07:48:32+00:00","article_modified_time":"2026-04-10T15:45:26+00:00","og_image":[{"width":1792,"height":1024,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp","type":"image\/webp"}],"author":"Jonathan Singer","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Jonathan Singer","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/"},"author":{"name":"Jonathan Singer","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19"},"headline":"DevSecOps: What DevOps NEEDS to Be When It Grows Up","datePublished":"2024-10-08T07:48:32+00:00","dateModified":"2026-04-10T15:45:26+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/"},"wordCount":952,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp","keywords":["Application Security","DevOps","DevSecOps"],"articleSection":["Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/","url":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/","name":"DevOps Security: What DevOps NEEDS to Be When It Grows Up","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp","datePublished":"2024-10-08T07:48:32+00:00","dateModified":"2026-04-10T15:45:26+00:00","description":"Learn why Devops Security naturally leads to Devsecops. Learn why DevSecOps is essential for building secure and resilient applications.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/devsecops-what-devops-needs-to-be-when-it-grows-up\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/10\/Web-page-End-The-Guesswork-blog-e1744343906169.webp","width":1792,"height":1024,"caption":"Integrate SCA into DevSecOps"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/12874993aa841b57e429c631b192aa19","name":"Jonathan Singer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_92.jpg","caption":"Jonathan Singer"},"url":"https:\/\/checkmarx.com\/author\/jonathansinger\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/98192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/92"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=98192"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/98192\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/100096"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=98192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=98192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=98192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}