Achieving DevSecOps maturity with GitHub

August 13, 2020 // 1 min read

image

GitHub has been rapidly evolving into a complete development platform over the past year and a half, with the addition of native CI/CD capabilities using GitHub Actions. But did you know that you can implement DevSecOps natively in GitHub Enterprise, using GitHub Advanced Security?

Before we dig into the how, let’s align on a definition of DevSecOps maturity. OWASP created the DevSecOps Maturity Model (DSOMM) framework to show application security measures which can be applied when using DevOps strategies and how these can be prioritized. DSOMM strives to incrementally increase the effectiveness of a security program from Level 1 (least mature) to Level 4 (a fully implemented DevSecOps program built into your DevOps practices).

There are four main evaluation criteria in DSOMM:

  1. Static depth: How comprehensive the static code scan that you are performing within the AppSec CI pipeline is
  2. Dynamic depth: How comprehensive the dynamic scan that is being run within the AppSec CI pipeline is...

Download the PDF to keep reading →

Wondering how GitHub can help your business?

Tell us more about your needs