DevSecOps — How Security Can Be Assimilated Into Scrum

Fredrik Carleson
Serious Scrum
Published in
7 min readJan 12, 2021

--

Borg ship from wallpapersafari.com

Scrum is today the de-facto standard for software development. As more extensive parts of the organization become involved in Scrum, they have to adapt to an agile way of working. It’s like the Borgs “Resistance is futile.” Scrum will assimilate you. This article describes how security operations can be assimilated into Scrum.

Testing was among the first to adjust to a new reality. In the old days, testing was done last. Suddenly testing had to be done earlier and continuously not to be a bottleneck. This adaption is known in the testing world as “shift left.”

Operations also felt the winds of change. Teams who could bring changes into production continuously had an advantage. To accomplish this, automation and cooperation between Development and Operations are required. DevOps saw the dawn of light.

As we become more and more agile we discover new bottlenecks which slow us down. As a Scrum Team we wish to expand our skills in order to not have external dependencies.

When commenting on this Article, Vasco Duarte expressed it very well:

Any Agile team will expand to include all the necessary tasks into the team, to be able to continue to be

--

--

Fredrik Carleson
Serious Scrum

Twenty years plus of continuous professional expertise in the information technology sector working in the private sector and United Nations in Europe and Asia.