Mitigating an Oxymoron: Compliance in a DevOps Environments
John R. Michener, Aaron T. Clager · 2016
Compliance and regulation are fundamentally intended to establish trust between entities that create and use shared computing systems across all layers. Security compliance requirements (such as those of Payment Card Industry (PCI) Data Security Standard (DSS)1or the US NIST 800 special publication series2) are framed around a classic “Waterfall” software development methodology. The software industries recent shift to a “DevOps” methodology has put the trust created with compliance at risk. This paper contains a proposed strategy to achieve compliance and establish trust using a DevOps environment.