# A DevSecOps Maturity Model in Seven Words

**November 04, 2018**  
By [Derek Weeks](/content/blog/author/derek-weeks/index.html)

1 minute read time

A few weeks ago, I delivered a lightning talk (5 minutes, 20 slides, auto-advancing every 15 seconds) at [DevOps](/content/resources/articles/what-is-devops/index.html) Enterprise Summit.

A conversation inspired the talk I had with Navin Vembar about a [DevSecOps](/content/resources/articles/what-is-devsecops/index.html) maturity model his organization developed at the U.S. Government Services Administration (GSA). While several DevSecOps maturity models exist, Navin's started with seven important words that made all the difference.

Take 5 minutes to watch [this lightning talk](https://www.youtube.com/watch?v=COJSrOWK7iU) now to learn how and why he used the words, "Not considered viable for a DevSecOps platform"

Here are some additional DevSecOps maturity models:

- [https://www.slideshare.net/shannonlietz/isaca-ireland-keynote-2015](https://www.slideshare.net/shannonlietz/isaca-ireland-keynote-2015)

- [https://www.slideshare.net/DevOpsWebinars/security-at-the-speed-of-software-development](https://www.slideshare.net/DevOpsWebinars/security-at-the-speed-of-software-development)

I hope Navin's insights and seven key words can help you on your DevSecOps journey.

Written by **Derek Weeks**

Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.
