DevOps and Opportunities in Software Supply Chain Governance

DevOps and Opportunities in Software Supply Chain Governance

February 09, 2017
By Wayne Jackson

4 minute read time

Governance has been an evil word for software developers, but new approaches unlock massive gains in productivity, reductions in cost, and improvements in quality.

These last few years have been a fascinating journey. Concepts that we at Sonatype have been evangelizing for years – component based software development, the proliferation of open source, the inevitability of DevOps – are now becoming widely understood if not accepted. The simple fact is that "software is eating the world" and innovation is driving competitive differentiation in almost every industry, in every market. These advances were inevitable.

Unfortunately, this tectonic shift is not without a downside. Unmanaged use of open source components, for example, can lead to a massive surface area that becomes impossible to maintain (robbing resources from innovation) and high risk from both cyber and operational perspectives.

Leading organizations in verticals such as Banking and Insurance internalized these challenges early and established centralized and highly structured open source governance programs. Typically, these programs consisted of processes by which developers requested permission to use components. Domain experts would then evaluate those requests, including Security, Legal, Architecture and others, who worked toward, most typically, a whitelist of components deemed acceptable for use, often stored in a "golden repository" to be accessed by developers.

Until recently, these approaches represented best practice. Today, these programs are incongruent with modern development practices for four simple reasons:

So now what? It is becoming increasingly obvious that as we embrace DevOps transformation, we must also embrace governance transformation. Governance transformation should naturally embrace the same concepts that enable successful DevOps initiatives:

Ironically, the organizations that were among the first to understand the challenges of modern software development now have the most entrenched, traditional (manual) governance programs. As challenging as reshaping these programs will be, human-led processes are simply incompatible with DevOps and the goals of continuous delivery. Waterfall concepts and capabilities will still play a role, but not in the native patterns of DevOps processes.

The good news is that for organizations with the will and resources to embrace DevOps and governance transformations, what Gartner has termed DevSecOps, the gains can be enormous. We have started to see customer studies of their own transformation initiatives, and the results are stunning. The most recent I have seen include three industry leading organizations in the Banking, Finance, and Insurance sectors. Their findings:

Competition has never been more intense for nearly every business in nearly every segment. As challenging as some transitions can be, the rewards for innovation delivery are increasingly obvious and quantitatively measurable. So while historically governance has carried negative connotations (especially for developers), modern software supply chain governance aligns interests, encourages innovation, and enables DevOps to realize its full potential.

Written by Wayne Jackson

Wayne is the CEO of Sonatype, a role he has held since 2010. Prior to Sonatype, Wayne served as the CEO of open source network security pioneer Sourcefire, Inc. (NASDAQ:FIRE), which he guided from fledgling start-up through an IPO in March of 2007, later acquired by Cisco for $2.7 billion. Before Sourcefire, Wayne co-founded Riverbed Technologies, a wireless infrastructure company, and served as its CEO until the sale of the company for more than $1 billion in March of 2000.