DevSecOps Reference Architecture.pdf

Level 5

DevSecOps Reference Architecture

Last Modified: January 16, 2020 Last Modified By: DJ Schleen

Legend

Threat Detected Neutralize Security
Product Architect Manual Developer
SRE Automated
Executives Internal Threat Business Actor

Green Deploy Environment
Supply Chain
Secret Store Secret Store Secret Secret Management Injection Secret Secret Secret Injection Injection Injection
Observation Deployment Iterate NotificationsDevelopmentContent TrustDeliveryAppStore / Play Integration Out of Band Production
Continuous Education Production CommitTestFlight Database (DaC) OSSM SCA MTD Threat Binary DAST Mobile Testing Play Beta Actor Scramble Iterate Work Item Backlog OSSM Build SBoM Sign Tracking Production DAST Message Test Case OSSM SCACommitPR Package Sign Production Deploy (Live) Coding (Live) Line indicates Blue/Green Lifecycle --------- Alert Customers Idea Work Item Threat Design ArchitectureCommitOSSM Sign SAST Sign Integration Sign CVA Sign DAST Sign Policy Sign Production Chaos Model Infrastructure OSSM SCA Test Repository Automated Check Promotion as Code Experiments (Iac) Tests Signatures Trigger

Business Open Source OSSMCommitSAST Out of Band Database Configuration "Staging" Dark/Canary Application OSSM SCA Acceptance Repository Migration Injection Testing Deployment Green (Live) Deployment Data Flow Stakeholder Interest Based on Third Party OSSM Speed (Vendors) Secret Flow Customer / Business

lifecycle repositoryVisible Deployment Customers

Docker OSSM Registry

Ethical Hacking Continued Ethical Hacking and Penetration Testing

Red, Blue, and firewall Purple Teamslifecycle

Continuous Observation

Threat Detected Automated Notifications Data Science Bring the Chaos

Data Third Party Security Compliance Governance Science Sign Check Risk Security Data Security Investigation Operations

Data Security Investigation Operations
Aggregation Models and Forensics Center
(SOC)
Continuous
Education

Stage Duration Stage Lag DRAG

Stage Detail