DevSecOps Through a Control Lens
摘要
In this chapter, DevSecOps will be viewed as a control mechanism designed for managing the risks and security of the system, as well as providing stability to the continuous delivery environment. Here, the role of security in DevSecOps is not seen as a phase in itself but rather as an integral feedback-driven constraint mechanism. The process of integrating security into decisions and actuators will be such that any activity performed by the system will be judged against a set of risk limits.