Summary
In this chapter, we explored essential practices for incorporating security during the plan phase of DevOps, focusing on agile threat modeling and continuous secure code-to-cloud training. We highlighted the challenges of traditional threat modeling in a DevSecOps environment. To address these challenges, we outlined a way to seamlessly integrate an agile threat modeling approach, using Mozilla’s RRA as an example. We concluded by detailing the maturity stages associated with a continuous secure code-to-cloud training framework. This chapter has equipped you with important knowledge and strategies to prioritize security right from the planning phase of the DevOps life cycle. Moving forward, the next chapter will address how to implement security controls in the pre-commit phase of the development workflow. Join us as we continue this enlightening journey!