Research Projects Blog Agent Skill Publications Contact
Publications  / DevOps

Organically DevOps: Building Quality and Security into the Software Supply Chain

November 8, 2016 · DevOpsCI/CDCultureSecuritySoftware Architecture
Organically DevOps: Building Quality and Security into the Software Supply Chain

This talk looked at transformation to Continuous Integration, Continuous Delivery, and DevOps in large, heavily regulated organizations. The core message: don’t mandate DevOps — grow it organically.

Key takeaways:

  • Don’t mandate DevOps. Give employees the chance to master their discipline with examples to set and follow
  • Favor deep end-to-end accomplishments over broad but incremental steps forward
  • Focus on taking the right teams far before encouraging broad adoption
  • Centralize the platforms and tools that your teams shouldn’t be thinking about
  • Provide foundational services/commodities and let teams stay on purpose
  • Incorporate contributions from everyone; don’t stifle autonomy
  • Stay open to new ways of working
  • Challenge security policies, but respect intentions — find new ways to enforce concerns without abandoning precaution