U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

DevSecOps

Existing Work to Leverage

NIST will leverage existing guidance, practices, and recommendations that may be applicable to DevSecOps. They have been and are being developed by NIST and other US government (USG) agencies, standards development organizations (SDOs), industry, and academia. NIST will also develop mappings to existing informative references to ensure the relationships among frameworks, guidance, practices, and recommendations are clear.

NIST held a virtual workshop in January 2021 on improving the security of DevOps practices; you can access the workshop recording and materials here.

Potential work that can be leveraged includes:

NIST Frameworks

NIST Technology Projects

NIST Technology Guidelines

Government, Industry, and Academia Guidance and Practices

Created October 21, 2020, Updated June 21, 2021