- Values
- Principles
- Methods
- Practices
- Tools
- culture
- automation
- measurements
- sharing
- system thinking
- feedback
- continous experiment
- People over Process over tools
- CD
- Lean Managment
- Visible ops-style change control
- Infrastructure as code
- Chaos Monkey
- Blue/Green Deployment
- Dependences Injection
- Andon Cords
- The Cloud
- Embedded Teams
- Blameless Postmortem 8.Public static pages 9.Developers on call 10.Incident command system
- Eliminate waste
- Amplify Learning
- Decide as late as possible
- Decide as fast as possible
- Empower the team
- Build in integrity
- See the whole
-
Continous Static Testing: sonarqube
-
Continous Dyanmic Testing: zap as docker
-
IAST: contrast Application Security Platform
-
Continous secret testing: Truffle Hog
-
Continous library testing: dependency check
-
Continous Container Security: anchore-engine
- Vulnerabilities
- Policies
- Runtime Detection
-
Use Jenkins or OWASP glue for all in one tools