Top 6 Reasons the Time Is Now for DevSecOps in the Federal Government

By Jason Green

2 minute read time

Underpinning all modern technology - software and hardware - is a supply chain. However, even as "software eats the world," or we could argue "ate the world," there is still too little understanding of the software supply chain, with continued focus on hardware. The reality, however, is that software is much easier to pollute than hardware. While awareness has increased around the need for a coordinated application security strategy, the federal government has historically focused on strong defense, putting up walls at the perimeter, and at the end of the software supply chain.

It's time to shift more security resources further left. In this way, the government can play better offense at the beginning of the software supply chain, so that federal agencies can better protect themselves and the American citizenry.

  1. Open source is powering federal software development - Open source software components are the backbone of federal software supply chains. In fact, 85% to 95% of an application is composed of open source components. Since they are free and readily available, they allow agencies to save time and money, and in many cases improve quality.

  2. Not all open source components are created equal - Sonatype's research shows that within the Java ecosystem 1 in 10 contains a known security vulnerability and within JavaScript, more than 51% of all components have a vulnerability, highlighting the security challenges agencies face.

  3. Agencies don't know how much open source they're using - There is a lack of transparency in how much open source software is being used throughout the federal government. A disconnect between developers and security teams makes it difficult to rectify this, but with proper controls, can be fixed. NIST Special Publication (SP) 800-161 offers specific supply chain risk management practice recommendations.

  4. Lack of open source policies leading to breaches - According to Sonatype's DevSecOps Community Survey of 5,500 IT pros, 1 in 4 organizations confirmed or suspected an open source related breach last year. Of organizations with DevOps practices, only 6 in 10 have policies evaluating open source use, and of those not practicing DevOps, it plummets to 2 in 10.

  5. Cost emphasized over security protocol - One of the biggest threats comes from the contractors paid to support the federal government and are supposed to help protect its sophisticated systems. Too often, they are inadvertently introducing vulnerabilities into the software supply chain, with the emphasis on cost over security.

  6. Regulations around software development is coming - However, new legislation and recommendations have begun to provide a roadmap for where the US should be headed. For savvy contractors and agencies, they can prioritize security in their development process now.

Legislation Timeline

SonatypeGovernment-1

Picture of Jason Green

Written by Jason Green

Jason Green, Vice President of Public Sector, Sonatype. Jason is a huge advocate of applying proven technology supply chain management principles into DevSecOps practices to improve efficiencies and sustain long-lasting secure and competitive advantages.

Jason has supported the Federal ...

Tags