Skip to main content

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

survey icon Share your experience with the FAS IT-Playbook by taking this brief survey

DevSecOps

DevSecOps is a model that tightly integrates the activities of development, security, and operations teams to increase GSA's ability to deliver applications and services faster than traditional approaches where each of these lifecycle phases are addressed separately.

DevSecOps Principles

GSA IT recommends and strongly encourages applications within the Cloud Ecosystem follow the six key DevSecOps principles described below to enable consistency and appropriately scale within the Enterprise.

1. Define all Infrastructure as Code

2. All changes to production should be tested in lower level environment

3. Version Controlled Assets

4. Configuration Data Storage

5. Implement Automated Configuration Management

6. Implement DocOps

Return to Standards Alignment