IBM Cloud DevSecOps Enables Secure and Compliant Deployment of External Applications

1:58 am
October 11, 2023

The rise in cyberattacks on software supply chains poses a significant risk to organizations worldwide, with an estimated 45% of organizations affected, according to Gartner. These attacks, known as supply chain risks, include vulnerabilities in code sourced from open source or third parties. These risks are especially concerning for critical systems, such as IT infrastructure and financial services organizations, as they need to balance innovation with security and compliance requirements.

IBM Cloud for Financial Services: A Solution for Security and Compliance

IBM Cloud for Financial Services provides a solution that supports innovation while ensuring security and compliance. By leveraging industry standards like NIST and the expertise of over a hundred financial services clients, IBM Cloud for Financial Services helps clients create secure and compliant hybrid cloud solutions. It utilizes IBM Cloud DevSecOps, also known as One Pipeline, to focus on the full software lifecycle, including continuous integration (CI), continuous delivery (CD), continuous deployment, and continuous compliance.

The Role of IBM Cloud DevSecOps in Ensuring Secure and Compliant Applications

IBM Cloud DevSecOps, or One Pipeline, is used to deploy applications on IBM Cloud while checking for vulnerabilities and ensuring auditability. The DevSecOps pipeline consists of three components: continuous integration (CI), continuous delivery/deployment (CD), and continuous compliance (CC). The CI pipeline is responsible for building the application and running best practices like unit testing, dynamic scans, and vulnerability checks. The CD pipeline supports the continuous deployment of the application, including evidence collection and compliance scans. The CC pipeline periodically scans the deployed application for continuous compliance.

In cases where third-party code is involved and a complete CI process cannot be run, alternative approaches can be used. The DevSecOps CLI, which contains the pipeline code logic, can be integrated into existing CI systems like Jenkins, Travis, or GitLab. This allows organizations to still verify the security and compliance of the application or component by leveraging the inventory and evidence pieces.

Case Study: Financial Transaction Manager (FTM)

An example of integrating the DevSecOps CLI into existing pipelines is demonstrated by the Financial Transaction Manager (FTM) team. Due to its complex build structure and long build time, FTM could not adopt a full One-Pipeline-based solution. However, by integrating the DevSecOps CLI into their existing Jenkins-based pipelines, the FTM team was able to generate the required inventory and evidence items for One Pipeline deployment.

The FTM team created utility classes in their Jenkins script libraries to facilitate interaction with the DevSecOps CLI. This allowed them to easily add evidence and inventory items to a Git repository, integrating them into their Jenkins infrastructure. This approach enables organizations to augment their existing pipelines and secure their software supply chain.

Conclusion

IBM Cloud DevSecOps, in combination with IBM Cloud for Financial Services, enables organizations to deploy external applications securely and compliantly. By integrating the DevSecOps CLI into existing CI systems, organizations can ensure the verification of security and compliance even when a full One-Pipeline deployment is not possible. This approach enhances the software supply chain’s security and mitigates the risks associated with supply chain attacks.

Frequently Asked Questions (FAQ)

What is IBM Cloud for Financial Services?

IBM Cloud for Financial Services is a platform that provides security and compliance for financial services companies. It leverages industry standards and the expertise of financial services clients to support innovation while ensuring security and compliance.

What is IBM Cloud DevSecOps?

IBM Cloud DevSecOps, also known as One Pipeline, is a set of toolchains and pipelines used to deploy applications on IBM Cloud. It focuses on continuous integration, continuous delivery/deployment, and continuous compliance to ensure the security and compliance of applications.

How can the DevSecOps CLI be integrated into existing CI systems?

The DevSecOps CLI can be integrated into existing CI systems, such as Jenkins, Travis, or GitLab. Organizations can use specific commands provided by the CLI, such as adding evidence or inventory items, to generate the necessary artifacts for secure and compliant deployments.

What is the role of the inventory and evidence lockers in secure and compliant deployments?

The inventory tracks artifact deployments, signatures, and components in a GitOps model. The evidence locker contains items that assert the completion of required checks, such as unit tests, code scans, and pull request reviews. These repositories are crucial in determining what should be deployed and ensuring the security and robustness of the application.

How does IBM Cloud DevSecOps enhance the security of the software supply chain?

By integrating the DevSecOps CLI into existing CI systems, organizations can augment their pipeline processes and secure their software supply chain. The CLI enables the generation of an evidence locker and inventory, allowing organizations to verify the security and compliance of the application or component before deployment.


Share:

More in this category ...

7:27 pm April 30, 2024

Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan

Featured image for “Ripple companions with SBI Group and HashKey DX for XRPL answers in Japan”
6:54 pm April 30, 2024

April sees $25M in exploits and scams, marking historic low ― Certik

Featured image for “April sees $25M in exploits and scams, marking historic low ― Certik”
5:21 pm April 30, 2024

MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips

Featured image for “MSTR, COIN, RIOT and different crypto shares down as Bitcoin dips”
10:10 am April 30, 2024

EigenLayer publicizes token release and airdrop for the group

Featured image for “EigenLayer publicizes token release and airdrop for the group”
7:48 am April 30, 2024

VeloxCon 2024: Innovation in knowledge control

Featured image for “VeloxCon 2024: Innovation in knowledge control”
6:54 am April 30, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
2:58 am April 30, 2024

Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy

Featured image for “Dogwifhat (WIF) large pump on Bybit after record reasons marketplace frenzy”
8:07 pm April 29, 2024

How fintech innovation is riding virtual transformation for communities around the globe  

Featured image for “How fintech innovation is riding virtual transformation for communities around the globe  ”
7:46 pm April 29, 2024

Wasabi Wallet developer bars U.S. customers amidst regulatory considerations

Featured image for “Wasabi Wallet developer bars U.S. customers amidst regulatory considerations”
6:56 pm April 29, 2024

Analyst Foresees Peak In Late 2025

Featured image for “Analyst Foresees Peak In Late 2025”
6:59 am April 29, 2024

Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block

Featured image for “Solo Bitcoin miner wins the three.125 BTC lottery, fixing legitimate block”
7:02 pm April 28, 2024

Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors

Featured image for “Ace Exchange Suspects Should Get 20-Year Prison Sentences: Prosecutors”
7:04 am April 28, 2024

Google Cloud's Web3 portal release sparks debate in crypto trade

Featured image for “Google Cloud's Web3 portal release sparks debate in crypto trade”
7:08 pm April 27, 2024

Bitcoin Primed For $77,000 Surge

Featured image for “Bitcoin Primed For $77,000 Surge”
5:19 pm April 27, 2024

Bitbot’s twelfth presale level nears its finish after elevating $2.87 million

Featured image for “Bitbot’s twelfth presale level nears its finish after elevating $2.87 million”
10:07 am April 27, 2024

PANDA and MEW bullish momentum cool off: traders shift to new altcoin

Featured image for “PANDA and MEW bullish momentum cool off: traders shift to new altcoin”
9:51 am April 27, 2024

Commerce technique: Ecommerce is useless, lengthy are living ecommerce

Featured image for “Commerce technique: Ecommerce is useless, lengthy are living ecommerce”
7:06 am April 27, 2024

Republic First Bank closed by way of US regulators — crypto neighborhood reacts

Featured image for “Republic First Bank closed by way of US regulators — crypto neighborhood reacts”
2:55 am April 27, 2024

China’s former CBDC leader is beneath executive investigation

Featured image for “China’s former CBDC leader is beneath executive investigation”
10:13 pm April 26, 2024

Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions

Featured image for “Bigger isn’t all the time higher: How hybrid Computational Intelligence development permits smaller language fashions”
7:41 pm April 26, 2024

Pantera Capital buys extra Solana (SOL) from FTX

Featured image for “Pantera Capital buys extra Solana (SOL) from FTX”
7:08 pm April 26, 2024

Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service release of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
12:29 pm April 26, 2024

SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M

Featured image for “SEC sues Bitcoin miner Geosyn Mining for fraud; Bitbot presale nears $3M”
10:34 am April 26, 2024

Business procedure reengineering (BPR) examples

Featured image for “Business procedure reengineering (BPR) examples”
7:10 am April 26, 2024

85% Of Altcoins In “Opportunity Zone,” Santiment Reveals

Featured image for “85% Of Altcoins In “Opportunity Zone,” Santiment Reveals”
5:17 am April 26, 2024

Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships

Featured image for “Sam Altman’s Worldcoin eyeing PayPal and OpenAI partnerships”
10:55 pm April 25, 2024

Artificial Intelligence transforms the IT strengthen enjoy

Featured image for “Artificial Intelligence transforms the IT strengthen enjoy”
10:04 pm April 25, 2024

Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers

Featured image for “Franklin Templeton tokenizes $380M fund on Polygon and Stellar for P2P transfers”
7:13 pm April 25, 2024

Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}

Featured image for “Meta’s letting Xbox, Lenovo, and Asus construct new Quest metaverse {hardware}”
2:52 pm April 25, 2024

Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display

Featured image for “Shiba Inu (SHIB) unveils bold Shibarium plans as Kangamoon steals the display”