IBM Cloud DevSecOps Enables Secure and Compliant Deployment of External Applications

1:58 am
October 11, 2023

The rise in cyberattacks on software supply chains poses a significant risk to organizations worldwide, with an estimated 45% of organizations affected, according to Gartner. These attacks, known as supply chain risks, include vulnerabilities in code sourced from open source or third parties. These risks are especially concerning for critical systems, such as IT infrastructure and financial services organizations, as they need to balance innovation with security and compliance requirements.

IBM Cloud for Financial Services: A Solution for Security and Compliance

IBM Cloud for Financial Services provides a solution that supports innovation while ensuring security and compliance. By leveraging industry standards like NIST and the expertise of over a hundred financial services clients, IBM Cloud for Financial Services helps clients create secure and compliant hybrid cloud solutions. It utilizes IBM Cloud DevSecOps, also known as One Pipeline, to focus on the full software lifecycle, including continuous integration (CI), continuous delivery (CD), continuous deployment, and continuous compliance.

The Role of IBM Cloud DevSecOps in Ensuring Secure and Compliant Applications

IBM Cloud DevSecOps, or One Pipeline, is used to deploy applications on IBM Cloud while checking for vulnerabilities and ensuring auditability. The DevSecOps pipeline consists of three components: continuous integration (CI), continuous delivery/deployment (CD), and continuous compliance (CC). The CI pipeline is responsible for building the application and running best practices like unit testing, dynamic scans, and vulnerability checks. The CD pipeline supports the continuous deployment of the application, including evidence collection and compliance scans. The CC pipeline periodically scans the deployed application for continuous compliance.

In cases where third-party code is involved and a complete CI process cannot be run, alternative approaches can be used. The DevSecOps CLI, which contains the pipeline code logic, can be integrated into existing CI systems like Jenkins, Travis, or GitLab. This allows organizations to still verify the security and compliance of the application or component by leveraging the inventory and evidence pieces.

Case Study: Financial Transaction Manager (FTM)

An example of integrating the DevSecOps CLI into existing pipelines is demonstrated by the Financial Transaction Manager (FTM) team. Due to its complex build structure and long build time, FTM could not adopt a full One-Pipeline-based solution. However, by integrating the DevSecOps CLI into their existing Jenkins-based pipelines, the FTM team was able to generate the required inventory and evidence items for One Pipeline deployment.

The FTM team created utility classes in their Jenkins script libraries to facilitate interaction with the DevSecOps CLI. This allowed them to easily add evidence and inventory items to a Git repository, integrating them into their Jenkins infrastructure. This approach enables organizations to augment their existing pipelines and secure their software supply chain.

Conclusion

IBM Cloud DevSecOps, in combination with IBM Cloud for Financial Services, enables organizations to deploy external applications securely and compliantly. By integrating the DevSecOps CLI into existing CI systems, organizations can ensure the verification of security and compliance even when a full One-Pipeline deployment is not possible. This approach enhances the software supply chain’s security and mitigates the risks associated with supply chain attacks.

Frequently Asked Questions (FAQ)

What is IBM Cloud for Financial Services?

IBM Cloud for Financial Services is a platform that provides security and compliance for financial services companies. It leverages industry standards and the expertise of financial services clients to support innovation while ensuring security and compliance.

What is IBM Cloud DevSecOps?

IBM Cloud DevSecOps, also known as One Pipeline, is a set of toolchains and pipelines used to deploy applications on IBM Cloud. It focuses on continuous integration, continuous delivery/deployment, and continuous compliance to ensure the security and compliance of applications.

How can the DevSecOps CLI be integrated into existing CI systems?

The DevSecOps CLI can be integrated into existing CI systems, such as Jenkins, Travis, or GitLab. Organizations can use specific commands provided by the CLI, such as adding evidence or inventory items, to generate the necessary artifacts for secure and compliant deployments.

What is the role of the inventory and evidence lockers in secure and compliant deployments?

The inventory tracks artifact deployments, signatures, and components in a GitOps model. The evidence locker contains items that assert the completion of required checks, such as unit tests, code scans, and pull request reviews. These repositories are crucial in determining what should be deployed and ensuring the security and robustness of the application.

How does IBM Cloud DevSecOps enhance the security of the software supply chain?

By integrating the DevSecOps CLI into existing CI systems, organizations can augment their pipeline processes and secure their software supply chain. The CLI enables the generation of an evidence locker and inventory, allowing organizations to verify the security and compliance of the application or component before deployment.


Share:

More in this category ...

2:09 am December 7, 2023

Data Monetization Strategies: Unleashing the Potential of Your Data Assets

1:00 am December 7, 2023

Successful Beta Service launch of SOMESING, ‘My Hand-Carry Studio Karaoke App’

Featured image for “Successful Beta Service launch of SOMESING, ‘My Hand-Carry Studio Karaoke App’”
12:16 am December 7, 2023

Coinbase unveils global, instant money transfers via popular messaging and social platforms

6:39 pm December 6, 2023

Decentralized Identity Management: The Power of Blockchain in Government

5:03 pm December 6, 2023

BitMEX Collaborates with PowerTrade to Introduce New Crypto Products for Traders

4:59 pm December 6, 2023

Reskilling your workforce in the time of AI

1:02 pm December 6, 2023

Assemblyman Proposes Bill to Regulate Digital Assets as Securities

Featured image for “Assemblyman Proposes Bill to Regulate Digital Assets as Securities”
9:45 am December 6, 2023

ORDI worth hits new all-time top as Bitcoin touches $42k

5:18 am December 6, 2023

Societe Generale Launches Inaugural Digital Green Bond on Ethereum Blockchain

2:33 am December 6, 2023

Bitcoin skyrockets to $44,000 as bulls brush bears apart

1:06 am December 6, 2023

DWF Labs Invests Additional $1.25M in FLOKI to Support the Ecosystem

Featured image for “DWF Labs Invests Additional $1.25M in FLOKI to Support the Ecosystem”
7:12 pm December 5, 2023

TokenFi (TOKEN) worth is up 48% as of late: Here’s why

5:38 pm December 5, 2023

Retailers can faucet into generative Computational Intelligence to beef up reinforce for patrons and staff

1:08 pm December 5, 2023

Record-Breaking Inflows in Crypto Investment Products Echo 2021 Bull Run

Featured image for “Record-Breaking Inflows in Crypto Investment Products Echo 2021 Bull Run”
12:36 pm December 5, 2023

Big Data and Analytics: Driving Efficiency in the Digital Supply Chain

11:58 am December 5, 2023

Jellyverse secures $2 million seed round to build DeFi 3.0

5:42 am December 5, 2023

A guide to efficient Oracle implementation

5:06 am December 5, 2023

From Fiat to Crypto: Exploring the Role of Regulated Exchanges in Digital Asset Adoption

4:44 am December 5, 2023

Top crypto picks to buy at rising market before it’s too late

1:10 am December 5, 2023

Core Scientific explains its latest bankruptcy plan ahead of court date

Featured image for “Core Scientific explains its latest bankruptcy plan ahead of court date”
9:36 pm December 4, 2023

Enhancing Privacy with Zero-Knowledge Proofs: The Power of Privacy-Focused Blockchains

9:29 pm December 4, 2023

Riot purchases BTC miners worth $290M from MicroBT

6:03 pm December 4, 2023

The Importance of Supply Chain Optimization in Today’s Business Environment

2:16 pm December 4, 2023

Standard Chartered Zodia integrates Ripple-owned Metaco’s crypto storage services

2:06 pm December 4, 2023

Web 3.0: The Internet of Value and Smart Contracts

1:13 pm December 4, 2023

Crypto Executives Predict Bull Run for Bitcoin in 2024, Others Disagree

Featured image for “Crypto Executives Predict Bull Run for Bitcoin in 2024, Others Disagree”
6:35 am December 4, 2023

Comparing Traditional and Decentralized Storage: What You Need to Know

6:23 am December 4, 2023

Empowering Security Analysts: Strategies to Maximize Productivity and Efficiency

1:12 am December 4, 2023

Bitcoin tops $40K for first time in 19 months, Matrixport tips $125K in 2024

Featured image for “Bitcoin tops $40K for first time in 19 months, Matrixport tips $125K in 2024”
11:01 pm December 3, 2023

How Token Economics Drive Value Creation and Incentives in Blockchain Projects