From the course: Building an Application Security Program
Unlock this course with a free trial
Join today to access over 25,500 courses taught by industry experts.
Continuous improvement
From the course: Building an Application Security Program
Continuous improvement
- [Narrator] A part of any good application security program and DevOps program is continuous improvement. Continuous improvement is a principle that DevOps really exemplifies in that it's always looking to get better. It's never staying with the status quo. We should always be looking at what went wrong, what went right, and how can we get better? Metrics can really enable this if we accurately track them. We can understand how effective our application security testing is if we're seeing patterns like too many vulnerabilities making it into production. We could also look and see how we can test quicker, how we can test more accurately, and we can use the data gathered throughout the process to help formulate answers to these decisions, and we have to look at everything. It's not just one part of the application security process. We have to look at the tools and the process. Am I using the right tools? Are the tools…