What Implementation of DevSecOps for a Microservices-based Application with Service Mesh requires
Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices, often implemented as containers, supported by an infrastructure for providing application services, such as service mesh. Due to security, business competitiveness, and the inherent structure of loosely coupled components, this class of applications needs a different development, deployment, and runtime paradigm. DevSecOps (Development, Security, and Operations) has been found to be a facilitating paradigm for these applications with primitives such as continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines. These pipelines are workflows for taking the developer’s source code through various stages, such as building, testing, packaging, deployment, and operations supported by automated tools with feedback mechanisms. For the purpose of this document, the entire set of source code involved in the application environment is classified into five code types: application code, application services code, infrastructure as code, policy as code, and observability as code. Separate CI/CD pipelines can be created for all five code types. The objective of this document is to provide guidance for the implementation of DevSecOps primitives for a reference platform, which consists of a container orchestration and resource management platform (e.g., Kubernetes). The benefits of this implementation for high security assurance and for enabling continuous authority to operate (C-ATO) are also discussed.
Pillar: Cloud & SaaS · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-204C.pdf
SHA-256 integrity: b2f7a931d4affac02c5581b8ee15f909e0cb8ae997914b6d11ea7d168c55d3d4
Primary Citations — 7 traced to source
- {"citation":"Section 1: DevSecOps (Development, Security, and Operations) is a facilitating paradigm for this class of applications since it facilitates agile and secure development, delivery, deployment, and operations through (a) primitives, such as continuous integration, continuous delivery/continuous deployment (CI/CD) pipelines...; (b) security testing throughout the life cycle; and (c) continuous monitoring during runtime, all of which are supported by automation tools."}
- {"citation":"Executive Summary: For the purpose of this document, the entire set of source code involved in the application environment is classified into five code types: 1. Application code, which embodies the application logic for carrying out one or more business functions. 2. Application services code... 3. Infrastructure as code... 4. Policy as code... 5. Observability as code..."}
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-devsecops-microservices-service-mesh.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-devsecops-microservices-service-mesh.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-devsecops-microservices-service-mesh
- Back to registry: Browse all 10,085 compliance nodes