What Implementation of DevSecOps for a Microservices-based Application with Service Mesh requires
Cloud-native applications have evolved into a standardized architecture consisting of multiple loosely coupled components called microservices that are supported by an infrastructure for providing application services, such as service mesh. In this architecture, the entire set of source code can be divided into five types: application code, application services code, infrastructure as code, policy as code, and observability as code. Due to security, business competitiveness, and the inherent structure of loosely coupled application components, this class of applications needs a different development, deployment, and runtime paradigm. DevSecOps (Development, Security, and Operations) has been found to be a facilitating paradigm for these applications with primitives such as continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines. These pipelines are workflows for taking the developer’s source code through various stages, such as building, testing, packaging, deployment, and operations supported by automated tools with feedback mechanisms. This document provides guidance for the implementation of DevSecOps primitives for cloud-native applications with the architecture and code types described. The benefits of this approach for high security assurance and for enabling continuous authority to operate (C-ATO) are also discussed.
Pillar: Cloud & SaaS · Authority: National Institute of Standards and Technology · Version: 1.0.0 · Last updated:
Primary source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-204C.pdf
SHA-256 integrity: c2c1c1214ac908327de0cd0f8c562efb543e804850f764ef82afdd5c938d5147
Primary Citations — 7 traced to source
- Executive Summary: DevSecOps (consisting of acronyms for Development, Security, and Operations, respectively) is one of the facilitating paradigms for the development, deployment, and operation of these applications with primitives such as continuous integration, continuous delivery, and continuous deployment (CI/CD) pipelines.
- Section 1.1: Infrastructure as code - expresses the computing, networking, and storage resources needed to run the application in the form of a declarative code.
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/nist-sp-800-204c-devsecops-microservices.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/nist-sp-800-204c-devsecops-microservices.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/nist-sp-800-204c-devsecops-microservices
- Back to registry: Browse all 10,090 compliance nodes