VOOZH about

URL: https://thenewstack.io/agile-coding-production-requires-agile-security/

⇱ Agile Coding Production Requires Agile Security - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-10-21 08:47:42
Agile Coding Production Requires Agile Security
contributed,sponsor-fortinet,sponsored,sponsored-post-contributed,
DevOps / Security / Software Development

Agile Coding Production Requires Agile Security

If you enable rapid code deployment without compromising security, security becomes a business enabler and a competitive advantage.
Oct 21st, 2021 8:47am by Brian Schwarz
👁 Featued image for: Agile Coding Production Requires Agile Security
Photo by Tim Mossholder from Pexels.
Fortinet sponsored this post.
Brian Schwarz
Brian is director of product for application security at Fortinet. With over 20 years of experience working with networking and security solutions for the enterprise, Brian focuses on Fortinet’s web application and API security solutions.

Organizations devote vast resources to developing new code. Sometimes that code is intended to fix bugs, sometimes to improve the user experience and sometimes to deliver entirely new capabilities. Whatever the purpose, the expectation is that all that effort is going to return value to the organization. But whenever deployment of the latest code is held up by inefficient or outdated security controls, the organization’s return on investment (ROI) shrinks. Organizations should never bypass security controls in the name of ROI, but to make sure you’re never put in a position where you may be tempted to decide between the two, the way we implement those security controls should add as little friction to the deployment process as possible.

How can organizations implement security in a way that gets their code into production faster so they can get the full value out of their latest and greatest code? This is a question explored in “The Phoenix Project: A Novel about IT, DevOps, and Helping Your Business Win” from 2013, and the author spends a lot of time discussing the concept of “Work in Progress” or WIP. The concept of WIP is not new, but “The Phoenix Projectpushes the idea that reducing WIP is key to successful DevOps. One key factor in reducing WIP is to implement appropriate security controls in ways that minimize deployment delays.

Common Challenges with Testing Environments for DevOps 

DevOps teams fix problems and work to bring new capabilities to our users, and every delay in getting that latest and greatest code into production affects the business. A common scenario and pain point for developers is when they push code into their testing environment and discover that some pre-existing security control is incompatible with their new code. This sends the development and security teams scrambling to make necessary changes to get the code to work. Those changes could be in the application or the security control, and just determining whether the application or the security control should change can be time-consuming. The later in the process these conflicts reveal themselves, the more expensive the resolution tends to be, and that expense should be measured both in terms of person-hours and in terms of delayed ROI.

Advanced Cloud Security Can Help

To avoid code implementation issues, security should be tightly integrated with every organization’s DevOps practices, or what is also known as DevSecOps. Here are three tips that can help:

  1. Choose security tools that are easy to deploy and easy to manage. The security skills shortage we face isn’t going away anytime soon, and you can’t count on your existing dev teams to already have a broad security skill set. Look for the tools that deliver effective security, but don’t generate the false positives that drive administrative overhead. You only have so much staff; deploy the right tools so that they minimize the time spent on labor-intensive policy tuning and false-positive resolution. With the right tools, your team will have more bandwidth to focus on higher-value tasks. Look for solutions that include tools that ease deployments (e.g. cloud formation templates for FortiGate) or that can be consumed as a service (e.g. FortiWeb Cloud WAF as a Service).
  2. Choose tools that enable you to maintain a consistent security posture wherever you deploy your applications. Modern enterprise networks are diverse and often span multiple environments. A typical enterprise today often has applications deployed across a range of private data centers and public clouds. You need security solutions that follow your applications and data to deliver consistent, seamless security and streamlined operations across all clouds.
  3. Create processes that enable developers to develop within the same security configuration that will be used in production. Leverage APIs and automation tools to make spinning up “production class” operating environments quick and easy. Leaving “add security controls” to the end of the process increases the chances for unpleasant late-breaking surprises. Don’t let setting up security be the task that keeps your awesome new code stuck in WIP status.
The Fortinet Security Fabric platform delivers broad, integrated, and automated protections across the entire digital attack surface. Ranked #1 for most security appliances worldwide, more than 580,000 customers trust Fortinet to secure their business and accelerate their digital journey.
Learn More
The latest from Fortinet

Conclusion

“The Phoenix Project” has been out for a few years, but it remains a great primer for getting up to speed on the basics of DevOps – and surprisingly, presenting it as a “DevOps novel” works pretty well. If our security controls and processes keep code stuck as WIP too long, we become an impediment to the business. Security is more than just a cost of doing business; if we do this right and enable rapid code deployment without compromising security, security becomes a business enabler and a competitive advantage.

The Fortinet Security Fabric platform delivers broad, integrated, and automated protections across the entire digital attack surface. Ranked #1 for most security appliances worldwide, more than 580,000 customers trust Fortinet to secure their business and accelerate their digital journey.
Learn More
The latest from Fortinet
TRENDING STORIES
Brian is director of product for application security at Fortinet. With over 20 years of experience working with networking and security solutions for the enterprise, Brian focuses on Fortinet’s web application and API security solutions.
Read more from Brian Schwarz
Fortinet sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.