VOOZH about

URL: https://thenewstack.io/sans-survey-shows-devsecops-is-shifting-left/

⇱ SANS Survey Shows DevSecOps Is Shifting Left  - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-10-31 08:00:18
SANS Survey Shows DevSecOps Is Shifting Left 
contributed,sponsor-synopsys,sponsored,sponsored-post-contributed,
Security / Software Development / Tech Culture

SANS Survey Shows DevSecOps Is Shifting Left 

Let’s take a look at some key findings and what they tell us about how the industry is making progress.
Oct 31st, 2022 8:00am by Charlotte Freeman
👁 Featued image for: SANS Survey Shows DevSecOps Is Shifting Left 
Image via Unsplash.
Synopsys sponsored this post.

The ultimate objective of any DevSecOps program is to significantly improve an organization’s security posture and operational effectiveness by aligning the development, security and operations teams. The SANS 2022 DevSecOps Survey: “Creating a Culture to Significantly Improve Your Organization’s Security Posture” showcases the ways that progress toward this goal is being made by the community, while recognizing the challenges, and highlighting areas for additional focus.

Let’s take a look at some key findings and what they tell us about how the industry is making progress on shifting security left.

‘Shift Left’ Is Happening

The survey showed that security testing increased at each phase of the build and release workflow. The majority of testing still occurs at the architecture/design stage, suggesting widespread agreement that security testing should be addressed early in the build and release workflow.

While testing at the code commit/pull request stage is still considered an important phase, this year’s survey shows an appropriate jump in testing at both the requirements and use case phase and the QA/acceptance phase.

These results show that the “shift left” principle, which holds that security is best addressed early in the development life cycle, is being followed by DevSecOps practitioners. This is a positive development.

Synopsys provides solutions that transform the way development teams build and deliver software. Our comprehensive portfolio interoperates with third-party and open source tools, allowing organizations to build the security program that’s best for them. Build trust in your software with Synopsys.
Learn More
The latest from Synopsys

Secure Coding Training for Developers and Engineers Is Highly Valued

Training developers and engineers in defensive coding and secure programming concepts, risks and techniques is key to shifting responsibilities for security to a stage early in the design and coding life cycle.

Developers also need security training to be effective participants in threat modeling, to perform code reviews and to adopt static application security testing (SAST) tools. When queried about this, 42.5% of respondents say that training is “very useful” while 39.8% agree that it is “useful.”

SANS survey respondents ranked secure coding training higher than pen testing, software composition analysis (SCA), automated SAST, threat modeling, container/image security scanning, dynamic application security testing (DAST), third-party compliance reviews, interactive application security testing (IAST), fuzz testing and bug bounties.

Survey respondents cited the cybersecurity skills shortage as the biggest challenge they continue to face and look to training in secure coding practices as a way to foster a culture of a shared responsibility for security.

‘What Is Measured Is Controlled’

Another key finding of the survey is the importance of key performance indicators (KPIs) and metrics. The number of open security vulnerabilities continues to be the top KPI, while time-to-fix security vulnerabilities remains No. 2.

Interestingly, the use of these KPIs appears to correspond to the 54% of respondents stating that their organization resolves critical security issues within a week or less.

The value of these metrics is conveyed by the axiom “What is measured is controlled” and its corollary, “What is not measured is not controlled.” Management must have the appropriate visibility to focus organizational resources on the underperforming metrics.

The survey’s top takeaway on this is that: “Benchmarking metrics with peer organizations can be used to garner management support and helps demonstrate due care.”

Shared Security Ownership Is Key to DevSecOps Success

Successful DevSecOps programs succeed by developing a culture where various teams share ownership of security. The SANS 2022 DevSecOps Survey results show that improving communication across development, operations and security remains a key success factor across industry sectors.

However, survey respondents continue to consider automating workflows and integrating automated security testing into developer and engineering toolchains as highly important to the success of DevSecOps programs.

Survey results show that respondents consider the following top five factors to have contributed to their security program’s success: Improving communications across development, operations, and security came in at 56%, up from 51% in 2021, while automating workflows increased in importance to 55%, up from 43% in the previous survey. Integrating automated security testing into developer tools and workflows also increased in importance to 53%, up from 45% while securing developer buy-in was also up to 52%, from 46% in 2021.

The only metric that decreased was training developers in secure coding, which fell to 48% from 52%.

Cultural Issues Remain a Barrier

Challenges remain to the full implementation of DevSecOps programs. It is no surprise to see the survey reflect the ongoing shortage of cloud security personnel and skills. This came in as the No. 1 problem organizations are facing, along with an ongoing lack of developer and engineer buy-in. Respondent ratings for the challenges of insufficient budget and funding for security programs and tools dropped by a bit more than 10 percentage points, while the closely related lack of management buy-in rose by nearly the same amount.

While respondents named improving communication across development, operations and security as their No. 2 success factor, organizational silos between these three teams remains a challenge, along with the associated lack of transparency into development and operations work.

Increasing workplace communication among these teams remains the key practice that leadership needs to encourage. Survey results also point to the need to attract hires who embrace solving problems and enjoy being innovative.

ASOC Is an Emerging Trend

The survey reports that the use of application security orchestration and correlation (ASOC) tools is on the rise and will likely increase in years to come. Respondents report that 10% of organizations have fully integrated ASOC tools while 19% have partially integrated and 14% are conducting pilot projects. However, while 17% of organizations are conducting preliminary investigations into ASOC, a full 17% are not investing in ASOC tools at all, while 23% of respondents don’t even know if their organization is investing in ASOC tools.

Along with ASOC, the adoption of artificial intelligence, machine learning, and other data science methodologies and tools will help to improve DevSecOps. Microservices offer DevSecOps teams the advantages of flexible, highly scalable, resilient and easy-to-deploy code.

Identity-based and network-based protections such as microsegmentation are being applied to enable organizations to achieve the widely sought zero trust approach. Through the orchestration of microservices, containers, and serverless technology, DevSecOps has the potential to secure code more thoroughly than has ever been achieved before.

How Synopsys Can Help

Synopsys has solutions for DevSecOps that help you shift security left without slowing down your development teams. Intelligent policy-driven DevSecOps solutions will allow you to run the right tests at the right time while correlating and prioritizing results so you can focus on the issues that matter most.

Synopsys also has tools to help you automate your security policies as code as well as to help your team develop standardized policies for automated security testing and remediation activities in your DevOps workflows.

Synopsys DevSecOps solutions can help your organization manage risks and remove friction from your digital transformation initiatives. Synopsys AppSec and DevSecOps solutions ensure security is built into your applications by offering tooling and services that span all stages of your software development life cycle (SDLC).

Download the full report here.

Synopsys provides solutions that transform the way development teams build and deliver software. Our comprehensive portfolio interoperates with third-party and open source tools, allowing organizations to build the security program that’s best for them. Build trust in your software with Synopsys.
Learn More
The latest from Synopsys
TRENDING STORIES
Charlotte Freeman has been writing about tech and security for over 20 years. She's currently a senior security writer for the Synopsys Software Integrity Group.
Read more from Charlotte Freeman
Synopsys sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.