VOOZH about

URL: https://thenewstack.io/what-does-shift-left-mean-if-every-process-is-a-circle/

⇱ What Does 'Shift Left' Mean if Every Process Is a Circle? - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2021-03-11 07:14:40
What Does 'Shift Left' Mean if Every Process Is a Circle?
contributed,sponsor-synopsys,sponsored,sponsored-post-contributed,
DevOps / Security

What Does ‘Shift Left’ Mean if Every Process Is a Circle?

The Synopsys Building Security In Maturity Model (BSIMM) has a new term to optimize security testing in DevOps: “shift everywhere.”
Mar 11th, 2021 7:14am by Arshad Rizvi
👁 Featued image for: What Does ‘Shift Left’ Mean if Every Process Is a Circle?
Synopsys sponsored this post.

Synopsys sponsored this post.

Arshad Rizvi
Arsh leads the Cloud and DevSecOps practice at Synopsys Software Integrity Group. His experience spans AWS/Azure/GCP Public and Hybrid Cloud Application Security, DevSecOps, Secure CI/CD, Cloud Platform Security, Data Security, Security tools/practices, Cloud GRC (Governance, Risk and Compliance), Cyberdefense, etc. Before joining Synopsys, Arshad worked in leadership roles at PwC and Accenture.

When it comes to security in the software development lifecycle (SDLC), there has been confusion about whether to “shift left” or “shift right.” To clear up this confusion, the Synopsys Building Security In Maturity Model (BSIMM) is introducing a new term to optimize security testing in a DevOps lifecycle: “shift everywhere.”

The term “shift left,” which originated roughly 15 years ago, was almost immediately misunderstood to mean implementing security testing earlier in the SDLC. This missed the point entirely. “Shift left” was always meant to mean performing security testing as early as possible in each stage of the SDLC.

Shifting left in the software delivery chain enables managing security issues early and often, mitigating the risks associated with security defects being discovered in production and reducing the cost of fixing a security vulnerability. Shifting right means testing, identifying and responding to security problems immediately in production.

“Shift everywhere” encompasses both approaches.

Why Shift Everywhere?

Organizations can no longer perform all traditional SDLC security activities in compartmentalized phases. Instead, security activities need to be expanded across all phases as a continuous effort. That means conducting a security activity as quickly as possible, with the highest fidelity, as soon as the artifacts on which that activity depends are available. In some cases, that means shift left — to the beginning of the SDLC. But in other cases, it means shift right or to the middle.

Synopsys provides solutions that transform the way development teams build and deliver software. Our comprehensive portfolio interoperates with third-party and open source tools, allowing organizations to build the security program that’s best for them. Build trust in your software with Synopsys.
Learn More
The latest from Synopsys

For example, dynamic application security testing (DAST) should be performed as soon as you have running code. Configuration reviews should be performed as soon as you have defined or running environments. Collecting composition analysis events from production agents that show dependencies dynamically incorporated into running systems should be done as soon as you have deployed code.

Again, sometimes that’s to the left of what your organization is doing today, but often it’s to the right — maybe all the way out in production.

When to Shift Left

Shifting security testing to the left in the software delivery chain enables organizations to manage security issues early and often, as part of the pipeline, and mitigating the risks associated with defects being discovered in production. This approach reduces the cost of fixing a security vulnerability.

When to Shift Right

While a shift-left approach is beneficial, it cannot mitigate the risks of critical vulnerabilities making it to production. Organizations evaluating defect discovery tools and services are showing an increased preference for continuous event-based security telemetry throughout a value stream (rather than a single point-in-time analysis).

Some common approaches to shift-right testing include leveraging blue/green, rolling deployments, runtime application self-protection (RASP), run-time analysis and tracing tools — all of which provide for continuous event-based telemetry, leading to optimizing or hardening of the application and improving the security posture.

Feedback loops from event-based telemetry enable the setup of security hooks and triggers for pipeline stages. These triggers leverage vulnerability data, attack data, threat intelligence, etc., to enforce and augment log and incident data. This results in quick identification and remediation of production vulnerabilities throughout the development workflow, from build to production to operations.

Shift right also allows leveraging data from vulnerabilities found in production, to understand gaps in security controls within the development workflow and pipeline. These gaps can be mitigated through improvements in tooling, processes and training, or through added shift-right runtime protection.

Key Benefits of Shifting Everywhere

  • Ability to address technical security debt
  • Secure software design
  • Improved code and software quality
  • Reduced false positives
  • Security attestation and immutable telemetry
  • Automated compliance safeguards
  • Improved incident-response capabilities

Conclusion

DevOps and DevSecOps are driving an IT culture change, including transforming the way organizations are handling security. This changing landscape includes engineering-led security integration, software-defined security, cloud configuration management, modern application frameworks, improvements in programming languages, container orchestration, adoption of microservices architecture, site reliability engineering (SRE), and more. All of this has resulted in the need for a “shift everywhere” security approach — leveraging telemetry, knowledge-driven intelligent pipelines, and tools that enable continuous security activities to spread throughout the development workflow, from build to operations.

Synopsys sponsored this post.

Feature image via Pixabay.

Synopsys provides solutions that transform the way development teams build and deliver software. Our comprehensive portfolio interoperates with third-party and open source tools, allowing organizations to build the security program that’s best for them. Build trust in your software with Synopsys.
Learn More
The latest from Synopsys
TRENDING STORIES
Arsh leads the Cloud and DevSecOps practice at Synopsys Software Integrity Group. His experience spans AWS/Azure/GCP Public and Hybrid Cloud Application Security, DevSecOps, Secure CI/CD, Cloud Platform Security, Data Security, Security tools/practices, Cloud GRC (Governance, Risk and Compliance), Cyberdefense, etc....
Read more from Arshad Rizvi
Synopsys sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.