Glossary

DevSecOps

DevSecOps is the practice of integrating security verification into the software delivery process rather than applying it as a separate review at the end.

Short answer

What is devsecops?

DevSecOps is the practice of integrating security verification into the software delivery process rather than applying it as a separate review at the end.

Explained two ways

Plain and technical

In plain terms

Security used to be a review that happened once the software was built, which meant problems were found when they were most expensive to fix and the review became something teams tried to route around. DevSecOps builds the checks into the delivery process so problems surface while they are still cheap.

Technically

DevSecOps implements security controls at multiple enforcement points: dependency and image scanning in the pipeline, infrastructure-as-code checks before apply, admission control in the cluster, and continuous posture evaluation at runtime. Findings are prioritised by environmental exposure rather than severity score alone and routed to the owning team with verified closure.

Example

What it looks like in practice

A pull request runs a dependency scan scoped to the diff. It reports one newly introduced vulnerable package with the version to upgrade to, rather than the repository entire backlog. The developer fixes it before merging.
Keep going

More definitions

See these concepts in a running system

A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.