Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Development and testing in DevSecOps determine whether security becomes part of daily engineering work or remains something teams address too late. Strong practices in coding, tooling, integration, and testing help teams find and fix problems while code is still being written.
This capability area describes how teams write secure code, accelerate development with sanctioned tools and components, and integrate and test their work. It's the point where security either becomes part of everyday engineering or remains an afterthought.
As organizations mature, development and testing move from disparate, unmanaged activity toward an optimized environment tuned for individual developers. Security testing becomes continuous, AI and open source move from ungoverned to enterprise-safe and purposeful, and testing shifts from periodic and manual to automated and left-shifted.
Core capability areas
Development and testing in DevSecOps focuses on three sub-capabilities:
Code security: How security tooling and testing are applied to code as it's written and reviewed.
Development accelerators: How AI, open source, and reusable components are governed and used to speed delivery.
Integration and testing: How repositories, branches, builds, and automated testing are managed.
Stages
Development and testing progress through five stages of maturity. These stages show how DevSecOps principles appear in developer activities, from unmanaged experimentation to an optimized code and test environment that improves developer efficiency.
| Overall stage | Stage name | What it looks like |
|---|---|---|
| Ad-hoc | Disparate | No management of resources; rapid prototyping and unbridled exploration. |
| Initiating | Emergent | Teams improvise oversight, beginning to shift toward a DevOps mindset. |
| Orchestrating | Continuous | A comprehensive strategy with automation bakes standards into continuous processes. |
| Streamlining | Left-shifted | Shifting left means issues are found earlier and cost less to remediate. |
| Pioneering | Optimized | The code and test environment is optimized for individual developer efficiency. |
Disparate (Ad-hoc)
Without management of resources or initial coding activities, rapid prototyping and unbridled exploration are possible. This state is a natural starting point for startups and new organizations.
Code security: There's little or no consistent use of code security tools, which creates a growing risk surface.
Development accelerators: Teams use unsanctioned AI tools outside the organization and make wide, ungoverned use of open source software or community code samples. A lack of policy can also cause some developers to avoid these tools entirely, missing opportunities for efficiency.
Integration and testing: Work is scattered across multiple repositories, and builds are done manually and infrequently with varying configurations.
Emergent (Initiating)
Teams begin to improvise oversight of assets and methodologies, starting a broader shift toward a DevOps mindset.
Code security: Teams use local security testing tools occasionally.
Development accelerators: Teams acknowledge risks from unsanctioned AI and open source, and policies emerge in pockets of the organization, including restrictions or guidance for code reuse from developer communities.
Integration and testing: Teams define repository and branching strategies. Testing is still mostly periodic, manual, and sometimes outsourced. At the same time, testability starts to emerge in pockets, and some teams adopt continuous integration practices.
Continuous (Orchestrating)
With a comprehensive strategy supported by automation, dynamic tools and processes help bake standards into continuous workflows and monitoring.
Code security: Some security testing is in place, security becomes part of code review, and deeper security testing runs on a schedule. Standardized naming and branching strategies are adopted.
Development accelerators: Enterprise-safe AI and open source are made available under usage policy. AI is integrated into IDEs as a programming aid and into DevOps tools that improve pull request workflows.
Integration and testing: Standardized naming, branching strategies, and testing frameworks are in place. Automated testing is introduced into primary CI/CD pipelines, including some integration testing.
Left-shifted (Streamlining)
Creating an environment for shifting left means issues are found earlier and cost less to remediate.
Code security: Teams enforce gating for high-severity security findings. IDE code tools include security features, including protection against prompt injection and data poisoning.
Development accelerators: Teams use enterprise-safe large language models (LLMs) aligned to clear patterns and standards. AI-powered software engineering and DevOps agents begin to automate work and operate with increasing autonomy.
Integration and testing: Widespread testing practices are in place, including unit and integration tests. Automated testing runs continuously and catches problems earlier in the process. Teams also use phishing simulations.
Optimized (Pioneering)
When you optimize the code and test environment for individual developers, you create more personalized efficiency.
Code security: Security becomes continuous and is supported by advanced observability.
Development accelerators: Developers extend code-assistant LLMs with their own custom patterns. Component use becomes deliberate and is designed to meet goals for performance, compliance, and risk management. MCP servers and orchestration emerge as part of the toolchain.
Integration and testing: Test automation becomes comprehensive, including performance testing. Teams also adopt AI-driven threat detection and pursue other opportunities to improve engineering feedback loops.