Release and deployment in DevSecOps

Release and deployment in DevSecOps determine whether the security work done earlier in the lifecycle is preserved through to production. Strong practices for dependency management, release governance, and deployment workflows help make software delivery secure, repeatable, and trustworthy.

This capability area describes how an organization manages secure dependencies, secures its releases, and operates its deployment workflows. It's where the security work of earlier phases is either preserved through to production or lost.

As organizations mature, release and deployment move from fragile, ad hoc delivery toward reflexive processes supported by prediction. Dependency management matures through Secure Supply Chain Consumption Framework (S2C2F) levels, releases gain automated security testing and rollback capabilities, and deployment workflows become continuous, code-managed, and increasingly self-healing.

Core capability areas

Release and deployment in DevSecOps focuses on three sub-capabilities:

  • Secure dependencies: How third-party and open source dependencies are inventoried, scanned, and maintained.

  • Secure releases: How vulnerabilities are identified and managed across milestones and releases.

  • Deployment workflows: How deployments are automated, tested, and made reliable and repeatable.

Stages

Release and deployment progresses through five stages of maturity. These stages show how DevSecOps principles appear in the administration of engineering systems, from late and inconsistent protection to protected processes that are augmented by prediction.

Overall stage Stage name What it looks like
Ad-hoc Fragile Little is protected from the beginning; threats are identified and mitigated late, if at all.
Initiating Structured Foundational processes lead to early benefits from more frequent, predictable releases.
Orchestrating Enriched Automation and expanded test coverage before deployment add certainty and reduce risk.
Streamlining Continuous Deeper coverage through automation increases confidence and provides release agility.
Pioneering Reflexive Protected processes are augmented with advances in prediction.

Fragile (Ad-hoc)

When teams focus only on producing initial output and delivery, they don't build security into the development process from the start. They often identify and mitigate threats late, if at all.

  • Secure dependencies: There's no organized inventory. Package updates are manual and might not happen at all.

  • Secure releases: Organized release security efforts are absent.

  • Deployment workflows: Deployment efforts are scattered and ad hoc.

Structured (Initiating)

As teams establish release and deployment processes, they begin to see the early benefits of more frequent and predictable releases.

  • Secure dependencies: Teams perform S2C2F level 1 activities. License checking is manual, and customer notices are rudimentary.

  • Secure releases: Teams run manual checks for vulnerabilities, licensing, and version issues at milestones and releases, typically by using third-party sites.

  • Deployment workflows: Workflows exist, but they're largely manual and can be inconsistent or incomplete. Deployments are usually large and infrequent.

Enriched (Orchestrating)

Introducing automation and expanding test coverage before deployment adds certainty and reduces risk.

  • Secure dependencies: Teams define an initial change-management process with review and approvals for version changes. They use software bills of materials (SBOMs), license scanning, and S2C2F level 2 activities. Data masking is introduced.

  • Secure releases: Automated dynamic application security testing tools are used at key milestones to identify vulnerabilities and other issues. Remediation is still difficult and time-consuming.

  • Deployment workflows: Workflows become mature and reliable. Release pipelines include comprehensive automated testing, including dynamic application security testing and performance testing. Artifacts are verified with code signing.

Continuous (Streamlining)

Automation that provides deeper coverage of components and scenarios increases confidence and gives teams more release agility.

  • Secure dependencies: Automated external situational awareness enables preventive defensive actions. Teams perform S2C2F level 3 activities and generate SBOMs automatically.

  • Secure releases: Teams maintain end-to-end inventory, introduce malware defense and zero-day detection, and avoid trading quality for speed because they can roll back effectively and quickly.

  • Deployment workflows: Automated, continuous dynamic application testing is integrated throughout the cycle. AI helps provide automatic healing, and infrastructure is managed as code. Smaller, more frequent changes can deploy continuously without sacrificing reliability.

Reflexive (Pioneering)

Protected and guarded processes are enhanced with predictive capabilities that create extra security and efficiency advantages.

  • Secure dependencies: Teams maintain contingency plans for each dependency, contribute security fixes and updates back to open source software, and perform S2C2F level 4 activities.

  • Secure releases: Strategic investments further improve the ability to predict and prevent exposure.

  • Deployment workflows: Agentic AI is used to optimize workflows and create efficiencies that improve security and streamline continuous deployment.