DevSecOps (v1.1.17)

DevSecOps CI/CD Orchestration Integration Pack.

Author
Ayman Mahmoud
Support
community
Categories
IT Services

Incident fields (89)

Indicator fields (6)

Indicator types (3)

Integrations (4)

Layouts (1)

README

DevSecOps content pack contains multiple integrations and playbooks to help shifting security as left as the planning stage of a continues integration pipeline and make DevSecOps orchestration to be within reach.

While CI/CD orchestration tools such as Jenkins, CircleCI and others were primarily built by and to developers, SOAR is better positioned to bridge this orchestration gap between DevOps and SecOps for the following reasons:

With SOAR integrations, playbooks, fields, XSOAR can be turned into a DevSecOps Orchestrator that taps in a DevSecOps Eco-System and solve for a spectrum of use cases in different stages of CI/CD piplines.

From threat-modeling in the Planning stage to IaC security in Dev, static code analysis in Build, post deployment scans in Deploy and Monitoring/Responding to incidents once the code is running in production.

This content pack will be updated with more integrations with different software factory tools:

This version of the pack has four integrations :

A new incident type along with new fields:

A new playbook: