Overview
This conference talk from Conf42 DevOps 2025 provides a comprehensive guide to establishing an effective DevSecOps program. Learn how to set clear goals for key stakeholders, develop engagement strategies to secure buy-in, and implement educational initiatives that build security awareness across teams. Discover the value of matrix teams and security champions in fostering collaboration between development and security professionals. The 32-minute presentation covers both technical and non-technical success patterns, explores program highlights that demonstrate measurable impact, and looks ahead to future developments like Software Bill of Materials (SBOM) integration. The talk concludes with actionable takeaways to help organizations successfully embed security practices throughout their development lifecycle.
Syllabus
00:00 Introduction to DevSecOps Program
01:42 Setting Goals for Key Players
04:29 Engagement Strategy and Stakeholder Buy-In
06:52 Educational Initiatives and Training
12:51 Matrix Teams and Security Champions
15:23 Program Highlights and Success Patterns
20:40 Technical and Non-Technical Success Patterns
27:37 Future Steps: SBOM and DevSecOps
29:39 Conclusion and Key Takeaways
Taught by
Conf42