OWASP DevSecOps Maturity Model

The DevSecOps Maturity Model, shows security measures which are applied when using DevOps strategies and how these can be prioritized.

With the help of DevOps strategies, security can also be enhanced.

For example, each component such as application libraries and operating system libraries in docker images can be tested for known vulnerabilities.

Attackers are intelligent and creative, equipped with new technologies and purpose. Under the guidance of the forward-looking DevSecOps Maturity Model, appropriate principles and measures are at hand implemented which counteract the attacks.

The DevSecOps Maturity Model shows security measures which are applied when using DevOps strategies and how these can be prioritized. The model defines 4 maturity levels:

  • Level 1: Basic understanding of security practices
  • Level 2: Adoption of basic security practices
  • Level 3: High adoption of security practices
  • Level 4: Advanced deployment of security practices at scale