by t_believ-er873 on 8/9/24, 8:48 AM with 13 comments
by thanksgiving on 8/9/24, 9:49 AM
If the business wants to dictate deadlines, the business is responsible for security.
Edit: I should say development team to include qa, but we don’t have those anymore at most places.
by drewcoo on 8/9/24, 9:33 AM
This is the best that most separate security teams do, too.
In all fairness, the "DevOps" part of things can manage deploys in ways to minimize exposure. But most teams that I've seen revert to manual "process" whenever something unusual occurs, so forget about the ideal automated responses to problems we were promised when we were trying to automate sysadmins out of their jobs. There are several layers of broken here that we're not allowed to talk about.
by firtoz on 8/9/24, 9:52 AM
by CAP_NET_ADMIN on 8/9/24, 10:55 AM
I've resisted this, because I know that I can sleep peacefully at night when the inevitable monthly "GitLab Critical Patch Release" email comes.