Security a Top Priority in the Software Development Process, Report Finds

SmileStudioAP/Getty

However, the government is lagging behind the private sector in using some of these tools.

Security remains a priority for DevSecOps, which is increasingly turning to developers and technology as part of the process, according to a GitLab DevSecOps report released Thursday. 

For example, there was an increase in developer led-security. According to the report, 71% of respondents said that their vulnerabilities are being caught by developers.

“That’s a sort of a signal to me that the security organizations I think are getting more comfortable with developers finding and correcting vulnerabilities during the development process, rather than waiting until the end, and then doing what folks traditionally do: running it through a bunch of tools, generating a report and then spending months fixing everything that’s in that report,” Bob Stevens, GitLab’s vice president of public sector, told Nextgov. “So, to me, the security groups [are] embracing the tools that exist and starting to rely more and more on them to be able to ensure that code is being developed securely.”

Despite the need for better digital experiences and improved security, the report found that 75% of public sector respondents reported deploying software at the same rate or slower than last year. In the 2022 report, this was 59% of respondents. 

“I’m surprised that number is so high, especially with the tools that exist out there today, but maybe I shouldn't be surprised,” Stevens said. “But I can tell you that there’s a lot of agencies that are still stuck in waterfall and haven’t moved to agile development and they’re still very stove-piped and they’re struggling to figure out how to get out of that scenario. It’s a cultural change is really what it comes down to.”

However, Stevens noted for the commercial sector this is only 40%, which he stated “would indicate that the government is falling behind in regards to their transition to newer development tools and building software factories and the deployment of a platform.”

Meanwhile more than 50% of government respondents reported evaluating or buying a DevSecOps platform in the next one to three years. 

However, the report found that 44% of public sector respondents were using more than six tools and some were using more than 15 tools. 

“The more tools you use, the more opportunity you create for vulnerabilities or poorly written code,” he added. “You also slow things down because things can be written in a stove pipe and then you try and merge all those pipes together in the end and, oh, by the way, they normally don’t work well when you do that. So you slow things down when there’s that many tools. Cost is another thing.”

Moreover, 59% of government and defense or aerospace respondents are looking to consolidate the number of tools they use.  

According to Stevens, this can help “reduce complexity, increase speed to mission, reduce cost,” which includes the cost of the tool and training. He added it also makes remote work more feasible.

Meanwhile, artificial intelligence and machine learning were also important for DevSecOps, the report noted. Specifically, developers that used a DevSecOps platform were more likely to utilize automation and AI or ML for testing purposes than those who do not use a platform. In particular, 65% of developers said they are using AI or ML to test or would be in the next three years. Additionally, 62% of developers using AI or ML use it to check code, an increase from the 2022 report which only had 51% of developers using it for this purpose. Furthermore, 53% of developers using AI or ML use bots for testing, in 2022 this was 39%. 

“I think that this is to help with speed to mission,” Stevens said. “If you don’t have to reinvent the wheel and you can rely on AI or machine learning to do something or aid in something that's kind of common in development, then you can help save time and ensure that it's secure. Both right, you're gonna accomplish efficiency and security. So, I think we're going to see more and more use of AI, in particular, in software development because there’s just aspects of it where it just makes sense. It just makes everybody's life a lot easier to be able to write the code.”

GitLab surveyed more than 5,000 IT and software professionals, including public sector professionals, in March 2023 for this report. 

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.