Depth 28.3 · Security and compliance readiness · Level 3

Secure delivery

Secure delivery is building security checks into the way software is written and released, so problems are caught before they reach production. It covers code review, dependency scanning, secrets handling, access to production and a record of what was deployed when. It reduces risk; it does not make software free of vulnerabilities.

Specification

Input
Access to your repositories and pipelines, and the list of people who can deploy or reach production today.
Method
We add dependency, secrets and code scanning to the pipeline, move secrets into a managed store, limit production access to named roles, and make every deployment traceable to a reviewed change.
Deliverable
A pipeline with security checks, a secrets store in use, a production access list and a deployment audit trail.
Measured by
Open findings from scanners by severity and age, secrets found in code, and deployments without a linked review, which should be zero.

Most often bought inPayments and fintech, B2B software, Logistics and supply chain

The artefact, before and after

A pipeline with security checks, a secrets store in use, a production access list and a deployment audit trail.

Before: a blank secure delivery record with a row for each of dependency and code scanning, secrets management, reviewed changes only in production, least privilege production access, deployment audit trail, and no entries. After: every row carries a finding and a checked status, which is the state the work hands over.

Inside it

  • 01Dependency and code scanning
  • 02Secrets management
  • 03Reviewed changes only in production
  • 04Least privilege production access
  • 05Deployment audit trail

Typical first engagement

The usual order of a first piece of work. Timing and price are set at scoping, once we have seen the stack.

  1. 01Pipeline reviewYou get: How code, secrets and access reach production today.
  2. 02ScanningYou get: Dependency, secrets and code scanning added to the pipeline.
  3. 03Access and auditYou get: Named production roles and a deployment trail linked to reviewed changes.

Security and compliance readiness

Next in this line

Ask about this part of the stack

Write one question about secure delivery in your own systems. We answer it in writing and name what we would need to see to answer it properly.

Send one question

A written reply, no call needed.