# Ensuring comprehensive security testing in DevOps pipelines

DevFeed: [Ensuring comprehensive security testing in DevOps pipelines](<https://devfeed.tech/articles/ensuring-comprehensive-security-testing-in-devops-pipelines-7906.md>)

Original publisher: [Read original article](<https://snyk.io/blog/ensuring-comprehensive-devops-security-testing/>)

Author: Jim Armstrong

Published: 2024-10-17T05:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [DevOps](<https://devfeed.tech/topics/devops.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [iac-security](<https://devfeed.tech/tags/iac-security.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [testing](<https://devfeed.tech/tags/testing.md>)

## AI overview

This article explains why traditional security processes often create friction when inserted into DevOps pipelines and presents DevSecOps as a model that integrates security into software delivery. It focuses on comprehensive security testing and monitoring, risk-profile-based policies, threat modeling, security requirements gathering, and the use of SAST and SCA tools with IDEs for real-time feedback.

## Source excerpt

Learn how to integrate comprehensive security testing into DevOps pipelines to protect your entire software development lifecycle.