The city’s internal DevOps team is adopting continuous delivery, while a legacy vendor still delivers waterfall releases for a mainframe tax batch system. How should security engage both?
Select an answer to reveal the explanation.
Short Explanation
One city, two delivery styles: wire security into the DevOps pipeline, and keep milestone gates for the waterfall vendor. Don’t wait for everyone to “go Agile” before caring about risk.
Full Explanation
Security must fit the delivery methodology in use: DevSecOps embeds automated and process controls in CI/CD for Agile/DevOps teams, while waterfall programs still need staged security checkpoints at defined milestones. Municipal environments often run both models concurrently. Refusing engagement until methodologies unify, or relying only on post-release hacking, leaves gaps. Methodology-aware security keeps Domain 8 controls practical across vendors and internal teams.