Secure Software Development, Security, and Operations (DevSecOps) Practices
Secure Software Development, Security, and Operations (DevSecOps) Practices
September 2026
This publication is available free of charge from https://www.nccoe.nist.gov/projects/secure-software-development-security-and-operations-devsecops-practices
National Institute of Standards and Technology
- 1. Introduction
- 2. Notional Reference Model for DevSecOps for Demonstration of NIST SSDF Updated
- 3. Mapping SSDF to DevSecOps Notional Reference Model New
- 4. Example Implementations Updated
- 5. Functional Demonstrations New
- 6. Next Steps
- Appendix A List of Acronyms
- Appendix B Component Description
- Appendix C SSDF Analysis New
- C.1. Prepare the Organization (PO)
- C.1.1. PRACTICE (PO.1) - Define Security Requirements for Software Development:
- C.1.2. PRACTICE (PO.2) - Implement Roles and Responsibilities:
- C.1.3. PRACTICE (PO.3) - Implement Supporting Toolchains:
- C.1.4. PRACTICE (PO.4) - Define and Use Criteria for Software Security Checks:
- C.1.5. PRACTICE (PO.5) - Implement and Maintain Secure Environments for Software Development:
- C.2. Protect Software (PS)
- C.3. Produce Well-Secured Software (PW)
- C.3.1. PRACTICE (PW.1) - Design Software to Meet Security Requirements and Mitigate Security Risks:
- C.3.2. PRACTICE (PW.2) - Review the Software Design to Verify Compliance with Security Requirements and Risk Information:
- C.3.4. PRACTICE (PW.4) - Reuse Existing, Well-Secured Software When Feasible Instead of Duplicating Functionality:
- C.3.5. PRACTICE (PW.5) - Create Source Code by Adhering to Secure Coding Practices:
- C.3.6. PRACTICE (PW.6) - Configure the Compilation, Interpreter, and Build Processes to Improve Executable Security:
- C.3.7. PRACTICE (PW.7) - Review and/or Analyze Human-Readable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements:
- C.3.8. PRACTICE (PW.8) - Test Executable Code to Identify Vulnerabilities and Verify Compliance with Security Requirements:
- C.3.9. PRACTICE (PW.9) - Configure Software to Have Secure Settings by Default:
- C.4. Respond to Vulnerabilities (RV)
- C.1. Prepare the Organization (PO)
- Appendix D Collaborators and their Contribution
- D.1. AMI
- D.2. Black Duck
- D.3. CyberArk Software
- D.3.1. CyberArk Privilege Cloud
- D.3.2. CyberArk Endpoint Privilege Manager
- D.3.3. CyberArk Code Sign Manager
- D.3.4. CyberArk Secrets Hub
- D.3.5. CyberArk Conjur Cloud
- D.3.6. CyberArk Workload Identity
- D.3.7. CyberArk Certificate Manager SaaS
- D.3.8. CyberArk Certificate Manager (Self-Hosted)
- D.3.9. CyberArk Certificate Manager for Kubernetes
- D.4. Dell Technologies
- D.5. DigiCert
- D.6. Endor Labs
- D.7. GitLab
- D.8. Google
- D.9. IBM
- D.10. Microsoft and GitHub Advanced Security (GHAzDO)
- D.10.1. Azure Container Registry (ACR)
- D.10.2. Azure DevOps (AzDO)
- D.10.3. Azure Entra ID
- D.10.4. Azure Key Vault (AKV)
- D.10.5. Azure Managed DevOps Pool (MDP)
- D.10.6. Azure Privileged Identity Management (PIM)
- D.10.7. Azure Sentinel
- D.10.8. Bicep and Azure Resource Manager (ARM)
- D.10.9. GitHub Advanced Security (GHAS)
- D.10.10. GitHub Copilot
- D.10.11. IDEs – Visual Studio and Visual Studio Code (VS Code)
- D.10.12. Microsoft Defender for Cloud (MDC)
- D.10.13. Microsoft SBOM Tool
- D.10.14. Notary Project
- D.11. NextLabs
- D.12. Palo Alto Networks
- D.13. Resilience Cyber Security
- D.14. Sagittal AI
- Appendix E Change Log Updated