DevOps Audit Defense Toolkit

Although dated, the principles in this toolkit are still relevant. I am using it to establish a healthy dialogue with developers and operations. I am looking forward to a new version, which addresses the new challenges of AI.

Hoang Vinh Nguyen, IT Internal Auditor

As IT organizations increasingly adopt DevOps patterns, there is more tension than ever between IT and audit. These new DevOps patterns challenge traditional thinking about auditing, controls, and risk mitigation. Just as “Dev” and “Ops” need to find new and better ways of working together to help their organization win, so now does IT and audit.

The goal of the DevOps Audit Defense Toolkit is to educate IT management and practitioners on the audit process so they can demonstrate to auditors they understand the business risks and are properly mitigating those risks.

We’ve studied a number of organizations using DevOps and continuous delivery practices that are also subject to various compliance requirements. The Toolkit summarizes the techniques they use to mitigate risk, and also provides a section answering the most common questions about value creation, compliance, and DevOps. The information in this document should help organizations wanting to pursue DevOps and continuous delivery explain their approach and improve communication between IT and audit.

Pages
22
Topics
Audit & Security
Formats
pdf
License
Creative Commons BY-NC-SA

About the author

IT Revolution

Trusted by technology leaders worldwide. Since publishing The Phoenix Project in 2013, and launching DevOps Enterprise Summit in 2014, we’ve been assembling guidance from industry experts and top practitioners.

Everything by IT Revolution →