“This book does an amazing job of explaining how good DevOps practices can help ensure that your software if safe, secure, and auditable. I learned a lot from it, which I can't say often after reading DevOps books over the last ten years. This is a must-read for any CISO or executive looking to improve the security and compliance practices in their organization.”
Description
Susan Jones had been the CEO of Investments Unlimited, Inc. (IUI) for five years, a financial institution that has successfully navigated their digital transformation. She is quick on her feet and is trusted by the board. But right now—although you can't tell from her demeanor—she was panicking.
Today, IUI received notice from bank regulators concerning their unsatisfactory audit and compliance practices. If they failed to address the regulators' concerns within the year, the company could go up in smoke.
She didn't understand. How had her team let this happen? How had she let this happen?
Over the past several years, IUI had executed a digital transformation strategy following the business accelerating principles of Agile and DevOps. By any metric they had seemingly done things right. Feedback from customers was astounding and conversion rates for new accounts was growing faster than ever. But along the way IUIs manual governance process had become inundated with friction, frustration, and failure for the teams attempting to deliver value for their organizations.
Now, it's all hands on deck for a cross-functional team of executives and engineers to develop a modern automated governance process that satisfies regulators without slowing the company's ability to meet customer demands and compete in the market.
In the vein of bestselling titles The Phoenix Project and The Unicorn Project, Investments Unlimited helps organizations radically rethink how they handle audit, compliance, and security for their software systems. By introducing concepts, tools, and ideas to reimagine governance, this book catalyzes a more humane way to enable high-velocity software delivery that inspires trust and is inherently more secure.
Reviews
“Investments Unlimited builds upon years of DevSecOps literature while firmly anchoring the principles into regulated entities like financial services. The technology fable will keep you engaged with relatable stories and conversations, and practical knowledge for you to implement at your own firm and inside your team.”
“Finally we have a book that can be leveraged by everyone in your organization involved in meeting security, audit, and compliance requirements. You'll be able to apply this practical guidance immediately, and I really appreciate the inclusion of all of the functions and roles required to be successful. It's a great reminder that we are all in this together!”
“Today, software developers are just as much security engineers, whether they know it or not. In a unique and compelling way, Investments Unlimited illustrates how to safely automate security testing, audit, and compliance to help organizations move faster, safer. It's a fast and fun story that sheds light on a much-needed subject: the importance of bringing security, audit, and compliance out of the shadows and into the everyday life of a developer. Security, audit, and compliance are everyone's job every day. Investments Unlimited joyfully brings to light that these essential functions are enabled by DevOps.”