Description

Susan Jones had been the CEO of Investments Unlimited, Inc. (IUI) for five years, a financial institution that has successfully navigated their digital transformation. She is quick on her feet and is trusted by the board. But right now—although you can't tell from her demeanor—she was panicking.

Today, IUI received notice from bank regulators concerning their unsatisfactory audit and compliance practices. If they failed to address the regulators' concerns within the year, the company could go up in smoke.

She didn't understand. How had her team let this happen? How had she let this happen?

Over the past several years, IUI had executed a digital transformation strategy following the business accelerating principles of Agile and DevOps. By any metric they had seemingly done things right. Feedback from customers was astounding and conversion rates for new accounts was growing faster than ever. But along the way IUIs manual governance process had become inundated with friction, frustration, and failure for the teams attempting to deliver value for their organizations.

Now, it's all hands on deck for a cross-functional team of executives and engineers to develop a modern automated governance process that satisfies regulators without slowing the company's ability to meet customer demands and compete in the market.

In the vein of bestselling titles The Phoenix Project and The Unicorn Project, Investments Unlimited helps organizations radically rethink how they handle audit, compliance, and security for their software systems. By introducing concepts, tools, and ideas to reimagine governance, this book catalyzes a more humane way to enable high-velocity software delivery that inspires trust and is inherently more secure.

About the author(s)

Helen Beal is a DevOps and Ways of Working coach, Chief Ambassador at DevOps Institute, and ambassador for the Continuous Delivery Foundation. She is the Chair of the Value Stream Management Consortium and provides strategic advisory services to DevOps industry leaders. She is also an analyst at Techstrong Research, hosts the Day-to-Day DevOps webinar series for BrightTalk and the Value Stream Evolution series on TechStrong TV. She currently lives in the UK.

Bill Bensing builds things that build things. He is a skilled leader and architect of software, people, teams, and companies. Bill is an expert at making innovation a wholly inclusive process. His love of DevOps comes from a background in logistics and operations management. Automated Governance is a topic Bill finds very interesting. He believes a lack of good governance is the single biggest issue preventing breakthrough value. Bill will tell you, “Good strategy and good governance are the grease and guide rails for success.” He lives in the Tampa Bay, FL, area.

Jason Cox is a champion of DevOps practices, promoting new technologies and better ways of working. He enjoys helping organizations deliver more value, better, faster, safer and happier. He is an inspirational speaker who loves people and delights in amplifying their abilities with technology. Jason frequently speaks at conferences, contributes to open source and writes on technical and leadership topics. He currently leads several SRE teams and resides in Los Angeles with his wife and their children.

Michael Edenzon is a senior IT leader and engineer that modernizes and disrupts the technical landscape for highly regulated organizations. Michael provides technical design, decisioning, and solutioning across complex verticals and leverages continuous learning practices to drive organizational change. He is a fervent advocate for the developer experience and believes that enablement-focused automation is the key to building compliant software at scale.

Caleb Queern helps CIOs and CISOs reduce risk across the software development life cycle so they can innovate quickly and win in the market. He lives in Austin, Texas with his wife, Marian, and son, Joseph.

John Rzeszotarski assists organizations with strategic planning and leadership in the solution and infrastructure focus areas; moreover, John provides thought leadership to large enterprises that need to focus on reliability, scalability, regulatory, and other business considerations. His expertise spans many verticals with a focus on digital, payments, security, development, and his primary passion is solving business and IT problems thru technology, process, and culture transformations.

 Andres Vega helps engineering organizations securely build large-scale, distributed software leveraging novel approaches to reduce the compliance toil associated with the area. He is recognized in the open-source community as a maintainer, contributor, and technical leader focused on the improvement of ecosystem security. Outside of his profession, he is a family guy and an avid outdoors person. You are sure to find him adventuring with his family all over the trails of the San Francisco Bay Area in his best attempt not to get mauled to death by hungry mountain lions.

John Willis is Senior Director of the Global Transformation Office at Red Hat. Prior to Red Hat, he was the Director of Ecosystem Development for Docker. John was one of the earliest cloud evangelists and is considered one of the founders of the DevOps movement. John is the author of 7 IBM Redbooks, as well as co-author of the The DevOps Handbook and Beyond the Phoenix Project.
 

Topo Pal is a thought leader, keynote speaker, evangelist in the areas of DevSecOps, Continuous Delivery, Cloud Computing, Open Source Adoption and Digital Transformation. He is a hands-on developer and Open Source contributor. Topo has been leading and contributing to industry initiatives around automated governance in DevOps practices. Topo resides in Richmond, VA, with his wife and two children.

Reviews

“This book does an amazing job of explaining how good DevOps practices can help ensure that your software if safe, secure, and auditable. I learned a lot from it, which I can't say often after reading DevOps books over the last ten years. This is a must-read for any CISO or executive looking to improve the security and compliance practices in their organization.”

Ross Clanton, Chief Architect and Managing Director, American Airlines

“Investments Unlimited builds upon years of DevSecOps literature while firmly anchoring the principles into regulated entities like financial services. The technology fable will keep you engaged with relatable stories and conversations, and practical knowledge for you to implement at your own firm and inside your team.”

Dr. Brandon R. Williams, VP IAM Strategy, Ping Identity

“Finally we have a book that can be leveraged by everyone in your organization involved in meeting security, audit, and compliance requirements. You'll be able to apply this practical guidance immediately, and I really appreciate the inclusion of all of the functions and roles required to be successful. It's a great reminder that we are all in this together!”

Courtney Kissler, SVP, Customer and Retail Technology Starbucks

“Today, software developers are just as much security engineers, whether they know it or not. In a unique and compelling way, Investments Unlimited illustrates how to safely automate security testing, audit, and compliance to help organizations move faster, safer. It's a fast and fun story that sheds light on a much-needed subject: the importance of bringing security, audit, and compliance out of the shadows and into the everyday life of a developer. Security, audit, and compliance are everyone's job every day. Investments Unlimited joyfully brings to light that these essential functions are enabled by DevOps.”

Jim Manico, Founder and Secure Coding Educator, Manicode Security

More by John Willis

More by Helen Beal

More by Jason Cox

More by Michael Edenzon

More by John Rzezotarski

More by Andres Vega

More by Caleb Queern

More by Bill Bensing

More by Tapabrata Pal

More Management

More Business & Economics

More Corporate Governance

More Production & Operations Management

More Information Management

More Computers & Information Technology

More Industries