PS Product SecurityKnowledge Base

DevSecOps Lifecycle

DevSecOps Lifecycle

Section focus: DevSecOps Lifecycle.
Best use: start with the section map below, then move into the deeper pages that match your role or stack.
Design note: this index was refreshed to act as a cleaner GitBook landing page instead of a plain directory listing.

Start with these pages

Page Why open it first
๐Ÿ› ๏ธ Develop Phase โ€” Practical DevSecOps Controls High-value page inside DevSecOps Lifecycle.
๐Ÿงช Test Phase โ€” Fast Gates, Deep Tests, and What Still Belongs Out of Band High-value page inside DevSecOps Lifecycle.
๐Ÿ—บ๏ธ DevSecOps Toolchain โ€” Practical Map, Legacy vs Current High-value page inside DevSecOps Lifecycle.
๐Ÿงญ DevOpsSec Foundations โ€” Shift Left, Small Batches, and Compliance as Code High-value page inside DevSecOps Lifecycle.
๐Ÿงญ DevSecOps Stage Map and Modern Pipeline Patterns Best next step when you want stage-based theory translated into 2026-ready pipeline controls.
๐Ÿ—บ๏ธ DevSecOps Playbook Domains, Priority, Difficulty, and Adoption Roadmap High-value page inside DevSecOps Lifecycle.
๐Ÿงญ DevSecOps Assessment Framework (DAF) and DSOMM โ€” Practical Positioning Best next step when you need a maturity workshop or assessment overlay.

Intro: This section connects the prepare โ†’ develop โ†’ build โ†’ test โ†’ deploy โ†’ operate model to practical Product Security work. It is intentionally tool-aware and workflow-aware: what belongs in fast developer feedback, what belongs in CI, what still belongs out of band, and how older DevSecOps patterns map to current 2026 practice.

What this page includes

  • practical controls for the develop phase;
  • a modern stage map that translates older public DevSecOps guidance into current CI/CD, OIDC, artifact-trust, and evidence patterns;
  • realistic security testing lanes for the test phase;
  • a legacy vs current toolchain map so older books and trainings remain useful without freezing the KB in 2018;
  • cross-links into API, CI/CD, cloud, container, and detection sections.

Section map

How to use this section

  1. start with Develop Phase if you need better fast feedback and pre-commit hygiene;
  2. read Test Phase if you need to place DAST, IAST, fuzzing, and pen testing into the right lanes;
  3. use Toolchain Practical Map when old courses, old books, or vendor screenshots mention products that have been renamed, retired, or replaced;
  4. use DevSecOps Stage Map and Modern Pipeline Patterns when you need a clean stage-by-stage control model for GitHub Actions, GitLab, and modern release evidence;
  5. use DevSecOps Playbook Domains when you need to turn theory into an implementation backlog;
  6. use DAF / DSOMM when you need to assess where the pipeline and platform currently sit on a maturity curve.

Author attribution: Ivan Piskunov, 2026 - Educational and defensive-engineering use.

Workflow visualization