Feedback Requested: DevSecOps Standard RFP from OMG
OMG发布RFP寻求开发标准化企业级DevSecOps集成方法,涵盖角色集成、实践对齐、兼容性、工具分析、成熟度与安全性等关键领域。DIDO Solutions正准备正式回应,并寻求行业反馈以制定实用标准。 2025-7-4 00:15:44 Author: www.reddit.com(查看原文) 阅读量:20 收藏

We’re part of the Object Management Group (OMG), which has issued a Request for Proposal (RFP) to develop a standardized approach to DevSecOps integration across the enterprise. If you or your organization are interested in contributing, you can view the full RFP here:
https://www.omg.org/cgi-bin/doc.cgi?c4i/2025-3-4

  • Role-based integration of DevSecOps into organizational guidance and policy

  • Alignment of practices, tools, and standards across varied enterprise teams

  • Compatibility across projects using different pipelines and infrastructures

  • Analysis of alternatives (AoA) for toolchains and methodologies

  • Maturity, reliability, and security measures for DevSecOps implementations

We’re currently working on a formal response at DIDO Solutions and are seeking constructive feedback and collaboration from the broader DevSecOps, cybersecurity, and infrastructure communities. Our goal is to shape a standard that reflects both technical realities and organizational constraints.

Attached: Requirements Overview (image)
This diagram outlines the role-based breakdown we're using as a foundation covering leadership, engineering, operations, QA, and compliance.

If you have suggestions, critiques, or want to contribute perspectives from the field, we’d love to hear from you. Please feel free to reply directly in the thread or leave comments on the google sheet. We will be converting it into a model by the end:


文章来源: https://www.reddit.com/r/netsec/comments/1lr51di/feedback_requested_devsecops_standard_rfp_from_omg/
如有侵权请联系:admin#unsafe.sh