100%
DevSecOps Assessment
Contact Information
First Name
Last Name
Phone
Email Address
People & Culture
Our leadership enables regular sharing and collaboration across operations, development, and security teams.This question is required.
Our leadership enables regular sharing and collaboration across operations, development, and security teams.This question is required.
Strongly Disagree
Disagree
Agree
Strongly Agree
We have established an effective onboarding process for new engineering hires which enables them to ramp up quickly.
We have established an effective onboarding process for new engineering hires which enables them to ramp up quickly.
Strongly Disagree
Disagree
Agree
Strongly Agree
Team members know who to report security concerns to
Team members know who to report security concerns to
Strongly disagree
Disagree
Agree
Strongly agree
Team members are able to discuss burnout and are empowered to take mitigation measures
Team members are able to discuss burnout and are empowered to take mitigation measures
Strongly disagree
Disagree
Agree
Strongly agree
Plan & Develop
Risk assessment or threat modeling is conducted for every new service as part of the design phase.
Risk assessment or threat modeling is conducted for every new service as part of the design phase.
Strongly disagree
Disagree
Agree
Strongly agree
We perform static code analysis (e.g., static application security testing, or SAST) during the development phase to prevent commits of vulnerable code.
We perform static code analysis (e.g., static application security testing, or SAST) during the development phase to prevent commits of vulnerable code.
Strongly agree
Agree
Disagree
Strongly disagree
Engineers spend the majority of their time on new features and improvements rather than unplanned / bug fix work.This question is required.
Engineers spend the majority of their time on new features and improvements rather than unplanned / bug fix work.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
We prioritize reducing our technical debt across applications and infrastructure.This question is required.
We prioritize reducing our technical debt across applications and infrastructure.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
Build & Test
We perform dynamic code scanning (e.g., dynamic application security testing, or DAST) on committed code to stop the packaging of vulnerable code.This question is required.
We perform dynamic code scanning (e.g., dynamic application security testing, or DAST) on committed code to stop the packaging of vulnerable code.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
We validate builds and signatures to block unsigned or vulnerable packages.This question is required.
We validate builds and signatures to block unsigned or vulnerable packages.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
Pull requests made to production branches are always subject to automated tests and approval/review.This question is required.
Pull requests made to production branches are always subject to automated tests and approval/review.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
We continuously test the core business functionality of our applications.
We continuously test the core business functionality of our applications.
Strongly disagree
Disagree
Agree
Strongly agree
Release & Deploy
Our tooling allows us to fully automate deployments and releases into production.
Our tooling allows us to fully automate deployments and releases into production.
Strongly disagree
Disagree
Agree
Strongly agree
We push code into production at a frequency that gives us a competitive edge in our industry.
We push code into production at a frequency that gives us a competitive edge in our industry.
Strongly disagree
Disagree
Agree
Strongly agree
We have decided on and implemented a set of criteria for failing a new deployment based on security posture.
We have decided on and implemented a set of criteria for failing a new deployment based on security posture.
Strongly disagree
Disagree
Agree
Strongly agree
We have the ability to quickly roll back or forward fix a failed deployment.This question is required.
We have the ability to quickly roll back or forward fix a failed deployment.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
Operate
Our infrastructure is managed by configuration management / orchestration tools and is committed to a code repository.This question is required.
Our infrastructure is managed by configuration management / orchestration tools and is committed to a code repository.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
We have a capacity planning process for our infrastructure that factors in growth and seasonality.
We have a capacity planning process for our infrastructure that factors in growth and seasonality.
Strongly disagree
Disagree
Agree
Strongly agree
We have the ability to auto-scale infrastructure and select services when certain conditions are met (e.g., an unexpected influx of legitimate requests).This question is required.
We have the ability to auto-scale infrastructure and select services when certain conditions are met (e.g., an unexpected influx of legitimate requests).This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
Our production environments are highly available, spanning multiple availability zones, regions, or cloud providers.This question is required.
Our production environments are highly available, spanning multiple availability zones, regions, or cloud providers.This question is required.
Strongly disagree
Disagree
Agree
Strongly agree
We run chaos tests or game days on our infrastructure and applications in production.
We run chaos tests or game days on our infrastructure and applications in production.
Strongly disagree
Disagree
Agree
Strongly agree
We conduct red team tests/adversary simulation to improve our security detection and operations capabilities.
We conduct red team tests/adversary simulation to improve our security detection and operations capabilities.
Strongly disagree
Disagree
Agree
Strongly agree
We have an established SLA for patching systems found to be vulnerable.
We have an established SLA for patching systems found to be vulnerable.
Strongly disagree
Disagree
Agree
Strongly agree
We have a disaster recovery (DR) strategy in place that is tested at regular intervals.
We have a disaster recovery (DR) strategy in place that is tested at regular intervals.
Strongly disagree
Disagree
Agree
Strongly agree
Observe & Respond
It is easy for teams to find all relevant observability data pertaining to the health and security of an application or platform.
It is easy for teams to find all relevant observability data pertaining to the health and security of an application or platform.
Strongly disagree
Disagree
Agree
Strongly agree
We have a mature metadata model, via the use of tags or labels, which helps us quickly search, filter, and correlate relevant monitoring data.
We have a mature metadata model, via the use of tags or labels, which helps us quickly search, filter, and correlate relevant monitoring data.
Strongly disagree
Disagree
Agree
Strongly agree
Using SLOs and error budgets is our preferred methodology for measuring infrastructure and service reliability.
Using SLOs and error budgets is our preferred methodology for measuring infrastructure and service reliability.
Strongly disagree
Disagree
Agree
Strongly agree
Our organization has visibility into end-to-end customer journeys.
Our organization has visibility into end-to-end customer journeys.
Strongly disagree
Disagree
Agree
Strongly agree
Security metrics are defined and visible to development, security, operations, and senior leadership teams across 100% of services.
Security metrics are defined and visible to development, security, operations, and senior leadership teams across 100% of services.
Strongly disagree
Disagree
Agree
Strongly agree
We continuously scan our production infrastructure and applications for vulnerabilities and misconfigurations.
We continuously scan our production infrastructure and applications for vulnerabilities and misconfigurations.
Strongly disagree
Disagree
Agree
Strongly agree
Our team is able to quickly detect and remediate incidents.
Our team is able to quickly detect and remediate incidents.
Strongly disagree
Disagree
Agree
Strongly agree
We create blameless post-mortems / root cause analyses in a timely manner with clear descriptions of what happened and plans to prevent similar incidents from occurring.
We create blameless post-mortems / root cause analyses in a timely manner with clear descriptions of what happened and plans to prevent similar incidents from occurring.
Strongly disagree
Disagree
Agree
Strongly agree
Demographic Questions
What's your role?
What's your role?
Director
VP
Manager
Engineer
C-Level
What's your team or discipline?
What's your team or discipline?
Development
Security
QA
Operations
SRE
Other
What's your industry?
What's your industry?
Education
Energy
Technology
Financial Services
Government
Healthcare
Industrial & Manufacturing
Media & Entertainment
Non-Profit
E-Commerce
Telecommunications
Other
What's your company size?
What's your company size?
0-100
100-499
500-999
1,000-4,999
5,000+
Done
Powered by
QuestionPro
Report Abuse
Create Your First Online Survey
Create a Survey
Loading...
close
drag_indicator
close
Yes
Cancel
Continue
Answer Question
Continue Without Answering
Keep Data
Discard
close
drag_indicator
Custom Title
highlight_off