Yes, Policies Can Speed Development

22
The Component Lifecycle Management Company Yes, Policies Can Speed Development Go Fast. Be Secure. The Webinar will start at 12 PM EDT Tweet your thoughts: #sonatype

description

Last year alone, there were 7.2 BILLION component requests from more than 71 thousand organization and millions of developers around the world. Policies are like 4 letter words to developers – but the policy is not the problem; the implementation is.

Transcript of Yes, Policies Can Speed Development

Page 1: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Yes, Policies Can Speed

Development

Go Fast. Be Secure.

The Webinar will start at 12 PM EDT

Tweet your thoughts: #sonatype

Page 2: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

90%AssembledWritten

Software Evolution

Page 3: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Component Usage Has Exploded

Page 4: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

The Need for Repository Management

Why Use a Repository?

Reduce Build Times by proxying cloud repositories and caching components locally.

Improve Collaboration by providing a central location to store, manage, and share common components used across developers and teams.

Enhance Control by providing a mechanism to observe, manager, and govern component usage.

 

#sonatype

Page 5: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Foundation for Agile, Component-Based Development

#sonatype

Page 6: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Nexus Pro

Go Beyond Basic Repository Management

Know Your Components with Repository Health Check.

Gain Control with automated controls for component management.

Ensure Security with access controls and secure connectivity to the Central Repository.

Scale with Ease with smart proxy to ensure your repos are always available and your teams are in sync.

Manage All Your Components with support for .NET / Nuget repositories.

 

#sonatype

Page 7: Yes, Policies Can Speed Development

State of Open Source Governance

Page 8: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Page 9: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Page 10: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Page 11: Yes, Policies Can Speed Development

The Problem With Policies:Why Developers think Policy is a “4 Letter Word”

Page 12: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

• They are manual• They are static• They are inflexible• They are document-centric• They are generic• They are approval-laden• The implementation is reactive

The Problem with Today’s Policy Approach

“All of our developers are killing us because of the work that comes out of using a static scan – it isn't even work prisoners should be made to do” – Senior IT Executive

Page 13: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

• Component volume, diversity, complexity & release cadence• Large number of applications• Varying risk posture of organizations & applications• Agile-based development or fast waterfall delivery cycles• Security, Legal/Compliance, Architecture, Dev, IT Ops silos

Ineffective Policies are Exacerbated by Today’s Development Approach

40,000 Projects200MM Classes

400K Components

Typical EnterpriseConsumes 100s of

Components Monthly

Typical Component is Updated 4X

per Year

One component may rely on 100s

of others

Page 14: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

The End Result of Ineffective Policies

OR

They slowdevelopment

Business needs arenot met – fingerpointing ensues

Developers follow them &

use sub-optimal components

Risk is increased since outdated “approved”

components are used

Developers bypass them

Organizations put at risk since components

are not properly governed

OR

Page 15: Yes, Policies Can Speed Development

One Potential Approach:Automating the Approval Workflow

Page 16: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Automated Approval Workflow Doesn’t Work

Linear

Reactive

Belated

Unenforceable

Static

Page 17: Yes, Policies Can Speed Development

A Better Approach:Automating Policies

Page 18: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Extends Trust into Production

Applications

Provides up-front guidance to developers

#sonatype

Integrates guidance & enforcement directly in Dev

Tools

Automated Policies Keep Pace With Today’s Development Approach

• Automated policies free humans to focus on higher value tasks (policy definition and exception management)

• Accommodates risk profiles for different organization / application requirements

• Policies drive proactive notification and action for newly discovered vulnerabilities (continuous trust for production apps)

Page 19: Yes, Policies Can Speed Development

Product Demo

Page 20: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Only Sonatype CLM is designed for how applications are constructed

today.

Only Sonatype provides automated policies that guide development and

production effort for the entire software lifecycle.

Page 21: Yes, Policies Can Speed Development

The Component Lifecycle Management Company

Sonatype Product Family

Nexus OSS

Sonatype CLM Component Lifecycle Management• Centrally define governance policies• Enforce throughout the lifecycle• Integrate with existing developer tools• Build security in from the start• Continuous trust for production apps

Sonatype Nexus Repository Management• Improve collaboration• Controlled release process

Industry standard open source repository manager

Nexus Pro

Enterprise features, enterprise support

Nexus Pro CLM Edition

Component governance in the repo

Sonatype CLM

Nexus OSS Repository• Speed Builds

#sonatype

Page 22: Yes, Policies Can Speed Development

The Component Lifecycle Management Company#sonatype

Download a Free Trial – Updated Trial Guide and New Ant & Gradle Samples http://www.sonatype.com/nexus/free-trial

Join Nexus Live – Nexus and Chef as Part of the DevOps Pipeline http://www.sonatype.com/news/november-nexus-live November 21st

Read the Brief – Enhanced Repository Management: Automated Policy Governance for Agile Development Efforts http://www.sonatype.com/nexusproclm

Resources to Learn More

Where to go to learn more?