In IT is is especially easy to get caught up in the How of just about any facet of our work. It all seems so mechanical, just tell me what tools to use and how you want it architected and we can go bang out a solution, it's what we do. DevOps and DevSecOps have been no different as we tend to focus on the CI/CD pipelines and which tools to integrate into it. Hopefully this article will ground us in what DevOps is when we pull back the curtain and why that matters.
To me, DevOps is fundamentally about creating a culture of learning. This is in stark contrast to the prescriptive and heavily planned nature of the past. Instead of trying to gather all of the requirements and understand all of the use cases, and then telling people what to do, we learn as we go. Any quick search on DevOps and culture should take you to the acronym, CALMS. Originally coined CAMS by John Willis and Damon Edwards after the first US based DevOpsDays event held in Mountainview California in 2010, it stood for Culture, Automation, Measurement, and Sharing. Jez Humble later added the L, for Lean, making it CALMS.The problem with an acronym is it comes off as a list of things but I want to connect them all. For me, it always starts with A Culture of… A culture of automation, a culture of lean, a culture of measurement and a culture of sharing. Where ‘culture’ means, the set of shared attitudes, values, goals, and practices that characterizes an institution or organization. In simple terms, expected norms, all of which support a culture of learning and going faster.
DevSecOps is still a culture of learning but we are explicitly inviting Security to the game of delivering customer value faster. Security can no longer keep to themselves and be seen as a barrier to delivery, instead we want them to embrace automation, lean, measurement, and sharing, like the rest of us, and learn to become an accelerator.While being resilient to change is helpful for when we need to react to disruptions in our industry there is another benefit. William Pollard, a principal founder of the Oakridge institute of Nuclear Studies has said “Learning and innovation go hand in hand. The arrogance of success is to think that what you did yesterday will be sufficient for tomorrow.” Being innovative can mean your organization is the one doing the disrupting and forcing the competition to react, testing their agility.
If being resilient or innovative isn’t compelling enough, let me leave with two Peter Senge quotes. Peter Senge is the author of the Fifth Discipline and senior lecturer at the MIT Sloan School of Management and was named "Strategist of the Century" by Journal of Business Strategy,
“A learning organization is a group of people who are continually enhancing their capabilities to create what they want to create”
“The only sustainable competitive advantage is an organization's ability to learn faster than the competition.”