Welcome!

Containers Expo Blog Authors: Liz McMillan, Yeshim Deniz, Pat Romanski, Elizabeth White, Ravi Rajamiyer

Related Topics: @DevOpsSummit, Linux Containers, Containers Expo Blog

@DevOpsSummit: Blog Feed Post

Three Steps to Painless Compliance | @DevOpsSummit #DevOps #BusinessIntelligence

Documenting processes and changes, ensuring segregation of duties, and so on is tedious and time-consuming

Three Steps to Painless Compliance
By Patrick Bishop

Ask any IT person from the financial sector about SOX requirements and they’ll probably use some colorful language about how much time and money it sucks away. According to the 2016 Sarbanes-Oxley compliance survey by global consultant Protiviti, the average annual internal cost of SOX Compliance Costs is over $1.2 million dollars, with 27% of these firms spending 2 million or more.

Release orchestration eases compliance requirements

Having worked with lots of financial institutions in my time, I’ve seen my fair share of IT people feeling overburdened by the demands of keeping up with regulations. Documenting processes and changes, ensuring segregation of duties, and so on is tedious and time-consuming. To be effective and lighten the compliance load you need automation, yes, but you also need intelligence about what’s happening across your pipeline. Release orchestration gives you both, which means you stay sane and keep the auditors happy.

But before you cross over that rainbow, you need to take some steps to get your house in order.

Step 1. Clean Up Your Software Delivery Pipeline
You can’t begin to automate compliance documentation if you’re pipeline is messy and inefficient. To clean it up, you first need to first find any bottlenecks that are standing in the way of streamlining the pipeline—the whole pipeline. Release orchestration gives you visibility from end to end, all the way from design through to production. Once you figure out exactly where your problems are, you can start to optimize your processes.

Step 2. Ditch the Manual Workflows
Creating deployment workflows
is like using static maps. If you come across road construction for example, you need to look at your map, recalculate your route, and commit it to memory to get to where you’re going. Doing so will probably delay your ETA too. Similarly, if you change any part of your deployment process, you must manually reconfigure steps and any dependencies affected by the change. This can make it time consuming for an enterprise, with its hundreds of applications, to accurate records for compliance.

In contrast, off the shelf release orchestrators are more like a GPS, which track your changes and automatically recalculate the route. All the underlying steps are still there, they’re just handled by the software. If you change some part of the release process, a release orchestrator automatically adjusts every step in your workflow, including all dependencies, approvals, and so on, ensuring up to date and accurate records for compliance.

Step 3. Automate Your Documentation
Cleaning up the pipeline and orchestrating your release process lays the groundwork for automating documentation. Enterprise-grade release orchestration tools capture a full audit trail automatically, which means you can easily show how you’ve supported compliance requirements, track the evolution of releases and demonstrate any deviations from your original plan. Release orchestrators also allow you to standardize release processes and enforce company compliance processes. This allows auditors to certify the release process itself, then simply confirm that all steps have been followed. In effect, the auditor becomes part of the process rather than an afterthought.

By cleaning up your pipeline and automating your workflows and documentation, you and your auditors can enjoy happier, pain-free days ahead.

The post 3 Steps to Painless Compliance appeared first on XebiaLabs.

Read the original blog entry...

More Stories By XebiaLabs Blog

XebiaLabs is the technology leader for automation software for DevOps and Continuous Delivery. It focuses on helping companies accelerate the delivery of new software in the most efficient manner. Its products are simple to use, quick to implement, and provide robust enterprise technology.

IoT & Smart Cities Stories
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing was coined and where technology buyers and vendors meet to experience and discuss the big picture of Digital Transformation and all of the strategies, tactics, and tools they need to realize their goals. Sponsors of DXWorldEXPO | CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities.
Disruption, Innovation, Artificial Intelligence and Machine Learning, Leadership and Management hear these words all day every day... lofty goals but how do we make it real? Add to that, that simply put, people don't like change. But what if we could implement and utilize these enterprise tools in a fast and "Non-Disruptive" way, enabling us to glean insights about our business, identify and reduce exposure, risk and liability, and secure business continuity?
The deluge of IoT sensor data collected from connected devices and the powerful AI required to make that data actionable are giving rise to a hybrid ecosystem in which cloud, on-prem and edge processes become interweaved. Attendees will learn how emerging composable infrastructure solutions deliver the adaptive architecture needed to manage this new data reality. Machine learning algorithms can better anticipate data storms and automate resources to support surges, including fully scalable GPU-c...
DXWorldEXPO LLC announced today that Telecom Reseller has been named "Media Sponsor" of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. Telecom Reseller reports on Unified Communications, UCaaS, BPaaS for enterprise and SMBs. They report extensively on both customer premises based solutions such as IP-PBX as well as cloud based and hosted platforms.
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As automation and artificial intelligence (AI) power solution development and delivery, many businesses need to build backend cloud capabilities. Well-poised organizations, marketing smart devices with AI and BlockChain capabilities prepare to refine compliance and regulatory capabilities in 2018. Volumes of health, financial, technical and privacy data, along with tightening compliance requirements by...
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22nd international CloudEXPO | first international DXWorldEXPO and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time t...
DXWorldEXPO LLC announced today that "IoT Now" was named media sponsor of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. IoT Now explores the evolving opportunities and challenges facing CSPs, and it passes on some lessons learned from those who have taken the first steps in next-gen IoT services.
SYS-CON Events announced today that Silicon India has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Published in Silicon Valley, Silicon India magazine is the premiere platform for CIOs to discuss their innovative enterprise solutions and allows IT vendors to learn about new solutions that can help grow their business.