{"title":"Improving Digital Forensic Readiness in DevOps Context: Lessons Learned from XYZ Company","authors":"F. Gunawan, S. Yazid","doi":"10.1109/iSemantic50169.2020.9234194","DOIUrl":null,"url":null,"abstract":"DevOps is a relatively new methodology and culture in software development to deliver software faster and with higher quality. DevOps changes how an organization works by flattening structures, increasing collaboration, and also promotes automation. However, it might pose serious security problems if outsourcing, intellectual property, and data protection are not put into consideration. XYZ Company is a typical small software company that is transforming to embrace DevOps. Digital forensic is a post-mortem mechanism to analyze incidents to help organizations mitigate and doing lawsuits. Digital forensic readiness (DFR) is assessed using Elyas et al [3] DFR framework. DFR improvement is part of the company’s effort to maintain the security level. The method we took and the issues we faced in this transformation are shared in this report.","PeriodicalId":345558,"journal":{"name":"2020 International Seminar on Application for Technology of Information and Communication (iSemantic)","volume":"43 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-09-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 International Seminar on Application for Technology of Information and Communication (iSemantic)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/iSemantic50169.2020.9234194","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2
Abstract
DevOps is a relatively new methodology and culture in software development to deliver software faster and with higher quality. DevOps changes how an organization works by flattening structures, increasing collaboration, and also promotes automation. However, it might pose serious security problems if outsourcing, intellectual property, and data protection are not put into consideration. XYZ Company is a typical small software company that is transforming to embrace DevOps. Digital forensic is a post-mortem mechanism to analyze incidents to help organizations mitigate and doing lawsuits. Digital forensic readiness (DFR) is assessed using Elyas et al [3] DFR framework. DFR improvement is part of the company’s effort to maintain the security level. The method we took and the issues we faced in this transformation are shared in this report.