<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SEI Blog | Continuous Deployment of Capability</title><link>http://www.sei.cmu.edu/feeds/topic/</link><description>Updates on changes and additions to the                         SEI Blog for posts matching Continuous Deployment of Capability</description><atom:link href="http://www.sei.cmu.edu/blog/feeds/topic/continuous-deployment-capability/rss/" rel="self"/><language>en-us</language><lastBuildDate>Mon, 14 Jul 2025 00:00:00 -0400</lastBuildDate><item><title>A Practitioner-Focused DevSecOps Assessment Approach</title><link>https://www.sei.cmu.edu/blog/a-practitioner-focused-devsecops-assessment-approach/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Regular DevSecOps assessments are necessary to track progress, adapt to evolving needs, and ensure you are consistently delivering value to your end users with speed, security, and efficiency.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Reffett, Timothy A. Chick</dc:creator><pubDate>Mon, 14 Jul 2025 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/a-practitioner-focused-devsecops-assessment-approach/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>A 5-Stage Process for Automated Testing and Delivery of Complex Software Systems</title><link>https://www.sei.cmu.edu/blog/a-5-stage-process-for-automated-testing-and-delivery-of-complex-software-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Managing and maintaining deployments of complex software present engineers with a multitude of challenges including security vulnerabilities.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Caden Milne, Lyndsi Hughes</dc:creator><pubDate>Wed, 21 May 2025 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/a-5-stage-process-for-automated-testing-and-delivery-of-complex-software-systems/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>The DevSecOps Capability Maturity Model</title><link>https://www.sei.cmu.edu/blog/the-devsecops-capability-maturity-model/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Implementing DevSecOps can improve multiple aspects of the effectiveness of a software organization and the quality of the software for which it is responsible.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Timothy A. Chick, Brent Frye, Aaron Reffett</dc:creator><pubDate>Mon, 10 Mar 2025 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/the-devsecops-capability-maturity-model/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Acquisition Archetypes Seen in the Wild, DevSecOps Edition: Cross-Program Dependencies</title><link>https://www.sei.cmu.edu/blog/acquisition-archetypes-seen-in-the-wild-devsecops-edition-cross-program-dependencies/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Shared capabilities can help manage costs and complexities but can also result in cross-program dependencies. This post examines this phenomenon in a DevSecOps context.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Novak</dc:creator><pubDate>Tue, 03 Sep 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/acquisition-archetypes-seen-in-the-wild-devsecops-edition-cross-program-dependencies/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Acquisition Transformation</category></item><item><title>Cultivating Kubernetes on the Edge</title><link>https://www.sei.cmu.edu/blog/cultivating-kubernetes-on-the-edge/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Members of the SEI DevSecOps Innovation team were asked to explore an alternative to VMware’s vSphere Hypervisor in an edge compute environment. This post explores their prototype.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Earl, Jeffrey Hamed, Doug Reynolds, José Morales</dc:creator><pubDate>Mon, 08 Jul 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/cultivating-kubernetes-on-the-edge/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Polar: Improving DevSecOps Observability</title><link>https://www.sei.cmu.edu/blog/polar-improving-devsecops-observability/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post introduces Polar, a DevSecOps framework developed as a solution to the limitations of traditional batch data processing.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Morgan Farrah, Vaughn Coates, Patrick Earl</dc:creator><pubDate>Mon, 06 May 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/polar-improving-devsecops-observability/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Example Case: Using DevSecOps to Redefine Minimum Viable Product</title><link>https://www.sei.cmu.edu/blog/example-case-using-devsecops-to-redefine-minimum-viable-product/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This SEI blog post, authored by SEI interns, describes their work on a microservices-based software application, an accompanying DevSecOps pipeline, and an expansion of the concept of minimum viable product to minimum viable process.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Yankel</dc:creator><pubDate>Mon, 11 Mar 2024 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/example-case-using-devsecops-to-redefine-minimum-viable-product/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Acquisition Archetypes Seen in the Wild, DevSecOps Edition: Clinging to the Old Ways</title><link>https://www.sei.cmu.edu/blog/acquisition-archetypes-seen-in-the-wild-devsecops-edition-clinging-to-the-old-ways/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This SEI blog post draws on SEI experiences conducting independent technical assessments to examine problems common to disparate acquisition programs. It also provides recommendations for recovering from these problems and preventing them from recurring.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">William Novak</dc:creator><pubDate>Mon, 18 Dec 2023 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/acquisition-archetypes-seen-in-the-wild-devsecops-edition-clinging-to-the-old-ways/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Acquisition Transformation</category></item><item><title>Extending Agile and DevSecOps to Improve Efforts Tangential to Software Product Development</title><link>https://www.sei.cmu.edu/blog/extending-agile-and-devsecops-to-improve-efforts-tangential-to-software-product-development/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The modern software engineering practices of Agile and DevSecOps have revolutionized the practice of software engineering. This blog post explores use of these practices in capability delivery and business mission.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David Sweeney, Lyndsi Hughes</dc:creator><pubDate>Mon, 07 Aug 2023 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/extending-agile-and-devsecops-to-improve-efforts-tangential-to-software-product-development/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>5 Challenges to Implementing DevSecOps and How to Overcome Them</title><link>https://www.sei.cmu.edu/blog/5-challenges-to-implementing-devsecops-and-how-to-overcome-them/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>The shift from project- to program-level thinking raises numerous challenges to DevSecOps implementation. This SEI Blog post articulates these challenges and ways to overcome them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Yankel, Hasan Yasar</dc:creator><pubDate>Mon, 12 Jun 2023 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/5-challenges-to-implementing-devsecops-and-how-to-overcome-them/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Actionable Data from the DevSecOps Pipeline</title><link>https://www.sei.cmu.edu/blog/actionable-data-from-the-devsecops-pipeline/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>In this blog post, we explore decisions that program managers make and information they need to confidently make decisions with data from DevSecOps pipelines.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bill Nichols, Julie Cohen</dc:creator><pubDate>Mon, 01 May 2023 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/actionable-data-from-the-devsecops-pipeline/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Agile Adoption in Government</category><category>Continuous Deployment of Capability</category><category>Measurement and Analysis</category><category>Agile</category></item><item><title>Writing Ansible Roles with Confidence</title><link>https://www.sei.cmu.edu/blog/writing-ansible-roles-with-confidence/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>How do you write Ansible roles in a way where you can be confident your role works as intended? This post provides guidance on how to best begin developing Ansible roles.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matthew Heckathorn</dc:creator><pubDate>Mon, 07 Nov 2022 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/writing-ansible-roles-with-confidence/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>A Technical DevSecOps Adoption Framework</title><link>https://www.sei.cmu.edu/blog/a-technical-devsecops-adoption-framework/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post describes our new DevSecOps adoption framework that guides the planning and implementation of a roadmap to functional CI/CD pipeline capabilities.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Vanessa Jackson, Lyndsi Hughes</dc:creator><pubDate>Mon, 24 Oct 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/a-technical-devsecops-adoption-framework/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Agile</category><category>Devops</category><category>Continuous Deployment of Capability</category></item><item><title>Combining Security and Velocity in a Continuous-Integration Pipeline for Large Teams</title><link>https://www.sei.cmu.edu/blog/combining-security-and-velocity-in-a-continuous-integration-pipeline-for-large-teams/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post explores how one team managed—and eventually resolved—the two competing forces of developer velocity and cybersecurity enforcement by implementing DevSecOps practices.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alejandro Gomez</dc:creator><pubDate>Mon, 11 Jul 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/combining-security-and-velocity-in-a-continuous-integration-pipeline-for-large-teams/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Modeling DevSecOps to Protect the Pipeline</title><link>https://www.sei.cmu.edu/blog/modeling-devsecops-to-protect-the-pipeline/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This blog post presents a DevSecOps Platform-Independent Model that uses model based system engineering constructs to formalize the practices of DevSecOps pipelines and organize guidance.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Timothy A. Chick, Joseph Yankel</dc:creator><pubDate>Mon, 13 Jun 2022 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/modeling-devsecops-to-protect-the-pipeline/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>From Model-Based Systems and Software Engineering to ModDevOps</title><link>https://www.sei.cmu.edu/blog/from-model-based-systems-and-software-engineering-to-moddevops/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Introduction to ModDevOps, an extension of DevSecOps that embraces model-based systems engineering (MBSE) technology</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jerome Hugues, Joseph Yankel</dc:creator><pubDate>Mon, 22 Nov 2021 00:00:00 -0500</pubDate><guid>https://www.sei.cmu.edu/blog/from-model-based-systems-and-software-engineering-to-moddevops/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Devops</category><category>Architecture Analysis and Design Language (AADL)</category><category>Model-Based Systems Engineering</category><category>Systems Engineering</category><category>Digital Engineering</category></item><item><title>The Role of DevSecOps in Continuous Authority to Operate</title><link>https://www.sei.cmu.edu/blog/the-role-of-devsecops-in-continuous-authority-to-operate/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>DevSecOps favors rapid development and deployment. Such rapid development and deployment must be balanced against the need to ensure software systems are secure with minimal risk, thus enabling them to receive timely ATOs and continuous ATOs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tom Scanlon</dc:creator><pubDate>Mon, 04 Oct 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/the-role-of-devsecops-in-continuous-authority-to-operate/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Taking DevSecOps to the Next Level with Value Stream Mapping</title><link>https://www.sei.cmu.edu/blog/taking-devsecops-to-the-next-level-with-value-stream-mapping/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>This post explores the relationship between DevSecOps and value stream mapping, both of which are rooted in the Lean approach to systems and workflow. It also provides guidance on preparing to conduct value stream mapping within a software-intensive product development environment.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nanette Brown</dc:creator><pubDate>Mon, 24 May 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/taking-devsecops-to-the-next-level-with-value-stream-mapping/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid></item><item><title>Aligning DevSecOps and Machine Learning</title><link>https://www.sei.cmu.edu/blog/aligning-devsecops-and-machine-learning/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>Luiz Antunes explores the machine learning (ML) and DevSecOps domains and proposes ways to use them in collaboration for increased performance.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Luiz Antunes</dc:creator><pubDate>Mon, 03 May 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/aligning-devsecops-and-machine-learning/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Machine Learning</category></item><item><title>The Current State of DevSecOps Metrics</title><link>https://www.sei.cmu.edu/blog/the-current-state-of-devsecops-metrics/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</link><description>DevSecOps practices yield useful, valuable information about software performance that is likely to lead to innovations in software engineering metrics.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bill Nichols</dc:creator><pubDate>Mon, 29 Mar 2021 00:00:00 -0400</pubDate><guid>https://www.sei.cmu.edu/blog/the-current-state-of-devsecops-metrics/?utm_source=blog&amp;utm_medium=rss&amp;utm_campaign=my_site_updates</guid><category>Measurement and Analysis</category></item></channel></rss>