Published: 16 February 2024
Summary
Automating security in software engineering is key to achieving both security and delivery outcomes. Software engineering leaders can use this benchmarking data to guide their decisions on automation tools and activities to automate, as well as work around barriers to automating security activities.
Included in Full Research
Overview
Key Findings
Organizations that automate more security activities can expect an estimated 15% improvement in their ability to meet targets on both security and delivery outcomes.
Many types of security automation are not yet widespread. Fewer than 50% of respondents to our survey were fully or mostly automating any of the 12 activities we asked about.
Application security testing (AST) andsigning and hashing are among the more commonly automated security activities. The least commonly automated activities are remediation based on testing output, software bills of materials (SBOMs) generation and threat modeling.
Organizations use a range of tools and technologies to automate
Clients can log in to view the entire
document.