Application Security

8/17/2017
10:00 AM
50%
50%

70% of DevOps Pros Say They Didn't Get Proper Security Training in College

Veracode survey shows majority of DevOps pros mostly learn on the job about security.

Demand for DevOps is rapidly rising throughout corporate America and beyond, but the vast majority of programmers in this field feel their college education failed to provide them with sufficient security training, leaving them to largely learn their most relevant skills on the job.

According to Veracode's 2017 DevSecOps Global Skills Survey, which queried 400 DevOps professionals worldwide, 70% say their college training did not prepare them to be successful in DevSecOps. And given the inadequacy of the security training they received, 65% learned their most relevant skills while on the job, they say.

Additionally, some 80% of survey respondents with a bachelor's or master's degree say they lacked cybersecurity skills prior to entering the workforce.  

"Anecdotally, some of my employees told me they received some security training in college, but it was more like it was an afterthought. There might be a lecture on security here or there, but it was not part of every assignment," says Maria Loughlin, senior vice president of engineering at Veracode. "I think they should make security part of every assignment."

A whopping 85% of survey respondents say they are either somewhat prepared or not at all prepared to securely deliver software at the speed that is usually performed for DevOps, according to the report.

Learn from the industry’s most knowledgeable CISOs and IT security experts in a setting that is conducive to interaction and conversation. Click for more info and to register.

Related Content:

Dawn Kawamoto is an Associate Editor for Dark Reading, where she covers cybersecurity news and trends. She is an award-winning journalist who has written and edited technology, management, leadership, career, finance, and innovation stories for such publications as CNET's ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Connoryk
50%
50%
Connoryk,
User Rank: Apprentice
8/25/2017 | 4:59:05 PM
Re: The flipside
Universerity of Denver, Colorado (School of Business) launched a cyber risk management course three years ago. The course is part of the Risk Management and Insurance program and covers the dark side of the digital era, including risk management techniques applicable as part of entperise wide risk management/cyber risk management frameworks. Not suprisingly, the curriculum is updated every year. Teaching cyber risk management is both a dynamic and challenging effort given the inability to rely on static information (textbooks, models, etc.). Nevertheless, the class is in high demand and the graduates report the class assists in their resume'positioning and post graduate job success.

 
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
8/23/2017 | 8:51:34 PM
Training
This is an issue that has started to get more attention, particularly with business, nonprofit, and public-sector partnerships through organizations like MIT's IC(3). Business and government want to see more cybersecurity coursework offered in colleges because they're currently in the position of having to compete for the talent that's out there and/or invest resources in training people themselves.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/18/2017 | 9:12:05 AM
Re: The flipside
This is is something a new career field - not as long as computers in general (anybody remember what a Novell CNE was!!)  I would wager that most security professionals just fell INTO the career from some other field in the computer support industry.  Our job path led us there.
WCLoehr
100%
0%
WCLoehr,
User Rank: Strategist
8/17/2017 | 12:10:33 PM
The flipside
What would be interesting to know some more about is for the small minority that did get security training in college. How was it structured? What it dedicated courses or was the security education woven into other classes? 
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12697
PUBLISHED: 2018-06-23
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
CVE-2018-12698
PUBLISHED: 2018-06-23
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
CVE-2018-12699
PUBLISHED: 2018-06-23
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
CVE-2018-12700
PUBLISHED: 2018-06-23
A Stack Exhaustion issue was discovered in debug_write_type in debug.c in GNU Binutils 2.30 because of DEBUG_KIND_INDIRECT infinite recursion.
CVE-2018-11560
PUBLISHED: 2018-06-23
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.