How to Keep DevSecOps Teams Motivated
Agile requires longstanding culture shifts and decisions rooted in data.

Agile and DevSecOps leaders in the federal government prioritize cultural overhaul and data-driven decision-making to succeed.
Mandy Moore, deputy director for the Office of Application Engineering and Development at the U.S. Patent and Trademark Office (USPTO), said federal agencies shouldnโt be worried about implementing โthe next big thing in IT.โ
โThe main goal here is to form that strong business and product team bond, and that team is responsible for the full backlog of work relating to these projects,โ she said during GovernmentCIO Media & Researchโs Disruptive DevSecOps event this week.
Moore said focusing on cultural transformation at USPTO helped break down silos of communication and data between the development, operations and security teams.
โI think itโs really about focusing on culture change and instilling that belief that it can be done,โ she said. โMaking an effort and commitment to showing incremental improvements and taking small steps and smaller teams and showing that even without impressive automation, you can achieve autonomous teams doing DevSecOps. Sometimes itโs about getting the collective to believe the change can happen.โ
Florence Kasule, director of procurement at the U.S. Digital Service (USDS), suggested federal agencies use the acronym CALMS to guide the shift to Agile and DevSecOps.
โCALMS stands for culture, automation, lean, measure and share,โ Kasule said during the event. โMaking sure your teams are as collaborative as possible and user-centered โฆ trying to get as scrappy as you can and making sure your teams are working closely together, figuring out the problems on both sides. Measure being making data-driven decisions, so there arenโt assumptions about why the development or security or operations teams are doing something. What is the data, what is it showing you? And then sharing information as much as possible in order to meet shared goals.โ
Kasule also recommended constant communication and open feedback loops to ensure problems get addressed quickly. Like Moore, she stressed breaking down silos between teams in order for a DevSecOps strategy to succeed.
โBlended teams are critical to making this work,โ Kasule said. โYou canโt work separately during a vacuum in this kind of model.โ
Defense Information Systems Agencyโs Services Development Director Brian Hermann and Lindsay Young, an 18F team member for Digital Service Delivery at the GSA, said federal agencies should keep the end goal of their production processes top of mind in order to create a successful Agile culture.
โAs far as implementation, I think itโs really important to keep your focus on those big goals,โ Young said. โSometimes you can add some Agile-sounding meetings to your waterfall scheduling, and that doesnโt give you any benefit. It will give you more meetings. When youโre thinking about Agile, ask yourself, what have we learned from building and testing so far? You should be learning all of the time.โ
Helping teams connect the dots between their work and the value they provide can help with this.
โWhen our teams are disengaged and not feeling that sense of mission and accomplishment โ we canโt do Agile for Agileโs sake,โ Hermann said.
Besides accelerating software production cycles and helping make them more secure, Hermann is optimistic about the ways DevSecOps can fortify IT security at the Defense Department.
โIโm especially excited about the synergy between DevSecOps and cloud hosting,โ Hermann said. โIt enables us to instantly deliver that capability. Figure out if somethingโs wrong, roll back if necessary, but keep moving forward. If we host things at the enterprise using cloud, we have a known capability, a known constantly updated cybersecurity status. That value alone provides some interest for the rest of the leadership in DOD because security is a huge issue for us.โ
Understanding what the value is in your DevSecOps approach and encouraging information-sharing so as to make better data-driven decisions are overall keys to successful implementation.
โThe No. 1 thing is value,โ Young said. โYou want your technical decisions to be driven by the value seen by the people using the products. It also might mean you want to try something that isnโt as shiny.โ
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
New SHARE IT Act Mandates Federal Code Sharing to Cut Software Costs
Agencies are under pressure to make code public, with CMS leading efforts to drive open-source collaboration and governmentwide savings.
5m read -
VAโs Platform One Offers Sandbox to Software Developers
Platform Oneโs sandbox environment allows developers to create applications in protected conditions, keeping veteran data safe and secure.
14m watch -
Modernizing IT Systems for AI Adoption
USPS, NIH and Lumen discuss how modernization, data strategies and security are shaping AIโs future role in government.
32m watch -
DOD Advances DevSecOps, ATO Reform to Speed Mission-Ready Software
Defense leaders adopt DevSecOps and automation to speed software delivery, streamline ATO and boost cyber agility.
3m read