
This episode explores the challenges of accountability and authority in DevSecOps, focusing on governance gaps and the role of Security Champions.
DevSecOps promises shared security responsibility, but what happens when accountability shifts without decision authority? In this episode of The ITSM Practice Podcast, Luigi Ferri explores governance gaps, risk ownership, Security Champions, burnout, and structural ambiguity in DevSecOps. A sharp reflection for CISOs, AppSec leaders, and ITSM professionals navigating security governance and enterprise risk management. In this episode, we answer to: Who is explicitly allowed to accept risk in a DevSecOps operating model? What happens when developers receive security accountability without authority? Are Security Champions strengthening governance, or masking leadership gaps? Resources Mentioned in this Episode: Blackduck website, article "DevSecOps: The good, the bad, and the ugly", link https://www.blackduck.com/blog/devsecops-challenges-benefits.html Jit website, article "6 DevSecOps Best Practices that Enable Developers to Deliver Secure Code", link https://www.jit.io/resources/devsecops/a-practical-guide-to-devsecops-making-it-work-for-developers Decipher Bureau website, article "DevSecOps Professionals: Avoiding ‘The Great Burnout’", link…
Explore listener stats, chart rankings, contacts and more on the The ITSM Practice: Elevating ITSM and IT Security Knowledge podcast page.