> For the complete documentation index, see [llms.txt](https://asafahmadov.gitbook.io/devsecops/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://asafahmadov.gitbook.io/devsecops/1.-devsecops-the-big-picture/understanding-devsecops-concepts/devsecops-manifesto.md).

# DevSecOps Manifesto

#### ⭕ Manifesto for Agile Software Development

We uncover better ways of developing software by doing it and helping others do it. Through this work, we have come to value:&#x20;

&#x20;    ▪ <mark style="color:green;">**Individuals and interactions**</mark> over processes and tools&#x20;

&#x20;    ▪ <mark style="color:green;">**Working software**</mark> over comprehensive documentation&#x20;

&#x20;    ▪ <mark style="color:green;">**Customer collaboration**</mark> over contract negotiation&#x20;

&#x20;    ▪ <mark style="color:green;">**Responding to change**</mark> over following a plan

While there is value in the items on the right, we value the items on the left more.

#### ⭕ Manifesto for DevSecOps

Through Security as Code, we have and will learn that there is simply a better way for security practitioners like us to operate and contribute value with less friction. We know we must adapt our ways quickly and foster innovation to ensure data security and privacy issues are not left behind because we were too slow to change.

By developing security as code, we will strive to create awesome products and services, provide insights directly to developers, and generally favor iteration over trying to always come up with the best answer before a deployment. We will operate like developers to make security and compliance available to be consumed as services. We will unlock and unblock new paths to help others see their ideas become a reality.

We won't simply rely on scanners and reports to make code better. We will attack products and services like an outsider to help you defend what you've created. We will learn the loopholes, look for weaknesses, and we will work with you to provide remediation actions instead of long lists of problems for you to solve on your own.

We will not wait for our organizations to fall victim to mistakes and attackers. We will not settle for finding what is already known; instead, we will look for anomalies yet to be detected. We will strive to be a better partner by valuing what you value:

&#x20;    ▪ <mark style="color:green;">**Leaning in (being part of the solution)**</mark> over Always Saying “No”\
&#x20;    ▪ <mark style="color:green;">**Data & Security Science**</mark> over Fear, Uncertainty, and Doubt\
&#x20;    ▪ <mark style="color:green;">**Open Contribution & Collaboration**</mark> over Security-Only Requirements\
&#x20;    ▪ <mark style="color:green;">**Consumable Security Services with APIs**</mark> over Mandated Security Controls & Paperwork\
&#x20;    ▪ <mark style="color:green;">**Business-Driven Security Scores**</mark> over Rubber Stamp Security\
&#x20;    ▪ <mark style="color:green;">**Red & Blue Team Exploit Testing**</mark> over Relying on Scans & Theoretical Vulnerabilities\
&#x20;    ▪ <mark style="color:green;">**24x7 Proactive Security Monitoring**</mark> over Reacting after being Informed of an Incident\
&#x20;    ▪ <mark style="color:green;">**Shared Threat Intelligence**</mark> over Keeping Info to Ourselves\
&#x20;    ▪ <mark style="color:green;">**Compliance Operations**</mark> over Clipboards & Checklists
