# 6mile/DevSecOps-Playbook

This is a step-by-step guide to implementing a DevSecOps program for any size organization

Repository: https://github.com/6mile/DevSecOps-Playbook
Canonical: https://ross.abutalabs.com/products/devsecops-playbook
License: GPL-3.0
License Family: copyleft
Topics: devsecops, security, playbook
Last push: 2024-12-21T08:29:05+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1760, "days_push": 620, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2051, forks 344 (observed 2026-08-28T04:06:09.163102+00:00)

## What it is
A step-by-step playbook for implementing DevSecOps practices in organizations of any size, organized into five lifecycle domains with 60 actionable tasks. It translates standards like OWASP ASVS and MVSP into concrete steps for introducing security controls, measuring effectiveness, and demonstrating business value.

## Use cases
- implement devsecops in my company
- introduce security controls into ci/cd pipeline
- build a secure software development lifecycle
- measure application security maturity
- get started with appsec as a small team
- align security practices with compliance frameworks
- convince leadership to invest in security

## When to choose
- you need prescriptive, actionable steps to start or mature a DevSecOps program
- you want guidance mapped to recognized standards like ASVS, MVSP, and DSOMM
- you need to justify security spending to business leaders

## When to avoid
- you need a runnable tool or automation rather than a written guide
- you want deep technical detail on individual security tools
- you need organization-specific or regulated-industry security policies

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, developer-tools, documentation, ci-cd, dependency-audit
- domain: security, developer-tools, documentation
- platform: cross-platform
- tags: devsecops, appsec, playbook, security-controls, shift-left, compliance, owasp, guide, devops

## Member repositories
- 6mile/DevSecOps-Playbook (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:09.163102+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:57:27.127216+00:00, confidence not recorded.
  - readme: https://github.com/6mile/DevSecOps-Playbook (fetched 2026-08-28T04:06:09.163102+00:00, sha 32de071be446)
- Data as of 2026-08-30T08:39:29.467469+00:00.
