<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Experiences with Continuous Deployment and Software Security in Google, Net ix, Facebook and others</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Laurie Williams</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>North Carolina State University</institution>
          ,
          <addr-line>Raleigh, North Carolina</addr-line>
          ,
          <country country="US">United States</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Continuous deployment is the software engineering practice of deploying many small incremental software updates into production, leading to a continuous stream of 10s, 100s, or even 1,000s of deployments per day. High-pro le Internet rms such as Amazon, Etsy, Facebook, Flickr, Google, and Net ix have embraced continuous deployment. However, the practice has not been covered in textbooks and no scienti c publication has presented an analysis of continuous deployment. This talk will relate experiences from the Continuous Deployment Summit, which has been run annually from 2015 to 2017. We will present a security integration checklist focusing on Communication, Culture and Technology, where we conclude that the summit participants get a green light for Technology, amber for Culture, and a red light for Communication.</p>
      </abstract>
      <kwd-group>
        <kwd>security</kwd>
        <kwd>continuous deployment</kwd>
        <kwd>DevOps</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>Acknowledgements
We thank the summit participants for their contribution. The work in this paper
was funded under National Science Foundation grant number 4900-1318428.</p>
      <p>Copyright c 2017 by the paper's authors. Copying permitted for private and academic
purposes.</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>