ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
Respondent ID
End Date
Q1 - Does your organization assess the security of its CI/CD pipeline as an integrated entity as opposed to just the artifacts that the pipeline builds?
Q2a - Q2a - Application Development
Q2b - DevOps and/or Application Management
Q2c - IT Operations and/or Site Reliability Engineering
Q2d - Information Security
Q2e - Quality Assurance
Q2f - Don’t know
Q2g - We do not have a CI/CD pipeline
Q2h - Other (please specify)
Q3a - Static application security testing (SAST)
Q3b - Dynamic application security testing (DAST)
Q3c - Dependencies
Q3d - Containers
Q3e - Container images
Q3f - License compliance
Q3g - None of the above
Q4 - Should the percentage of software component dependencies that are out-of-date (i.e., a newer version has been released) be a performance metric for DevOps teams?
2
115037432844/14/2020NoApplication Development
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dependencies
Containers
Yes
3
115037468014/14/2020YesApplication Development
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Quality Assurance
Dependencies
Containers
Container images
License compliance
Yes
4
115038441544/14/2020Yes
DevOps and/or Application Management
Quality Assurance
the team on mars
Static application security testing (SAST)
Dependencies
Container images
Yes
5
115050047294/15/2020YesApplication Development
DevOps and/or Application Management
Dependencies
Containers
Don't know
6
115050945524/15/2020Yes
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Containers
Container images
Yes
7
115056209964/15/2020YesApplication Development
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Quality Assurance
License compliance
No
8
115057574904/15/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Dependencies
Containers
Container images
License compliance
Yes
9
115057907754/15/2020
Don’t know
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
License compliance
Don't know
10
115059465264/15/2020NoApplication Development
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dependencies
Container images
License compliance
Yes
11
115059635114/15/2020
Don’t know
Don’t know
None of the above
No
12
115059679404/15/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Dynamic application security testing (DAST)
Container images
Yes
13
115059719734/15/2020Yes
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Container images
Yes
14
115060264964/15/2020
Don’t know
0.9240506329
Information Security
Container images
Yes
15
115060276704/15/2020No
Quality Assurance
None of the above
Yes
16
115060398174/15/2020
Don’t know
Information Security
None of the above
No
17
115060442894/15/2020YesApplication Development
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Don't know
18
115060490744/15/2020
We do not have a CI/CD pipeline
Don’t know
License compliance
Yes
19
115060604244/15/2020No
DevOps and/or Application Management
Information Security
None of the above
No
20
115060645834/15/2020No
Don’t know
Containers
Yes
21
115061108284/15/2020No
Information Security
Container images
Yes
22
115061287694/15/2020Yes
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Containers
Container images
Yes
23
115061312954/15/2020Yes
DevOps and/or Application Management
DependenciesNo
24
115061987694/15/2020YesApplication Development
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Static application security testing (SAST)
Yes
25
115062570294/15/2020Yes
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Yes
26
115062816254/15/2020Yes
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Containers
Container images
License compliance
Yes
27
115062982894/15/2020Yes
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dependencies
Container images
License compliance
Yes
28
115064446374/15/2020YesApplication Development
Static application security testing (SAST)
Dependencies
License compliance
Yes
29
115064548754/15/2020No
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Dependencies
Containers
Container images
Yes
30
115065171544/15/2020No
Information Security
Static application security testing (SAST)
Yes
31
115066646304/15/2020NoApplication Development
Information Security
Static application security testing (SAST)
Yes
32
115071775044/15/2020
We do not have a CI/CD pipeline
We do not have a CI/CD pipeline
Dynamic application security testing (DAST)
Yes
33
115072075664/15/2020YesApplication Development
Information Security
Quality Assurance
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Container images
License compliance
No
34
115073833504/15/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Containers
Container images
Yes
35
115077044074/16/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
Yes
36
115077890604/16/2020Yes
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dependencies
Container images
License compliance
Yes
37
115078106544/16/2020
We do not have a CI/CD pipeline
We do not have a CI/CD pipeline
Static application security testing (SAST)
No
38
115079183154/16/2020YesApplication Development
IT Operations and/or Site Reliability Engineering
Information Security
None of the above
Yes
39
115080597064/16/2020YesApplication Development
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Containers
Container images
License compliance
Yes
40
115081064674/16/2020Yes
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Yes
41
115082113714/16/2020Yes
DevOps and/or Application Management
Static application security testing (SAST)
DependenciesNo
42
115082549164/16/2020
We do not have a CI/CD pipeline
Don’t know
Containers
Don't know
43
115082969254/16/2020
Don’t know
Application Development
Static application security testing (SAST)
Don't know
44
115084645504/16/2020YesApplication Development
DevOps and/or Application Management
Dependencies
Containers
Container images
Yes
45
115085621914/16/2020No
Delivery Platform Engineering
None of the above
Yes
46
115088173934/16/2020
Don’t know
DevOps and/or Application Management
Static application security testing (SAST)
DependenciesNo
47
115094395644/16/2020No
IT Operations and/or Site Reliability Engineering
Dynamic application security testing (DAST)
Yes
48
115100463064/16/2020No
Information Security
Container images
Yes
49
115104943574/16/2020YesApplication Development
DevOps and/or Application Management
Static application security testing (SAST)
DependenciesYes
50
115107279264/16/2020Yes
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
Yes
51
115129421414/17/2020Yes
Information Security
DependenciesNo
52
115132889164/17/2020YesApplication Development
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Container images
Yes
53
115135024144/17/2020No
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Yes
54
115158073594/18/2020No
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
License compliance
No
55
115195155934/20/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Dynamic application security testing (DAST)
Container images
Yes
56
115204189124/20/2020YesApplication Development
Information Security
Static application security testing (SAST)
Dependencies
Container images
License compliance
Yes
57
115207337684/20/2020Yes
Information Security
DependenciesYes
58
115241114554/21/2020YesApplication Development
DevOps and/or Application Management
None of the above
Yes
59
115247512954/21/2020NoApplication Development
Static application security testing (SAST)
Dependencies
Containers
Container images
License compliance
Yes
60
115322100344/23/2020No
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
Yes
61
115348865954/24/2020YesApplication Development
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
Yes
62
115349333434/24/2020Yes
IT Operations and/or Site Reliability Engineering
Dynamic application security testing (DAST)
Don't know
63
115352445284/24/2020NoApplication Development
IT Operations and/or Site Reliability Engineering
None of the above
Yes
64
115361416244/24/2020No
We do not have a CI/CD pipeline
None of the above
Yes
65
115366581954/24/2020No
DevOps and/or Application Management
Static application security testing (SAST)
Dynamic application security testing (DAST)
Yes
66
115371850444/25/2020Yes
Information Security
Containers
Container images
Yes
67
115395689514/26/2020YesApplication Development
DevOps and/or Application Management
Information Security
Quality Assurance
Static application security testing (SAST)
Dynamic application security testing (DAST)
Yes
68
115401241074/26/2020Yes
We don't have a scan-related tool.
None of the above
No
69
115417829504/27/2020No
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
License compliance
Yes
70
115488623004/29/2020No
We do not have a CI/CD pipeline
Dynamic application security testing (DAST)
Yes
71
115491411994/29/2020YesApplication Development
DevOps and/or Application Management
Static application security testing (SAST)
License compliance
Don't know
72
115559513384/30/2020NoApplication Development
DevOps and/or Application Management
Static application security testing (SAST)
DependenciesYes
73
115579370725/1/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Dependencies
Containers
Container images
License compliance
Yes
74
115579795265/1/2020YesApplication Development
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Containers
Container images
License compliance
Yes
75
115580541675/1/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Yes
76
115670749275/5/2020YesApplication Development
DevOps and/or Application Management
Information Security
Dependencies
Containers
Container images
No
77
115678584845/5/2020NoApplication Development
DevOps and/or Application Management
Information Security
Static application security testing (SAST)
Dynamic application security testing (DAST)
Containers
Container images
License compliance
Yes
78
115685209295/5/2020Yes
DevOps and/or Application Management
IT Operations and/or Site Reliability Engineering
Information Security
Containers
Container images
License compliance
No
79
115690713535/5/2020No
IT Operations and/or Site Reliability Engineering
Static application security testing (SAST)
Container images
Yes
80
115693374135/5/2020No
DevOps and/or Application Management
Containers
Container images
License compliance
Yes
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100