4 ms·
I think they are arguing that this is changing now. When I first started software engineering ~15 years ago, it was pretty common for enterprises to exert quite
by thinkharderdev 6y ago
I think they are arguing that this is changing now. When I first started software engineering ~15 years ago, it was pretty common for enterprises to exert quite a lot of control over what tech could be used. You had to use some solution from the "approved" list of languages/frameworks/versions (that was always hilariously out of date). Then that swung in the opposite direction (mostly concurrently with cloud adoption where dev teams were in charge of their own infrastructure) where individual teams had complete free reign to choose their own tech. The author is arguing that things are now swinging back in the other direction and it's largely driven by security considerations. So its not "you have to use something on the approved list of tech maintained by the Enterprise Architecture gods" but rather "you have to use something that is supported by our enterprise SAST solution." It will still likely be more lax than it was back in the old days because it is harder to enforce those restrictions in a world where the dev team manages their own cloud infrastructure, but still.
- raesene9 6y agosure, and it's the argument that it's swinging back in the favour of centralised control that I don't buy. I look at major enterprises quickly adopting what are still quite new technologies, a good example being the uptake of things that come under the cloud native banner and that doesn't tell me that things are becoming more centralised/controlled. I've spoken to multiple security teams looking at container security who've said things along the lines of "this is getting deployed whether we want it or not, so we're doing our best to keep up" Ofc my examples will just be anecdotal, but that's what I'm seeing.
- thinkharderdev 6y agoYeah, I would mostly agree. I have noticed personally at my (largish) company a bit of a shift back towards centralized control, but only slightly. One thing that does seem very different now is that there is a lot more pressure on the vendors of SAST and other security products to support newer tech stacks. And if the big boys won't then there are always a huge number of smaller players ready to jump in to take advantage of that opening. The number of products just in the Serverless space offering "next-gen" WAF solutions is pretty amazing given how recent large scale adoption of Serverless stacks has been.