REFERENCE MODEL

Secure Software Delivery

DEVSECOPS OPERATING MODEL  |  SOFTWARE DELIVERY  |  SECURITY ARCHITECTURE
Jon Silvester on LinkedIn
v1.0  |  September 2026
Source control · CI/CD · SAST · SCA · DAST · AWS / Azure / GCP
devsecops.cyberassure.uk
Colour by Select any element for the control detail and the risk of not having it.
BUSINESS & REGULATORY DRIVERS Secure by Design (10 principles) · NCSC CAF v4.0 · GovS 007 · GDS Service Standard · UK GDPR · OWASP ASVS & SAMM · NCSC secure development Accountable: SIRO | CISO | Director of Digital | Head of Security Architecture | SROs & Service Owners | Delivery Leads
BUSINESS ATTRIBUTES  |  THE SECURITY OUTCOMES EVERY SERVICE MUST EXHIBIT
Security domains of the software delivery lifecycle
The toolchain
The pipeline, end to end
SECURE BY DESIGN STAGES

FEEDBACK LOOP — SAST, SCA and quality findings, cloud posture alerts and SOC detections return to PLAN and CODE, and revise the golden pipeline that let them through

GOVERNANCE CADENCE Daily Pipeline health · blocked builds · secret alerts Weekly SAST / SCA severity burn-down + SLA breach Monthly Design Authority · exception review · golden pipeline release Quarterly GovAssure / CAF return · toolchain assurance review
PIPELINE GATES — WHAT BLOCKS, WHAT WARNS A gate that only warns is a preference. Every BLOCK below is a control with an owner, and every bypass is a time-bound Design Authority exception (B-07).