Struggling to document & collect evidence to demonstrate compliance and operate securely while keeping your deploy cadence the same? We’ll share our strategy doing a minimum of 20 deploys/week through a continuous security/compliance approach. View it as ‘security as code’ and ‘compliance as code’. Complicated security/compliance frameworks can wreak havoc on devops processes. With security frameworks and their related compliance programs becoming more and more comprehensive, better security and compliance automation approaches are needed so the high cadence of release cycles associated with devops can be maintained. We’ll share our DevSecOps mindset and related experience doing a minimum of 20 deploys a week while still logging/tracking all evidences needed to remain compliant with HIPAA/HITRUST – one of the broadest security frameworks in existence. We’ll highlight how we automate production change management tickets and also use a dynamic search/graph asset inventory model to operate securely & also demonstrate/document compliance requirement without having to slow down release cycle.