As a PM at JPMC, I'd approach defining OKRs, strategy, and goals for a new DevSecOps platform by first clarifying the scope: is this platform for a specific business unit or enterprise-wide? Understanding if we're evolving an existing DevOps practice to include security or building from scratch is also crucial.
My strategic approach would involve:
-
Defining Core Objectives: Aligning the platform's goals with JPMC's broader business objectives, such as accelerating secure software delivery, reducing operational risk, and fostering a culture of shared security responsibility.
-
Establishing Key Pillars: Identifying the foundational elements of the DevSecOps platform, including:
- Integrated Security Tooling: Selecting and integrating security scanning, testing, and monitoring tools across the CI/CD pipeline (e.g., SAST, DAST, SCA, IaC scanning).
- Automated Workflows: Designing CI/CD pipelines that embed security gates and automated remediation where possible.
- Culture & Training: Promoting security awareness and best practices among development and operations teams.
- Observability & Governance: Implementing robust logging, monitoring, and compliance frameworks.
-
Setting Measurable OKRs: Based on these pillars, I would define Objectives and Key Results. For example:
- Objective: Enhance the security posture of all deployed applications.
- KR1: Reduce critical vulnerabilities found in production by 50% within Q3.
- KR2: Achieve 90% adoption of automated security scanning in all CI pipelines by EOY.
- KR3: Decrease mean time to remediate (MTTR) security findings by 30% within six months.
- Objective: Accelerate secure software delivery velocity.
- KR1: Increase deployment frequency for security-vetted code by 25% per quarter.
- KR2: Reduce the average time from code commit to production deployment by 15% while maintaining security compliance.
This framework ensures that the DevSecOps platform is not just a technical initiative but a strategic enabler for JPMC, driving both speed and security.