Conf42 DevOps 2023 - Online

Automated DevSecOps maturity Assessment using Next-gen Technologies

Video size:

Abstract

Are you CTO/CDIO/IT manager /Business Owner, who is struggling to answer - ‘Why your organization/business Units/Applications are not delivering continuously and cost-efficiently? “How to identify the improvement areas for future investment?” and many more; then spend 30 mins listening to this talk! Zurich, jointly with TCS, has developed a capability called ‘DATA HOOK’ using Next-Gen technologies, for measuring DevSecOps adoption. DATA HOOK (a technology + industry-agnostic tool) calculates the metrics automatically using the Application Programming Interface (APIs), from the real data produced by the enterprise applications in the standard tools (for instance, JIRA for Sprints deliveries). Some of its SALIENT FEATURES include 1) Cloud based (can be scaled easily to any dimension) 2) Technology independent (can be implemented for any platform/technology) 3) Industry-independent (cross-industry solution) 4) Highly configurable (to any tool in the world using standard APIs) Flexible to hook to any Business intelligence tool (based on customer needs) 5) User-friendly customizable dashboards along with Error reports Moreover, Existing tools prevailing in the market are SURVEY/QUESTIONAIRE based on the annual entries. Juan and Sandeep will explain the challenges, opportunities, and benefits identified when introducing this DevSecOps assessment practice implemented at the enterprise level around the globe and the set of KPIs calculated automatically by the tool.

Summary

  • Tata Group is a global it services consulting and business solution provider. With a market capitalization of 144 billion with a revenue of 25 plus billion dollars in FY 2022. The company has spreaded its wings across all the industries ranging from BFSI, retail, manufacturing. Today we are going to explain you a bit about our case.
  • An automated continuous dashboard with neo human error. There are no standard setup developed matrices which can be applied across the business units. There isn't any harmonization of the Devsecops adoption view of the organization. Here we have Juan who will be talking about the solution.
  • Data hoop is a tool that provides the application team, the business units it heads, but also the group leaders information about how we are doing developed in our corporation. The benefits that data hoop brings to organization include faster agile adoption.
  • More than 200 applications from twelve business units has been assessed. Monthly onboarding ratio is about 20% plus 20%. Lead time to market KPIs decreased by 9% over the last nine months. More to come within the next months and years.
  • Thank you very much for listening us and if you are interested to know a bit more about data hook. Here you have our email address. Feel free to reach out. I will be more than happy to get in contact with you.

Transcript

This transcript was autogenerated. To make changes, submit a PR.
You. Hello everybody. First of all, thank you for inviting us to present in the 42 Devsecops 2023 event. So today we are going to explain you a bit about our case. And to do so, I'm having here with me Sandeep Panghal, which is managing consultant within tcs and myself Juan Antonio Conde, head head head head head of application portfolio composition. We enter into the case. So let's provide a brief update on where we are with who we are. So Zurich is a little more deliveries insurance that serve its customer in a global and local market. Funded in 1872 with about 56,000 employees, it provides a wide range of property and casualty and life insurance products and services in more than 210 countries and territories. Sandeep, I will hand over to you to provide a brief update on Tata and then we can go into the case. Yeah, Tata Tata Tata Tata Consultancy Services World renowned Tata Group is a global it services consulting and business solution provider who has been building greater futures through innovations and knowledge for over 50 plus years. So we have been recommended has a top two most valuable brand in 2022 with a market capitalization of 144 billion with a revenue of 25 plus billion dollars in FY 2022. So we are a company of 600,000 plus employees representing 150 plus nationalities with a 35 plus diversity percentage. So we are a company who has spreaded its wings across all the industries ranging from BFSI, retail, manufacturing. So whatever you name it, TCS is there with BFSI predominantly dominating in the revenue market. So if I talk about from the geographical area. So we have spread it across the globe with the major businesses working, coming from the North America followed by Europe, continental Europe as well as the Asia. So we have been ranked as a top 20 future brand in the index 2021 and has been ranked as a top hundred as a leader by the research firms. Moving on. Basically now I will be giving you a walkthrough about our automated Devsecops maturity assessment, about the background, basically how we came out talk about this solution. So basically here is our CTO or CIO of an organization who is thinking that how do I know about Devsecops adoption of the business unit functions or the entire organization? How matured am I organization in Devsecops with respect to industry standards? How do I compare business units in terms of future investment? Which business units, applications or the platforms are less efficient with lower quality and lower production deliveries and the vice versa? Where I need to invest more? How can I benchmark each business unit application or the functions against each other or with other insurance providers or moreover with other industries. Can I have some kind of a point in time? Dashboards, automated continuous dashboard with neo human error. So this was the background. Now, if I talk about the problem statement, there are no standard setup developed matrices which can be applied across the business units which have been globally spreaded across the different countries for using. And there isn't any harmonization of the Devsecops adoption view of the organizationbusiness and the matrices which are being produced with the big manual efforts due to the multiple data sources, due to the complexities of the various applications, diverse landscapes and the tools used across the various business units. And the teams are focusing on introducing mattresses and the measurement rather than on the production deliveries. So in order to resolve this problem, here we have Juan who will be talking about the solution. So yeah, so Sandeep went through the problem statement. What were the major headaches that it brings to our organization? But I'm pretty sure that that's something that is common across quite a lot of companies worldwide, especially if they are big corporations. So after many different meetings with quite a lot of different stakeholders across Zurich, but also we engage with many different partners to confirm the direction to follow. So we have been talking with key reference partners and consultant firms around the globe. So it came up on the solution has indeed said that we need to build something that brings automation on how we produce metrics that is tool agnostic and just provide the metrics that we require, but also providing the flexibility in case that we need to adjust the metrics. And here it is where data hoop, which is the product that we have built from scratch, is coming into the picture. So first of all we thought, okay, so how we are going to be building something new. Of course this needs to be cloud based, needs to be scalable, agnostic of technologies, underlying technologies, but of course flexible enough to integrate with the different DevOps tools that we are having in the market. Also code quality tools, security testing tools, different testing tools that we can incorporate into data hook in terms of data points or metadata retrieve from data hook. In one side we have the technology, but in the other side we have been designing data hook with the customer in mind. So of course we have been applying design thinking and user experience principles. It has been secured by design. So in the sense that we protect the business units, data or group data to don't be shared with others, at least that we are interested providing benchmarks also from global organization to the business units to the teams without compromising that anonymization of data to be presented from one group to another. It has been also user friendly error reports produced in order to make business units application teams understand why they are not seeing their data within the dashboard, how they can improve the way that they are doing things. All right? And this has been the main purpose of data hook. So create a tool that provides the application team, the business units it heads, but also the group leaders information about how we are doing developed in our corporation. So what is our development efficiency? So the benefits that data hoop brings to organization. And you can see some of them here on this slide. And I have been referring to some of those already. So faster agile adoption. So of course, I'm pretty sure that many big corporations like us can think, hey, how agile is our organization? How many agile applications do we have? Right? So with Datacoop, we have been able to not only identify how our teams are applying those agile behaviors on the different tools that we are using to do software development, but also to do project management. We have been also able to incorporate other disciplines like how automated processes are, how we are doing testing across the different applications and teams. Right? So once you know the data, of course you can improve, which is describe the continuously improvement behavior. But as I mentioned earlier, so that allow us really to compare with the different units, the different teams, and not just with the aim of knowing where we are, also with the aim of course, always to improve. And of course last but not least, so we have been able to produce metric at a scale almost with no effort or with a very little effort on the team side. All right. The outcome up to date about what we have done. So here you have some figures so we have implemented or we have onboarded within data hook. I would say that right now it's a bit more than 200 applications from twelve business units has been assessed. The monthly onboarding ratio is about 20% plus 20%. The onboarding process for new application is automated through Azure pipeline. So almost an onboarding of an application can be performed without any manual intervention. Metrics related to customer value, organizational effectiveness, service quality, measurement areas continuously from several tool sets. So we are retrieving data on a regular basis, on a monthly basis and we are producing those metrics to our different teams, global business units and department benchmark is available for test, SEc ops adoption, maturity assessment. Lead time to market KPIs decreased by 9% over the last nine months. So we're here becoming faster. So this is going back to the continuous improvement that we have seen on the previous slide and then also we have identified up to 10% month to month increase in technical, therefore 20 plus business areas over the last year. So those numbers areas just reflecting the adoption of data who within Zurich. And this well is more to come within the next months and years. So hopefully this has been something interesting for you. Thank you very much for listening us and if you are interested to know a bit more about data hook. So here you have our email address. Feel free to reach out. I will be more than happy to get in contact with you and to provide more details about how we have implemented data hook in our corporation. Thank you very much.
...

Sandeep Panghal

Senior Engagement Manager @ Tata Consultancy Services

Sandeep Panghal's LinkedIn account Sandeep Panghal's twitter account

Juan Antonio Conde

Head of Application Portfolio Composition @ Zurich Insurance Group

Juan Antonio Conde's LinkedIn account



Join the community!

Learn for free, join the best tech learning community for a price of a pumpkin latte.

Annual
Monthly
Newsletter
$ 0 /mo

Event notifications, weekly newsletter

Delayed access to all content

Immediate access to Keynotes & Panels

Community
$ 8.34 /mo

Immediate access to all content

Courses, quizes & certificates

Community chats

Join the community (7 day free trial)