Delivery processes
A comprehensive catalog of tools and technologies used in the delivery pipeline, organized by process area with status tracking and implementation details.
The Delivery Processes Catalog provides a comprehensive list of tools and technologies used in the delivery pipeline.
New technologies can be introduced by preparing a “spike” that identifies the need, establishes clear acceptance criteria, and builds a provable case that adding the new technology provides a significant benefit exceeding the cost of doing so.
For this activity, refer to chapter 2.8 Delivery processes & tools as a guide. As technologies are adopted, keep your service catalog up to date. Use the tags Proposed, Under review and Approved to reflect the current status of each catalog entry.
Delivery processes map
The following drawing provides a high-level map and identifies different processes you’ll want to think about.
Service catalog
The following table identifies products and technologies used in the delivery pipeline, and where appropriate indicate a priority for implementation.
New entries should be added with a Proposed tag and must be reviewed and approved by the Architecture Review Board.
| Process | Status | Functional Area | Implementation |
|---|---|---|---|
| Manage | |||
| Audit Events | Proposed P2 | Observability |
|
| Audit Reports | Proposed P2 | Observability |
|
| Compliance Management | Proposed P2 | Compliance |
|
| Operational Visibility | Proposed P2 | Observability |
|
| … | |||
| Plan | |||
| Issue Tracking | Under review P1 | Incident Management |
|
| Design Management | Under review P1 | Asset Management |
|
| … | |||
| Create | |||
| Source Code Control | Approved P1 | Asset Management |
|
| Code Review | Approved P1 | Development | |
| Peer Review | Approved P1 | Development |
|
| Common Repository | Approved P1 | Development |
|
| Ephemeral Environments | Approved P1 | Infrastructure Management |
|
| … | |||
| Verify | |||
| Continuous Integration | Approved P1 | Build Management |
|
| Code Testing and Coverage | Under review P1 | Development |
|
| Package | |||
| Package Registry | Approved P1 | Build Management |
|
| Container Registry | Approved P1 | Build Management |
|
| Dependency Management | Under review P1 | Build Management |
|
| Release Evidence | Approved P1 | Build Management |
|
| … | |||
| Secure | |||
| SAST | Approved P1 | Security |
|
| Secret Detection | Approved P1 | Security |
|
| Code Quality Analysis | Approved P1 | Security |
|
| DAST | Under review P2 | Security | |
| Fuzz Testing | Under review P2 | Security |
|
| Dependency Analysis | Under review P2 | Security |
|
| … | |||
| Release | |||
| Continuous Delivery | Approved P1 | Build Management |
|
| Review Apps | Approved P1 | Build Management |
|
| … | |||
| Configure | |||
| Secrets Management | Under review P1 | Security |
|
| Infrastructure as Code | Under review P1 | Infrastructure Management |
|
| … | |||
| Monitor | |||
| Operational Observability | Under review P2 | Monitoring |
|
| Telemetry | Under review P2 | Monitoring |
|
| Integrated Dashboard | Under review P2 | Monitoring |
|
| … | |||
| Protect | |||
| Container Scanning | Approved P1 | Security |
|
| … | |||