January 21, 2025
“Efficiency” seems like the new buzzword for federal technology in the next few years. When writing software sense, efficiency can mean writing code once and moving on to regular maintenance.
However, we see security initiatives being mandated that cause developers to go back to previous stable systems and add code alterations to comply with new cyber threats. Even beginner efficiency experts will tell you the time and cost of operating in this manner can be expensive.
Further, recording can add new bugs and risks, making the system more complex.
Federal technology leaders from CISA have not lost sight of this. They have a “Secure by Design” initiative that addresses this issue. As in many tech concerns, the concern is how to accomplish this noble task.
"And in fact, that's some of the capability that we drive is using, the capability that when they're developing the code, the developer can see right away that they're writing something that is either duplicative, problematic, or an error."
Nathan Jones, Sonar Tweet
Today, we sit down with Nathan Jones from Sonar. He offers a solution that seeks to “shift left” the whole concept of security by design. His company provides systems that can review code to ensure its compliance. Further, he expands on an approach that can collaborate with developers while they write code.
Nathan Jones gives listeners details about how SonarQube can be deployed on a server, in the cloud, or with IDE.
The benefits are ample: lower maintenance, minimizing risk, and allowing a focus on innovation rather than rewriting code.
Want to learn more? There is an event in Reston on March 12 where you can see how SonarQube works.
If you liked this interview, you may want to listen to:
EP 211: Build Software Faster with GitLab
This episode discusses tools and processes that speed up software development, fitting well with the shift-left theme of early testing and automation.
EP 215: Federal Acquisition is the Key to Taking Advantage of Technology Innovation
Since shift-left involves improving the acquisition and delivery cycle, linking to acquisition and innovation topics can be valuable
