Summary
Key results
One operating model for secure product development across business units
Phased implementation roadmap for all product teams
Product development in need of consistent security governance
The client’s growing connected and embedded product environment combined software, firmware, cloud components, and digital delivery processes. It covered products developed under both automotive and non-automotive requirements, with responsibilities distributed across product, platform, security, and compliance functions. As this environment expanded, the organization needed one consistent approach to security throughout product delivery.
The release process still depended on several separate steps and too much manual work. Security gates were missing, software bill of materials practices were not standardized, and teams applied static application security testing and software composition analysis inconsistently. Artifact signing, promotion, and compliance evidence collection were not automated, while publishing remained outside controlled pipelines. Responsibilities for releases and cryptographic keys also needed clearer separation.
These gaps increased operational and compliance risk, limited scalability, and created dependencies on individual specialists. Before introducing additional tools or starting implementation, the client needed a clear view of the current state and a practical direction for aligning processes, roles, governance, and technology. It engaged Sii Poland to define that direction.
Turning assessment findings into a phased implementation roadmap
Over 4 months, a Sii Poland team analyzed the client’s product delivery environment, covering processes, roles, governance, CI/CD, tooling, cloud architecture, infrastructure management, and compliance.
The scope of work included:
- Mapping development and security processes, responsibilities, and stakeholder requirements
- Reviewing release controls, artifact signing and promotion, pipeline-controlled publishing, separation of duties, and compliance evidence collection
- Identifying gaps against relevant industry standards, regulations, and the OWASP DevSecOps Maturity Model
- Evaluating governance, process, and tooling options for the target secure development approach
- Turning the findings into a target DevSecOps strategy, organization-wide operating model, and phased implementation roadmap with workstreams, maturity levels, dependencies, phases, and milestones for all product teams
Clear priorities for controlled DevSecOps adoption
Sii Poland translated the analysis into clear priorities for the next phase. The client could sequence changes according to identified gaps, dependencies, and maturity levels before introducing new tools or modifying delivery processes.
This reduced the risk of fragmented or tool-driven adoption across business units and provided product teams with a consistent path for developing DevSecOps capabilities over time. It also strengthened the organization’s readiness to meet compliance requirements and scale security-by-design practices across connected and embedded products.
The strategy then moved into practice as the cooperation continued with level 1 of the OWASP DevSecOps Maturity Model.
Key results
- One organization-wide operating model for secure product development
- Phased implementation roadmap covering all product teams
- Defined workstreams, maturity levels, dependencies, phases, and milestones
- Implementation priorities based on identified security and compliance gaps
- Lower risk of fragmented or tool-driven DevSecOps adoption
- Implementation started for level 1 of the OWASP DevSecOps Maturity Model