Automation is a foundation of DevSecOps because it removes the prospect of human error from some common build tasks and security checks.
A move to DevSecOps is about the transformation of processes, tools, frameworks, job roles, and even culture. Some teams will transition from DevOps to the more security focused DevSecOps bringing together formerly separate teams, roles, and processes to assert security and compliance goals and responsibilities through standard processes and technology. There are also teams transitioning from a legacy software development lifecycle (SDLC) to DevOps and DevSecOps at the same time.
Prioritizing security as a design principle built into your development flow doesn’t happen overnight — which is why it requires a DevOps to DevSecOps transformation. You need collaboration from your developers, cybersecurity experts, sysadmins, business stakeholders, and even your executives.