SlideShare a Scribd company logo
Ops Happens:
Improve Security Without Getting in the Way
February 29, 2016 ● San Francisco
Damon Edwards
@damonedwards
Damon
Edwards
Operational Improvement
DevOps Consulting
Tools
Damon
Edwards
Operational Improvement
DevOps Consulting
Tools
Community
The Shared Plight of Ops and Security
OPS
&
SEC
“Go faster!”
“Open it up!”
“Be more secure!”
“Be more reliable!”
Deployment dominates the conversation
2013
Deployment. Deployment.
Continuous Delivery.
Deployment. Deployment.
Continuous Deployment.
Deployment. CI/CD.
Deployment. Deployment.
Deployment. PaaS.
Deployment. IaaS.
Deployment. Deployment.
Infrastructure as Code.
Deployment. Deployment.
Deployment. Deployment.
Containers. Containers.
Deployment. Deployment.
Deployment. Docker
Deployment. Docker. CaaS.
Deployment. Docker.
Docker. Docker. Docker.
Mesos. Deployment.
Kubernetes. Deployment.
Microservices. Deployment.
Deployment. Docker.
2016
What this sounds like to enterprise Ops & Sec
“What we always give you, but more of it… and a lot more frequently”
“What we always give you, but more of it… and a lot more frequently”
What this sounds like to enterprise Ops & Sec
“Shift Left” to avoid disaster (a.k.a “DevOps 101”)
Writing / Running Automated Tests
Writing / Exercising Deploy Automation
Running Security Scanning Tools
“Shift Left” to avoid disaster (a.k.a “DevOps 101”)
Writing / Running Automated Tests
Writing / Exercising Deploy Automation
Running Security Scanning Tools
Deploy.
Deploy.
Deploy.
“Shift Left” to avoid disaster (a.k.a “DevOps 101”)
But guess what...
Sh*t happens
But guess what...
Sh*t happens
Operations
How do you “shift left” incident response?
How do you “shift left” incident response?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
But...
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
But...
How do you safely and securely give out access?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
But...
How do you safely and securely give out access?
How do you enable the experts to contribute remediations?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
But...
How do you safely and securely give out access?
How do you enable the experts to contribute remediations?
How do you give visibility into operations?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
How do you “shift left” incident response?
But...
How do you safely and securely give out access?
How do you enable the experts to contribute remediations?
How do you give visibility into operations?
How do you do postmortems days/weeks/months later?
Those who build something define the procedures to fix it
Those who build something fix it when it breaks
1
2
Design pattern we’ve seen developing in the community...
Shift Left Step 1: Establish a Secure Ops Portal
Shift Left Step 2: Establish a SDLC for Ops Procedures
Shift Left Step 3: Connect with Enterprise Management Systems
Shift Left Step 4: Make Compliance Really Happy
Who created the procedure?
Who reviewed it? Who? When? Where? Approval trail?
Pay for it with ROI outside of Security
Mark
Maun
Jody
Mulkey
Ticketmaster’s “Support at the Edge” model
• Empowered support teams with self-service ops tasks
• Automated Ops procedures written/vetted by the delivery teams
• Expanded who could take action, but ops remained in full control of
the policy
Pay for it with ROI outside of Security
Mark
Maun
Jody
Mulkey
Ticketmaster’s “Support at the Edge” model
• Empowered support teams with self-service ops tasks
• Automated Ops procedures written/vetted by the delivery teams
• Expanded who could take action, but ops remained in full control of
the policy
Sources: https://www.youtube.com/watch?v=_hr4KiB19bQ
http://rundeck.org/stories/mark_maun.html
• Removed multiple days of effort from throughout the lifecycle
• Reduced escalations by 30% - 40% and overall support incident
costs by 55%
• Reduced mean time to repair (MTTR) by 50% - 150%
Want to talk more about “shift left” and operations?
@alexhonor
alex@simplifyops.com
My colleague who
thinks a lot about
these solutions
A word from today’s organizers…
A word from today’s organizers…
A word from today’s organizers…

More Related Content

PDF
Silver Lining for Miles: DevOps for Building Security Solutions
PDF
What we learned from three years sciencing the crap out of devops
PPTX
The R.O.A.D to DevOps
PPTX
Amy DeMartine - 7 Habits of Rugged DevOps
PPTX
The Journey to DevSecOps
PDF
What We Learned from Three Years of Sciencing the Crap Out of DevOps
PPTX
Failure is inevitable but it isn't permanent
PDF
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Silver Lining for Miles: DevOps for Building Security Solutions
What we learned from three years sciencing the crap out of devops
The R.O.A.D to DevOps
Amy DeMartine - 7 Habits of Rugged DevOps
The Journey to DevSecOps
What We Learned from Three Years of Sciencing the Crap Out of DevOps
Failure is inevitable but it isn't permanent
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon

What's hot (17)

PPTX
Open Source Defense for Edge 2017
PDF
New Barriers of Transformation
PDF
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
PDF
Continuous Delivery to Continuous Operations, DevOps & SRE = Continuous Culture
PDF
Using security to drive chaos engineering
PPTX
451 AppSense Webinar - Why blame the user?
PDF
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
PDF
Shifting Security Left - The Innovation of DevSecOps - AgileDC
PPTX
Security and DevOps Overview
PDF
DevOps not a Toolbox
PPTX
Colin Domoney -
PDF
Outpost24 webinar - The economics of penetration testing in the new threat la...
PDF
DevSecCon Singapore 2018 - Measuring and maximizing vuln discovery efforts by...
PPTX
Shifting Security Left from the Lean+Agile 2019 Conference
PPTX
State of DevSecOps - DevOpsDays Jakarta 2019
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
PPTX
Scaling Rugged DevOps to Thousands of Applications - Panel Discussion
Open Source Defense for Edge 2017
New Barriers of Transformation
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Continuous Delivery to Continuous Operations, DevOps & SRE = Continuous Culture
Using security to drive chaos engineering
451 AppSense Webinar - Why blame the user?
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
Shifting Security Left - The Innovation of DevSecOps - AgileDC
Security and DevOps Overview
DevOps not a Toolbox
Colin Domoney -
Outpost24 webinar - The economics of penetration testing in the new threat la...
DevSecCon Singapore 2018 - Measuring and maximizing vuln discovery efforts by...
Shifting Security Left from the Lean+Agile 2019 Conference
State of DevSecOps - DevOpsDays Jakarta 2019
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Scaling Rugged DevOps to Thousands of Applications - Panel Discussion
Ad

Viewers also liked (13)

PDF
世界のコーフボール紹介
PPTX
Ethnography and product design by Prof William Beeman at ProductCamp Twin Cit...
PPTX
Tips de belleza
PDF
100 ιδι τικο συμφ νητικο υπεκμισθ σησ
PDF
Speciale mobilità-elettrica-urbana qualenergia-nov2013
PPTX
Determinantes y pronombres
PDF
Kaixin's UROP_symposium_poster
PDF
Paths to Fisheries Subsidies Reform: Creating sustainable fisheries through t...
PPTX
AMIZONER Status Report - March 2014
PPTX
Pitch to win Sales and Investment
PPTX
Jhon quiroga mi historia inspiradora 1
PPS
Paseando Por Asturias 23 10 08
世界のコーフボール紹介
Ethnography and product design by Prof William Beeman at ProductCamp Twin Cit...
Tips de belleza
100 ιδι τικο συμφ νητικο υπεκμισθ σησ
Speciale mobilità-elettrica-urbana qualenergia-nov2013
Determinantes y pronombres
Kaixin's UROP_symposium_poster
Paths to Fisheries Subsidies Reform: Creating sustainable fisheries through t...
AMIZONER Status Report - March 2014
Pitch to win Sales and Investment
Jhon quiroga mi historia inspiradora 1
Paseando Por Asturias 23 10 08
Ad

Similar to Ops Happen: Improve Security Without Getting in the Way (20)

PDF
The left is not wrong, just not right; It's time to shift right!
PDF
Helping Ops Help You: Development’s Role in Enabling Self-Service Operations
PDF
Ops Happens: DevOps Beyond Deployment - Damon Edwards
PDF
Shift Left. Wait, what? No, Shift Right!!!
DOCX
Shift Left Save Resources DevSecOps and the CICD Pipeline
PDF
Operations as a Service: Because Failure Still Happens
PDF
Shift Left Security
PDF
Shift Left Security
PDF
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
PDF
DevSecOps at Agile 2019
PDF
Keeping Your DevOps Transformation From Crushing Your Ops Capacity
PDF
Deepfence.pdf
PPTX
Shifting security all day dev ops
PDF
Shift Left Security – Guidance on embedding security for a Digital Transforma...
PPTX
Learning from Learnings: Anatomy of Three Incidents
PPTX
The Journey to DevSecOps
PDF
SRE Organizational Framework
PDF
Rick Clymer - Incident Management.pdf
PPTX
Mapping Networks for Day 3 Management
PPTX
Proactive Approach to OT incident response - HOUSECCON 2023
The left is not wrong, just not right; It's time to shift right!
Helping Ops Help You: Development’s Role in Enabling Self-Service Operations
Ops Happens: DevOps Beyond Deployment - Damon Edwards
Shift Left. Wait, what? No, Shift Right!!!
Shift Left Save Resources DevSecOps and the CICD Pipeline
Operations as a Service: Because Failure Still Happens
Shift Left Security
Shift Left Security
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
DevSecOps at Agile 2019
Keeping Your DevOps Transformation From Crushing Your Ops Capacity
Deepfence.pdf
Shifting security all day dev ops
Shift Left Security – Guidance on embedding security for a Digital Transforma...
Learning from Learnings: Anatomy of Three Incidents
The Journey to DevSecOps
SRE Organizational Framework
Rick Clymer - Incident Management.pdf
Mapping Networks for Day 3 Management
Proactive Approach to OT incident response - HOUSECCON 2023

More from SeniorStoryteller (20)

PPTX
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
PPTX
Where Bits & Bytes Meet Flesh and Blood - Joshua Corman
PDF
Implementing DevOps in a Regulated Environment - DJ Schleen
PPTX
Making Security Agile - Oleg Gryb
PDF
What We Learned from Four Years of Sciencing the Crap Out of DevOps - Nicole ...
PDF
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
PDF
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
PDF
Building Security In - A Tale of Two Stories - Laksh Raghavan
PDF
Breaking Bad Equilibruim - John Willis
PDF
DevSecOps - Building Rugged Software
PPTX
NuGet Package Management Done Right
PPTX
Hero's Tookit: Start Your Rugged DevOps Journey with Nexus, Jenkins and Docker
PPTX
The End of Security as We Know It - Shannon Lietz
PPTX
Safely Removing the Last Roadblock to Continuous Delivery
PPTX
Software Supply Chain Automation Removes Roadblocks to Rugged DevOps
PDF
Heroes’ Journey: Learning from Successful DevOps Transformations
PPTX
Rugged DevOps: Aligning Your Team and Your Powers for Success
PPTX
Create Rugged Applications: Managing Your Software Supply Chain
PPTX
Aligning Your Team and Your Powers for Success
PPTX
Leveraging Nexus Repository Manager at the Heart of DevOps
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World! - S...
Where Bits & Bytes Meet Flesh and Blood - Joshua Corman
Implementing DevOps in a Regulated Environment - DJ Schleen
Making Security Agile - Oleg Gryb
What We Learned from Four Years of Sciencing the Crap Out of DevOps - Nicole ...
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
Building Security In - A Tale of Two Stories - Laksh Raghavan
Breaking Bad Equilibruim - John Willis
DevSecOps - Building Rugged Software
NuGet Package Management Done Right
Hero's Tookit: Start Your Rugged DevOps Journey with Nexus, Jenkins and Docker
The End of Security as We Know It - Shannon Lietz
Safely Removing the Last Roadblock to Continuous Delivery
Software Supply Chain Automation Removes Roadblocks to Rugged DevOps
Heroes’ Journey: Learning from Successful DevOps Transformations
Rugged DevOps: Aligning Your Team and Your Powers for Success
Create Rugged Applications: Managing Your Software Supply Chain
Aligning Your Team and Your Powers for Success
Leveraging Nexus Repository Manager at the Heart of DevOps

Recently uploaded (20)

PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
A Presentation on Artificial Intelligence
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Big Data Technologies - Introduction.pptx
PDF
Electronic commerce courselecture one. Pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPT
Teaching material agriculture food technology
PDF
Approach and Philosophy of On baking technology
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Encapsulation theory and applications.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
A Presentation on Artificial Intelligence
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Spectral efficient network and resource selection model in 5G networks
Unlocking AI with Model Context Protocol (MCP)
Big Data Technologies - Introduction.pptx
Electronic commerce courselecture one. Pdf
Advanced methodologies resolving dimensionality complications for autism neur...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Teaching material agriculture food technology
Approach and Philosophy of On baking technology
“AI and Expert System Decision Support & Business Intelligence Systems”
Understanding_Digital_Forensics_Presentation.pptx
Digital-Transformation-Roadmap-for-Companies.pptx
Encapsulation theory and applications.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
20250228 LYD VKU AI Blended-Learning.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Dropbox Q2 2025 Financial Results & Investor Presentation
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...

Ops Happen: Improve Security Without Getting in the Way

  • 1. Ops Happens: Improve Security Without Getting in the Way February 29, 2016 ● San Francisco Damon Edwards @damonedwards
  • 4. The Shared Plight of Ops and Security OPS & SEC “Go faster!” “Open it up!” “Be more secure!” “Be more reliable!”
  • 5. Deployment dominates the conversation 2013 Deployment. Deployment. Continuous Delivery. Deployment. Deployment. Continuous Deployment. Deployment. CI/CD. Deployment. Deployment. Deployment. PaaS. Deployment. IaaS. Deployment. Deployment. Infrastructure as Code. Deployment. Deployment. Deployment. Deployment. Containers. Containers. Deployment. Deployment. Deployment. Docker Deployment. Docker. CaaS. Deployment. Docker. Docker. Docker. Docker. Mesos. Deployment. Kubernetes. Deployment. Microservices. Deployment. Deployment. Docker. 2016
  • 6. What this sounds like to enterprise Ops & Sec “What we always give you, but more of it… and a lot more frequently”
  • 7. “What we always give you, but more of it… and a lot more frequently” What this sounds like to enterprise Ops & Sec
  • 8. “Shift Left” to avoid disaster (a.k.a “DevOps 101”)
  • 9. Writing / Running Automated Tests Writing / Exercising Deploy Automation Running Security Scanning Tools “Shift Left” to avoid disaster (a.k.a “DevOps 101”)
  • 10. Writing / Running Automated Tests Writing / Exercising Deploy Automation Running Security Scanning Tools Deploy. Deploy. Deploy. “Shift Left” to avoid disaster (a.k.a “DevOps 101”)
  • 12. But guess what... Sh*t happens Operations
  • 13. How do you “shift left” incident response?
  • 14. How do you “shift left” incident response? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 15. How do you “shift left” incident response? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 16. How do you “shift left” incident response? But... Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 17. How do you “shift left” incident response? But... How do you safely and securely give out access? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 18. How do you “shift left” incident response? But... How do you safely and securely give out access? How do you enable the experts to contribute remediations? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 19. How do you “shift left” incident response? But... How do you safely and securely give out access? How do you enable the experts to contribute remediations? How do you give visibility into operations? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 20. How do you “shift left” incident response? But... How do you safely and securely give out access? How do you enable the experts to contribute remediations? How do you give visibility into operations? How do you do postmortems days/weeks/months later? Those who build something define the procedures to fix it Those who build something fix it when it breaks 1 2
  • 21. Design pattern we’ve seen developing in the community...
  • 22. Shift Left Step 1: Establish a Secure Ops Portal
  • 23. Shift Left Step 2: Establish a SDLC for Ops Procedures
  • 24. Shift Left Step 3: Connect with Enterprise Management Systems
  • 25. Shift Left Step 4: Make Compliance Really Happy Who created the procedure? Who reviewed it? Who? When? Where? Approval trail?
  • 26. Pay for it with ROI outside of Security Mark Maun Jody Mulkey Ticketmaster’s “Support at the Edge” model • Empowered support teams with self-service ops tasks • Automated Ops procedures written/vetted by the delivery teams • Expanded who could take action, but ops remained in full control of the policy
  • 27. Pay for it with ROI outside of Security Mark Maun Jody Mulkey Ticketmaster’s “Support at the Edge” model • Empowered support teams with self-service ops tasks • Automated Ops procedures written/vetted by the delivery teams • Expanded who could take action, but ops remained in full control of the policy Sources: https://www.youtube.com/watch?v=_hr4KiB19bQ http://rundeck.org/stories/mark_maun.html • Removed multiple days of effort from throughout the lifecycle • Reduced escalations by 30% - 40% and overall support incident costs by 55% • Reduced mean time to repair (MTTR) by 50% - 150%
  • 28. Want to talk more about “shift left” and operations? @alexhonor alex@simplifyops.com My colleague who thinks a lot about these solutions
  • 29. A word from today’s organizers…
  • 30. A word from today’s organizers…
  • 31. A word from today’s organizers…