SlideShare a Scribd company logo
DEVOPS = CI + CD + Continuous Security
H OW CAN I P USH T H E COD E I N T O P R OD AS
EAR LY BY T H I S WEEK EN D
M OR E N EW 10 FEAT UR ES T O BE R ELEASED
WI T H I N T H E CH R I STM AS H OLI D AY S !
SH ALL I GO FOR P ER FOR M AN CE T EST I NG
BEFOR E R ELEASI N G T H E COD E
D O I R EALLY N EED R ELEASE AN D BUI LD
M AN AGER T O AD D COST I N T O M Y T EAM
I N EED T H E AP P LI CAT I ON BUI LD T O BE
AUT OM AT I C..GR R R !!
I H AD COM M I T TED T H E COD E AGES BACK !
WH ER E I S T H E BUI LD GUY M I SSI N G ? ?
20
15
15
20
25
5
DEVELOPER
OH M Y GOD ! H E H AS AGAI N COM E
BACK FOR SY ST EM ACCESS
HOW DO I ASCER T AI N T HAT T HE
COD E I S N OT FUN CT I ONIN G D UE …
I N EED T O P AT CH T H E LI N UX SER VER S
WI T H T H E BASH VULN ER ABI LI TY …
SECUR I TY M EETI NGS ! H OW CAN I
H AN D LE SO M AN Y T H I N GS AT ON E …
LOG M AN AGEM EN T AN D P ASSWOR D
M AN AGEM EN T N EED S I M POR TAN CE
I WAN T T O WR I T E R ECI P ES AN D
P LAY BOOK S AN D WAN T T O M AK E …
20
10
25
10
20
15
OPERATIONS
Security Absorption in DevOps
GITHUB
Nexus
Jenkins
TEST
ELK
SECURITY
PenTest the
underlying
Operating
system
AppScan
using
OWASP ZAP
scanning
Monitor and
block on
weblayer.
Use strict
baselining
standards23%
49%
78%
DEVOPS
Continuous
Development
Business
requirements
Continuous
Security
Continuous
Integration &
Deployment
What should be automated
What should help ITIL process
What should bring Agility
What will bring affordability to business
How to bring resiliency
Which is the way to say No dependencies
OLD
school
Advanced
Continuous Integration
-Jenkins , CircleCI , Travis CI,Bamboo
Continuous Deployment
-Chef , puppet , Ansible
Continuous Monitoring
- Splunk , ELK , Nagios
Continuous Security
- OWASP ZAP,McAfee,Trend Micro

More Related Content

PDF
Continuous Integration with Jenkins and ANT
PPT
21 surprising facts about workplace productivity you must know
PDF
The SAFE-O-METER
PDF
How to Successfully Run a Remote Team
PPTX
DevOps in a Regulated and Embedded Environment (AgileDC)
PDF
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
PPTX
Making Security Agile - Oleg Gryb
Continuous Integration with Jenkins and ANT
21 surprising facts about workplace productivity you must know
The SAFE-O-METER
How to Successfully Run a Remote Team
DevOps in a Regulated and Embedded Environment (AgileDC)
Release Engineering & Rugged DevOps: An Intersection - J. Paul Reed
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Making Security Agile - Oleg Gryb

Viewers also liked (20)

PDF
Building Security In - A Tale of Two Stories - Laksh Raghavan
PPTX
Empowering Application Security Protection in the World of DevOps
PDF
Application Security at DevOps Speed - DevOpsDays Singapore 2016
PDF
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
PDF
DevSecOps - Building Rugged Software
PDF
Integrating DevOps and Security
PDF
Implementing DevOps in a Regulated Environment - DJ Schleen
KEY
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
PDF
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
PPTX
The Journey to DevSecOps
PDF
DevSecOps: Taking a DevOps Approach to Security
PPTX
DevOps & Security: Here & Now
PDF
The Retail Enterprise - And the rise of the omni-present consumer Part 2
PDF
Application Secret Management with KMS
PPTX
Beschikbaar jr. HBO Netwerk/Security/DevOps Engineer
PPTX
My Little Webap - DevOpsSec is Magic
PDF
Devops/Sysops security
PDF
Devops security
PDF
What's My Security Policy Doing to My Help Desk w/ Chris Swan
PPTX
Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Prac...
Building Security In - A Tale of Two Stories - Laksh Raghavan
Empowering Application Security Protection in the World of DevOps
Application Security at DevOps Speed - DevOpsDays Singapore 2016
Requirements Gathering for a Successful Rugged DevOps Implementation - Hasan ...
DevSecOps - Building Rugged Software
Integrating DevOps and Security
Implementing DevOps in a Regulated Environment - DJ Schleen
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
The Journey to DevSecOps
DevSecOps: Taking a DevOps Approach to Security
DevOps & Security: Here & Now
The Retail Enterprise - And the rise of the omni-present consumer Part 2
Application Secret Management with KMS
Beschikbaar jr. HBO Netwerk/Security/DevOps Engineer
My Little Webap - DevOpsSec is Magic
Devops/Sysops security
Devops security
What's My Security Policy Doing to My Help Desk w/ Chris Swan
Software Security in DevOps: Synthesizing Practitioners’ Perceptions and Prac...
Ad

Similar to DevOps and IT security (20)

PDF
5 principles-securing-devops-veracode-whitepaper
ODP
Dev ops ci-ap-is-oh-my_security-gone-agile_ut-austin
PDF
Fixing security by fixing software development
PPTX
Rooted con 2020 - from the heaven to hell in the CI - CD
PDF
Devops is a Security Requirement
PPTX
Rising Above the Noise: Continuous Integration, Delivery and DevOps
PDF
Faster Secure Software Development with Continuous Deployment - PH Days 2013
PPTX
Secure DevOPS Implementation Guidance
PDF
Devops Interview Question PDF By ScholarHat
PPTX
Securing the continuous integration
PDF
AppSec How-To: Achieving Security in DevOps
PDF
Run stuff, Deploy Stuff, Jax London 2017 Edition
PPTX
Bringing CD to the DoD
PDF
The What, Why, and How of DevSecOps
PPTX
Top 20 Devops Engineer Interview Questions And Answers For 2023 | Devops Tuto...
PPTX
From Continuous Integration to DevOps
PDF
Devops, Secops, Opsec, DevSec *ops *.* ?
PPTX
Testing in the new age of DevOps
PDF
Dev secops opsec, devsec, devops ?
PPTX
BsidesMCR_2016-what-can-infosec-learn-from-devops
5 principles-securing-devops-veracode-whitepaper
Dev ops ci-ap-is-oh-my_security-gone-agile_ut-austin
Fixing security by fixing software development
Rooted con 2020 - from the heaven to hell in the CI - CD
Devops is a Security Requirement
Rising Above the Noise: Continuous Integration, Delivery and DevOps
Faster Secure Software Development with Continuous Deployment - PH Days 2013
Secure DevOPS Implementation Guidance
Devops Interview Question PDF By ScholarHat
Securing the continuous integration
AppSec How-To: Achieving Security in DevOps
Run stuff, Deploy Stuff, Jax London 2017 Edition
Bringing CD to the DoD
The What, Why, and How of DevSecOps
Top 20 Devops Engineer Interview Questions And Answers For 2023 | Devops Tuto...
From Continuous Integration to DevOps
Devops, Secops, Opsec, DevSec *ops *.* ?
Testing in the new age of DevOps
Dev secops opsec, devsec, devops ?
BsidesMCR_2016-what-can-infosec-learn-from-devops
Ad

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Network Security Unit 5.pdf for BCA BBA.
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Machine learning based COVID-19 study performance prediction
PPTX
Big Data Technologies - Introduction.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPT
Teaching material agriculture food technology
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Encapsulation theory and applications.pdf
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Network Security Unit 5.pdf for BCA BBA.
“AI and Expert System Decision Support & Business Intelligence Systems”
Machine learning based COVID-19 study performance prediction
Big Data Technologies - Introduction.pptx
Encapsulation_ Review paper, used for researhc scholars
MIND Revenue Release Quarter 2 2025 Press Release
Teaching material agriculture food technology
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Spectral efficient network and resource selection model in 5G networks
Encapsulation theory and applications.pdf
Mobile App Security Testing_ A Comprehensive Guide.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Programs and apps: productivity, graphics, security and other tools
Diabetes mellitus diagnosis method based random forest with bat algorithm
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
The Rise and Fall of 3GPP – Time for a Sabbatical?

DevOps and IT security

  • 1. DEVOPS = CI + CD + Continuous Security
  • 2. H OW CAN I P USH T H E COD E I N T O P R OD AS EAR LY BY T H I S WEEK EN D M OR E N EW 10 FEAT UR ES T O BE R ELEASED WI T H I N T H E CH R I STM AS H OLI D AY S ! SH ALL I GO FOR P ER FOR M AN CE T EST I NG BEFOR E R ELEASI N G T H E COD E D O I R EALLY N EED R ELEASE AN D BUI LD M AN AGER T O AD D COST I N T O M Y T EAM I N EED T H E AP P LI CAT I ON BUI LD T O BE AUT OM AT I C..GR R R !! I H AD COM M I T TED T H E COD E AGES BACK ! WH ER E I S T H E BUI LD GUY M I SSI N G ? ? 20 15 15 20 25 5 DEVELOPER OH M Y GOD ! H E H AS AGAI N COM E BACK FOR SY ST EM ACCESS HOW DO I ASCER T AI N T HAT T HE COD E I S N OT FUN CT I ONIN G D UE … I N EED T O P AT CH T H E LI N UX SER VER S WI T H T H E BASH VULN ER ABI LI TY … SECUR I TY M EETI NGS ! H OW CAN I H AN D LE SO M AN Y T H I N GS AT ON E … LOG M AN AGEM EN T AN D P ASSWOR D M AN AGEM EN T N EED S I M POR TAN CE I WAN T T O WR I T E R ECI P ES AN D P LAY BOOK S AN D WAN T T O M AK E … 20 10 25 10 20 15 OPERATIONS
  • 3. Security Absorption in DevOps GITHUB Nexus Jenkins TEST ELK SECURITY PenTest the underlying Operating system AppScan using OWASP ZAP scanning Monitor and block on weblayer. Use strict baselining standards23% 49% 78%
  • 4. DEVOPS Continuous Development Business requirements Continuous Security Continuous Integration & Deployment What should be automated What should help ITIL process What should bring Agility What will bring affordability to business How to bring resiliency Which is the way to say No dependencies
  • 5. OLD school Advanced Continuous Integration -Jenkins , CircleCI , Travis CI,Bamboo Continuous Deployment -Chef , puppet , Ansible Continuous Monitoring - Splunk , ELK , Nagios Continuous Security - OWASP ZAP,McAfee,Trend Micro