SlideShare a Scribd company logo
Multilevel Mario
Engineer Challenge
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
Value Stream Architect | DevOps Advocate
@LBMKRISHNA
Pictures Courtesy:
Internet
Super Mario Games (https://www.nintendo.com/)
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
Delivery Teams Expectation to go faster
Funding Traditional– Initiative/Project Focused
Architecture / Design Centralized & Committee Based
Governance Overloaded Documentation, Processes
Risk & Audit Paper/Document/Spread Sheet Based
@LBMKRISHNA
Fill – More
Documents
Fill – More
Templates
Tick – More
Tick Boxes
@LBMKRISHNA
Committee
Approval
Committee
Approval
Committee
Approval
Monthly Quarterly Weekly
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
Equifax: (At least) $575 Million
Home Depot: ~$200 million
Uber: $148 million
Yahoo: $85 million
Capital One: $80 million
Morgan Stanley: $60 million
British Airways: $26.2 million
Tesco Bank: $21 million
Target: $18.5 million
Anthem: $16 million
Ticketmaster: $10 million
Google: $7.5 million
Magecart Attack on Warner Music Group
Target Lost Data on 40 Million Cards
Adobe’s Million Dollar Data Breach
Heartland Payment Systems Loses Processing Privileges
Equifax
https://www.goanywhere.com/blog/the-5-biggest-pci-compliance-breaches
https://www.csoonline.com/article/2130877/the-biggest-data-breaches-of-the-21st-century.html
https://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
- Adrian Cockcroft, Vice President of Cloud
https://d1.awsstatic.com/executive-insights/en_US/ebook-cloud-for-ceos.pdf
@LBMKRISHNA
- Jonathan Smart
https://itrevolution.com/sooner-safer-happier/
@LBMKRISHNA
@LBMKRISHNA
Organizations today are subject to many
regulations governing the protection of
confidential information, financial
accountability, data retention and disaster
recovery, among others. They're also under
pressure from shareholders, stakeholders and
customers.
https://www.cio.com/article
@LBMKRISHNA
“IT governance is the responsibility of executives and
the board of directors, and consists of leadership,
organizational structures, and processes that ensure
that the enterprise’s IT sustains and extends the
organization’s strategies and objectives.”
https://www.architectureandgovernance.com/
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
uilding compliance into development and
operations, and wiring compliance policies and
checks and auditing into Continuous Delivery so that
regulatory compliance becomes an integral part of
how DevOps teams work on a day-to-day basis
Justin Arbuckle
@LBMKRISHNA
@LBMKRISHNA
@LBMKRISHNA
http://dearauditor.org/
@LBMKRISHNA
The team compiled a list of audit concerns
and documented them in a DevOps Risk
Control Matrix with lot of details around
the controls, our practices and evidences
that are collected to support the control.
https://itrevolution.com/devops-audit-defense-toolkit/
@LBMKRISHNA
The goal of the DevOps Audit Defence
Toolkit is to educate IT management and
practitioners on the audit process so they
can demonstrate to auditors they
understand the business risks and are
properly mitigating those risks.
As more and more DevOps practices are
automated, it becomes harder to capture the
data required to ensure all security and
compliance concerns are met. Organizations
need an automated way to track governance
throughout the entire software delivery
process so they can attest to the integrity of all
assets and to the security of all running
applications.
@LBMKRISHNA
https://itrevolution.com/book/devops-automated-governance-
reference-architecture/
@LBMKRISHNA
The intent of this paper is to provide greater
choice and options for corporations to
consume cloud computing services by
automating manual cloud governance
processes. This paper seeks to accelerate
compliance at the speed and scale of
DevOps.
https://www.onug.net/app/uploads/2020/05/ONUG_WP_Automated-
Cloud-Gov_Final.pdf
@LBMKRISHNA
https://medium.com/faun/compliance-as-programming-language-da25f11be9d2
@LBMKRISHNA
Policy-based control for cloud native environments
Flexible, fine-grained control for administrators across the stack
https://www.openpolicyagent.org/
@LBMKRISHNA
https://www.youtube.com/watch?v=7YiFiCGRQto
@LBMKRISHNA
https://www.sonatype.com/referencearchitecturetestdrive
Successful DevSecOps practices encompass people,
processes, tools, and measurement. But where should
you start, how can you validate your existing practices,
or what are the possibilities? Then answer the
following:
•Where can we further automate manual, security, and
business tasks?
•What DevSecOps tools and integrations are others
deploying?
•What interactions do we need to be aware of or map
out?
@LBMKRISHNA
TO RELEASE
Multilevel Mario
Engineer Challenge
@LBMKRISHNA
@LBMKRISHNA

More Related Content

PPTX
DevOps 101 - an Introduction to DevOps
PDF
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
PDF
The Four Keys - Measuring DevOps Success
PDF
DevOps 2016 summit
PPTX
DevOps by examples - Continuous Lifecycle London 2017
ODP
PPTX
Introduction to DevOps
PDF
DevOps: A Culture Transformation, More than Technology
DevOps 101 - an Introduction to DevOps
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
The Four Keys - Measuring DevOps Success
DevOps 2016 summit
DevOps by examples - Continuous Lifecycle London 2017
Introduction to DevOps
DevOps: A Culture Transformation, More than Technology

What's hot (20)

PDF
DevOps: What, who, why and how?
PPTX
Devops skills you got what it takes ?
PDF
Devops at SlideShare: Talk at Devopsdays Bangalore 2011
PPTX
Devops
PDF
DevOps
PDF
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
PPTX
DevOps 101
PPTX
Intro to DevOps
PDF
Introduction to DevOps
PDF
Cloud and Network Transformation using DevOps methodology : Cisco Live 2015
PPTX
The Devops Handbook
PPTX
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
PDF
Introduction to devops - update 2017
PPTX
PPTX
Introduction to devops
PPTX
DevOps Kaizen: Practical Steps to Start & Sustain a Transformation
PDF
What is DevOps
PPTX
CI/CD Best Practices for Your DevOps Journey
PPTX
Introduction to DevOps
PDF
DevOps-Redefining your IT Strategy-28thJan15
DevOps: What, who, why and how?
Devops skills you got what it takes ?
Devops at SlideShare: Talk at Devopsdays Bangalore 2011
Devops
DevOps
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
DevOps 101
Intro to DevOps
Introduction to DevOps
Cloud and Network Transformation using DevOps methodology : Cisco Live 2015
The Devops Handbook
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
Introduction to devops - update 2017
Introduction to devops
DevOps Kaizen: Practical Steps to Start & Sustain a Transformation
What is DevOps
CI/CD Best Practices for Your DevOps Journey
Introduction to DevOps
DevOps-Redefining your IT Strategy-28thJan15
Ad

Similar to A DevOps Mario Developer Game Challenge with GRC (20)

PPTX
The Cloud 9 - Threat & Solutions 2016 by Bobby Dominguez
PPTX
DevSecCon Keynote
PPTX
DevSecCon KeyNote London 2015
PPTX
ISACA Ireland Keynote 2015
PDF
Treating Security Like a Product
PPTX
Keynote at the Cyber Security Summit Prague 2015
PPTX
S360 2015 dev_secops_program
PDF
Security & DevOps - What We Have Here Is a Failure to Communicate!
PDF
Transform your DevOps practices with Security
PPTX
Solnet dev secops meetup
PDF
Detecting Malicious Cloud Account Behavior: A Look at the New Native Platform...
PDF
Webinar–Creating a Modern AppSec Toolchain to Quantify Service Risks
PDF
Threat Modeling in the Cloud
PPTX
Secure Iowa Oct 2016
PDF
Tenants for Going at DevSecOps Speed - LASCON 2023
PPTX
A recommendation for software development responses for future
PDF
The What, Why, and How of DevSecOps
PDF
DevSecOps: Taking a DevOps Approach to Security
PDF
Introduction to DevSecOps
PDF
Security's DevOps Transformation
The Cloud 9 - Threat & Solutions 2016 by Bobby Dominguez
DevSecCon Keynote
DevSecCon KeyNote London 2015
ISACA Ireland Keynote 2015
Treating Security Like a Product
Keynote at the Cyber Security Summit Prague 2015
S360 2015 dev_secops_program
Security & DevOps - What We Have Here Is a Failure to Communicate!
Transform your DevOps practices with Security
Solnet dev secops meetup
Detecting Malicious Cloud Account Behavior: A Look at the New Native Platform...
Webinar–Creating a Modern AppSec Toolchain to Quantify Service Risks
Threat Modeling in the Cloud
Secure Iowa Oct 2016
Tenants for Going at DevSecOps Speed - LASCON 2023
A recommendation for software development responses for future
The What, Why, and How of DevSecOps
DevSecOps: Taking a DevOps Approach to Security
Introduction to DevSecOps
Security's DevOps Transformation
Ad

More from BMK Lakshminarayanan (9)

PDF
Banking On Flow Metrics - Why Flow?
PDF
Overcoming Enterprise Disconnect With Value Streams and Flow Metrics
PDF
Our DevOps Journey is Incomplete Without Data
PDF
DevOps India Summit - Cloud Confusion, DevOps Dilemma, Microservice Madness
PDF
Journey to the Cloud and Beware of the Speed Breakers
PDF
Bnz DevOps Presentation | PluggedIn Session | BMK
PPTX
Banking on Containers - Need for Speed
PPTX
Improving process for agile delivery | BMK | MSD Presentation
PDF
Culture shock DevOps meetup Wellington 27 Sep 2016
Banking On Flow Metrics - Why Flow?
Overcoming Enterprise Disconnect With Value Streams and Flow Metrics
Our DevOps Journey is Incomplete Without Data
DevOps India Summit - Cloud Confusion, DevOps Dilemma, Microservice Madness
Journey to the Cloud and Beware of the Speed Breakers
Bnz DevOps Presentation | PluggedIn Session | BMK
Banking on Containers - Need for Speed
Improving process for agile delivery | BMK | MSD Presentation
Culture shock DevOps meetup Wellington 27 Sep 2016

Recently uploaded (20)

DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Empathic Computing: Creating Shared Understanding
PDF
Approach and Philosophy of On baking technology
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
sap open course for s4hana steps from ECC to s4
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
Big Data Technologies - Introduction.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
KodekX | Application Modernization Development
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
Spectroscopy.pptx food analysis technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
The AUB Centre for AI in Media Proposal.docx
Encapsulation_ Review paper, used for researhc scholars
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Understanding_Digital_Forensics_Presentation.pptx
Programs and apps: productivity, graphics, security and other tools
NewMind AI Weekly Chronicles - August'25 Week I
Spectral efficient network and resource selection model in 5G networks
Empathic Computing: Creating Shared Understanding
Approach and Philosophy of On baking technology
Diabetes mellitus diagnosis method based random forest with bat algorithm
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
sap open course for s4hana steps from ECC to s4
MYSQL Presentation for SQL database connectivity
Unlocking AI with Model Context Protocol (MCP)
Big Data Technologies - Introduction.pptx
Network Security Unit 5.pdf for BCA BBA.
KodekX | Application Modernization Development
MIND Revenue Release Quarter 2 2025 Press Release
Spectroscopy.pptx food analysis technology
The Rise and Fall of 3GPP – Time for a Sabbatical?

A DevOps Mario Developer Game Challenge with GRC