SlideShare a Scribd company logo
DevSecOps – London Gathering
4th July 2018
TONIGHT’S PRESENTATION
“Bringing Rapid Prototyping To The Threat Model Process”
Geoffrey Hill
@Tutamantic_Sec
geoff@tutamantic.com
WAYS TO STAY IN TOUCH
https://www.meetup.com/DevSecOps-London-Gathering
https://twitter.com/DevSecOps_LG
https://www.linkedin.com/groups/8630205
THE JOURNEY SO FAR … 1
• September 2017
• DevSecOps Engineer
http://slides.com/chossrutter/securing#/17
• Project Management Experience: Security in Agile
https://www.slideshare.net/MichaelMan11/project-management-experience-security-in-agile-1309
• October 2017
• Practical Threat Modelling
http://slides.com/chossrutter/securing-6
• Threat Modelling Automation
http://slides.com/mattjoyce/automatetm#/
• December 2017
• Security Automation in DevOps
https://www.slideshare.net/MichaelMan11/dev-secops-testautomation
https://www.slideshare.net/MichaelMan11/dynaminet-devsecops
THE JOURNEY SO FAR … 2
• February 2018
• DevSecOps: The Evolution of DevOps
https://www.slideshare.net/MichaelMan11/devsecops-the-evolution-of-devops
• March 2018
• The mechanics behind how attackers exploit simple programming mistakes
https://www.slideshare.net/MichaelMan11/the-mechanics-behind-how-attackers-exploit-simple-
programming-mistakes
• April 2018
Secret Dragons – Harder To Execute
• https://www.slideshare.net/MichaelMan11/vulnerability-management-in-devsecops-easy-
concept-but-harder-to-execute
• https://www.slideshare.net/MichaelMan11/secret-management-journey-here-be-dragons-aka-
secret-dragons
THE JOURNEY SO FAR … 3
• May 2018
• Continuous Security: From tins to containers - now what!
https://www.slideshare.net/MichaelMan11/continuous-security-from-tins-to-containers-now-what
• June 2018
• The Bastion Server That Isn't There ...
https://www.slideshare.net/MichaelMan11/the-bastion-server-that-isnt-there-joshua-kite
• July 2018
• Scale Security For A Dollar Or Less
https://www.slideshare.net/secfigo/scale-security-for-a-dollar-or-less/
• Threat Modelling: The Ultimate DevSecOps
https://speakerdeck.com/zeroxten/threat-modeling-the-ultimate-devsecops
• Practical Steps For Securing Containers
https://www.slideshare.net/MichaelMan11/practical-steps-for-securing-containers-liz-rice
WHAT’S HAPPENING IN SEPTEMBER
1200 – Doors Open: Location CONFIRMED
Session 1
1230 - Culture, People and Workflow CONFIRMED
1330 - Real life experience implementing SAST – MM J CONFIRMED
1430 - Refreshments & Network
Session 2
1500 - Repeat A Past Presentation CONFIRMED
1600 – Supporters of this community (30min each) CONFIRMED
Session 3
1730 - Food & Network
1800 - DevSecOps Maturity 1 CONFIRMED
1845 - DevSecOps Maturity 2
1930 - DevSecOps Maturity 3
CLOSING
2015 - Network
2100 - Crash the other conference J
DISCOUNTS: CONFERENCES
20% Off
Discount Code: PCDSOL20
DevSecOps – People & Culture
• Break down the silo; no change here, just like the original DevOps movement
• Not aware of what is going on – likely you are not part of the “DevSecOps” team; leave
your ivory tower and build relationships
• Conduct a Value Stream Mapping exercise to optimize your delivery (rinse and repeat)
• Drill down and sketch out the details of each workflow before solutionising
• Try new checks/controls as part of the pipeline
IDE Static Code
Analysis
SCM
Dynamic
Analysis
Open Source
Software Security
Security Testing
Framework
Binary
Repository
Define Security
Test Cases
Threat
Modeling
Security
Standards
Automation Tools:
Passing Criteria
Risk
Management
Out of Band
Security Testing
Security
Champions
DevSecOps
Engineer
Security Audit
Artifacts
CI Build Server
DevSecOps – Tooling & Assurance Examples (Shift Left)
curl
nmap
sslyze
sqlmap
Interactive
Testing
Reporting
Dashboard
Infrastructure
Assurance
Threat
Modeling
Dev Workstation Build Server
Centralize Report (Vulnerability Management) Server
SCM
Static Code Analysis
(SAST)
Dynamic Testing
(DAST)
Interactive Testing
(IAST)
Open Source Component Security
Manual Penetration Testing – Out of Band
Scope: Application and Network layer – White/Black box
Defect
Management
AUTOMATION
INTEGRATION POINTS
SECURITYASSURANCEMODEL
Legend
Black Box: Development Stack
Blue Box: Automation - Integration
Red Box: Security Tools and Controls
Infrastructure Scanning
REMINDER – I KEEP FORGETTING
• Are you a Developer
• Are you from Security
• Are you from Operations
• Other roles
• First time here at The Gathering
• Take a group picture
• What other prizes or stuff would you like

More Related Content

PDF
A Secure DevOps Journey
PDF
Painless DevSecOps: Building Security Into Your DevOps Pipeline
PDF
DevSecOps - The big picture
PPTX
Be a User first; then a Tester
PPTX
ATAGTR2017 Security Test Driven Development (STDD)
PDF
Ast in CI/CD by Ofer Maor
PDF
Dev secops. Real experience.
PDF
NodeJS security - still unsafe at most speeds - v1.0
A Secure DevOps Journey
Painless DevSecOps: Building Security Into Your DevOps Pipeline
DevSecOps - The big picture
Be a User first; then a Tester
ATAGTR2017 Security Test Driven Development (STDD)
Ast in CI/CD by Ofer Maor
Dev secops. Real experience.
NodeJS security - still unsafe at most speeds - v1.0

What's hot (20)

PPTX
ATAGTR2017 Test the REST
PPTX
Dev secops security and compliance at the speed of continuous delivery - owasp
PDF
Design Microservice Architectures the Right Way
PDF
Integrating DevOps and Security
PPTX
ATAGTR2017 Performance Automation in Dev-Ops
PDF
NYC Continuous Delivery Meetup - Introducing delta
PDF
Production - Designing for Testability
PDF
Security in a Continuous Delivery World
PPTX
SecDevOps: The New Black of IT
PPT
Sri monthly presentation 2015
PPT
Sri monthly presentation 2016
PPTX
DevOps Fest 2020. Kohsuke Kawaguchi. GitOps, Jenkins X & the Future of CI/CD
PPTX
DevSecOps
PDF
You build it - Cyber Chicago Keynote
PPTX
ATAGTR2017 Machine Learning telepathy for Shift Right approach of testing
PPTX
Automated Testing in Continuous Change Management
PPTX
DevOps Friendly Doc Publishing for APIs & Microservices
PDF
Embracing the Rise of SecDevOps
PDF
Git in the Enterprise: How to succeed at DevOps using Git and a monorepo
PPTX
DevOps and All the Continuouses w/ Helen Beal
ATAGTR2017 Test the REST
Dev secops security and compliance at the speed of continuous delivery - owasp
Design Microservice Architectures the Right Way
Integrating DevOps and Security
ATAGTR2017 Performance Automation in Dev-Ops
NYC Continuous Delivery Meetup - Introducing delta
Production - Designing for Testability
Security in a Continuous Delivery World
SecDevOps: The New Black of IT
Sri monthly presentation 2015
Sri monthly presentation 2016
DevOps Fest 2020. Kohsuke Kawaguchi. GitOps, Jenkins X & the Future of CI/CD
DevSecOps
You build it - Cyber Chicago Keynote
ATAGTR2017 Machine Learning telepathy for Shift Right approach of testing
Automated Testing in Continuous Change Management
DevOps Friendly Doc Publishing for APIs & Microservices
Embracing the Rise of SecDevOps
Git in the Enterprise: How to succeed at DevOps using Git and a monorepo
DevOps and All the Continuouses w/ Helen Beal
Ad

Similar to August 2018: DevSecOps - London Gathering (20)

PPTX
Extract Oct 2019: DSO-LG Rolling Slides
PDF
SecDevOps Risk Workflow - v0.6
PDF
DevSecOps - Background, Status and Future Challenges
PPTX
Dev{sec}ops
PPTX
Cross Platform Angular 2 and TypeScript Development
PPTX
DevSecOps Story with added security controls
PDF
DevSecOps - The big picture
PPTX
Security for developers
PDF
Threat Modelling in DevSecOps Cultures
PPTX
Threat Modeling All Day!
PDF
Weaponizing Your DevOps Pipeline
PDF
Devops security-An Insight into Secure-SDLC
PPTX
Alexey Sintsov- SDLC - try me to implement
PDF
Scale security for a dollar or less
PDF
Strengthen and Scale Security for a dollar or less
PDF
Modern Web 2019 從零開始加入自動化資安測試
PPTX
DevSecOps - London Gathering : June 2018
PDF
Scaling security in a cloud environment v0.5 (Sep 2017)
PDF
AI-assisted development: how to build and ship with confidence
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Extract Oct 2019: DSO-LG Rolling Slides
SecDevOps Risk Workflow - v0.6
DevSecOps - Background, Status and Future Challenges
Dev{sec}ops
Cross Platform Angular 2 and TypeScript Development
DevSecOps Story with added security controls
DevSecOps - The big picture
Security for developers
Threat Modelling in DevSecOps Cultures
Threat Modeling All Day!
Weaponizing Your DevOps Pipeline
Devops security-An Insight into Secure-SDLC
Alexey Sintsov- SDLC - try me to implement
Scale security for a dollar or less
Strengthen and Scale Security for a dollar or less
Modern Web 2019 從零開始加入自動化資安測試
DevSecOps - London Gathering : June 2018
Scaling security in a cloud environment v0.5 (Sep 2017)
AI-assisted development: how to build and ship with confidence
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Ad

More from Michael Man (20)

PPTX
5 things i wish i knew about sast (DSO-LG July 2021)
PDF
K8S Certifications - Exam Cram
PDF
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
PDF
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PPTX
Sept 2019 - DSO-LG Tooling Examples
PPTX
DevSecOps Manchester - May 2019
PDF
Chris Rutter: Avoiding The Security Brick
PPTX
Extract: DevSecOps - London Gathering (March 2019)
PDF
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
PDF
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
PDF
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
PDF
Continuous Security: From tins to containers - now what!
PDF
The mechanics behind how attackers exploit simple programming mistakes ...
PDF
Secret Management Journey - Here Be Dragons aka Secret Dragons
PPTX
DevSecOps March 2018 - Extract
PDF
DevSecOps The Evolution of DevOps
PDF
Dynaminet -DevSecOps
PPTX
DevSecOps: Test Automation
PPTX
Project management experience security in agile 1309
5 things i wish i knew about sast (DSO-LG July 2021)
K8S Certifications - Exam Cram
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Sept 2019 - DSO-LG Tooling Examples
DevSecOps Manchester - May 2019
Chris Rutter: Avoiding The Security Brick
Extract: DevSecOps - London Gathering (March 2019)
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
Continuous Security: From tins to containers - now what!
The mechanics behind how attackers exploit simple programming mistakes ...
Secret Management Journey - Here Be Dragons aka Secret Dragons
DevSecOps March 2018 - Extract
DevSecOps The Evolution of DevOps
Dynaminet -DevSecOps
DevSecOps: Test Automation
Project management experience security in agile 1309

Recently uploaded (20)

PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPT
Teaching material agriculture food technology
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Electronic commerce courselecture one. Pdf
PDF
Machine learning based COVID-19 study performance prediction
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
KodekX | Application Modernization Development
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
NewMind AI Weekly Chronicles - August'25 Week I
Digital-Transformation-Roadmap-for-Companies.pptx
Teaching material agriculture food technology
The AUB Centre for AI in Media Proposal.docx
Encapsulation_ Review paper, used for researhc scholars
Chapter 3 Spatial Domain Image Processing.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Electronic commerce courselecture one. Pdf
Machine learning based COVID-19 study performance prediction
Per capita expenditure prediction using model stacking based on satellite ima...
KodekX | Application Modernization Development
The Rise and Fall of 3GPP – Time for a Sabbatical?
MYSQL Presentation for SQL database connectivity
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
20250228 LYD VKU AI Blended-Learning.pptx
CIFDAQ's Market Insight: SEC Turns Pro Crypto
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
NewMind AI Weekly Chronicles - August'25 Week I

August 2018: DevSecOps - London Gathering

  • 1. DevSecOps – London Gathering 4th July 2018
  • 2. TONIGHT’S PRESENTATION “Bringing Rapid Prototyping To The Threat Model Process” Geoffrey Hill @Tutamantic_Sec geoff@tutamantic.com
  • 3. WAYS TO STAY IN TOUCH https://www.meetup.com/DevSecOps-London-Gathering https://twitter.com/DevSecOps_LG https://www.linkedin.com/groups/8630205
  • 4. THE JOURNEY SO FAR … 1 • September 2017 • DevSecOps Engineer http://slides.com/chossrutter/securing#/17 • Project Management Experience: Security in Agile https://www.slideshare.net/MichaelMan11/project-management-experience-security-in-agile-1309 • October 2017 • Practical Threat Modelling http://slides.com/chossrutter/securing-6 • Threat Modelling Automation http://slides.com/mattjoyce/automatetm#/ • December 2017 • Security Automation in DevOps https://www.slideshare.net/MichaelMan11/dev-secops-testautomation https://www.slideshare.net/MichaelMan11/dynaminet-devsecops
  • 5. THE JOURNEY SO FAR … 2 • February 2018 • DevSecOps: The Evolution of DevOps https://www.slideshare.net/MichaelMan11/devsecops-the-evolution-of-devops • March 2018 • The mechanics behind how attackers exploit simple programming mistakes https://www.slideshare.net/MichaelMan11/the-mechanics-behind-how-attackers-exploit-simple- programming-mistakes • April 2018 Secret Dragons – Harder To Execute • https://www.slideshare.net/MichaelMan11/vulnerability-management-in-devsecops-easy- concept-but-harder-to-execute • https://www.slideshare.net/MichaelMan11/secret-management-journey-here-be-dragons-aka- secret-dragons
  • 6. THE JOURNEY SO FAR … 3 • May 2018 • Continuous Security: From tins to containers - now what! https://www.slideshare.net/MichaelMan11/continuous-security-from-tins-to-containers-now-what • June 2018 • The Bastion Server That Isn't There ... https://www.slideshare.net/MichaelMan11/the-bastion-server-that-isnt-there-joshua-kite • July 2018 • Scale Security For A Dollar Or Less https://www.slideshare.net/secfigo/scale-security-for-a-dollar-or-less/ • Threat Modelling: The Ultimate DevSecOps https://speakerdeck.com/zeroxten/threat-modeling-the-ultimate-devsecops • Practical Steps For Securing Containers https://www.slideshare.net/MichaelMan11/practical-steps-for-securing-containers-liz-rice
  • 7. WHAT’S HAPPENING IN SEPTEMBER 1200 – Doors Open: Location CONFIRMED Session 1 1230 - Culture, People and Workflow CONFIRMED 1330 - Real life experience implementing SAST – MM J CONFIRMED 1430 - Refreshments & Network Session 2 1500 - Repeat A Past Presentation CONFIRMED 1600 – Supporters of this community (30min each) CONFIRMED Session 3 1730 - Food & Network 1800 - DevSecOps Maturity 1 CONFIRMED 1845 - DevSecOps Maturity 2 1930 - DevSecOps Maturity 3 CLOSING 2015 - Network 2100 - Crash the other conference J
  • 9. DevSecOps – People & Culture • Break down the silo; no change here, just like the original DevOps movement • Not aware of what is going on – likely you are not part of the “DevSecOps” team; leave your ivory tower and build relationships • Conduct a Value Stream Mapping exercise to optimize your delivery (rinse and repeat) • Drill down and sketch out the details of each workflow before solutionising • Try new checks/controls as part of the pipeline
  • 10. IDE Static Code Analysis SCM Dynamic Analysis Open Source Software Security Security Testing Framework Binary Repository Define Security Test Cases Threat Modeling Security Standards Automation Tools: Passing Criteria Risk Management Out of Band Security Testing Security Champions DevSecOps Engineer Security Audit Artifacts CI Build Server DevSecOps – Tooling & Assurance Examples (Shift Left) curl nmap sslyze sqlmap Interactive Testing Reporting Dashboard Infrastructure Assurance Threat Modeling
  • 11. Dev Workstation Build Server Centralize Report (Vulnerability Management) Server SCM Static Code Analysis (SAST) Dynamic Testing (DAST) Interactive Testing (IAST) Open Source Component Security Manual Penetration Testing – Out of Band Scope: Application and Network layer – White/Black box Defect Management AUTOMATION INTEGRATION POINTS SECURITYASSURANCEMODEL Legend Black Box: Development Stack Blue Box: Automation - Integration Red Box: Security Tools and Controls Infrastructure Scanning
  • 12. REMINDER – I KEEP FORGETTING • Are you a Developer • Are you from Security • Are you from Operations • Other roles • First time here at The Gathering • Take a group picture • What other prizes or stuff would you like