SlideShare a Scribd company logo
COPYRIGHT © 2020 ACCELERATED STRATEGIES GROUP, INC. ALL RIGHTS RESERVED.
Democratizing Security - the next frontier
for DevSecOps adoption in the Enterprise
Sanjeev Sharma, Principal Analyst
• 20+ Years experience in Software Development and Delivery, Cloud
Adoption and Data Modernization
• Led the Data Modernization Practice at Delphix
• Driving the definition of ‘DataOps’ for Application Delivery, and AI and
Machine Learning
• IBM Distinguished Engineer, and IBM’s 1st CTO for DevOps Adoption
owning the DevOps practice
• Chair of the Architecture Review Board for IBM’s response to the
DoD’s JEDI RFP
• Conference Keynote speaker, Blogger, Podcaster and Vlogger
• Author of two bestseller books:
• DevOps For Dummies: https://ibm.biz/BdsPMX
• The DevOps Adoption Playbook: http://amzn.to/2hH7rt2
All about me - Sanjeev Sharma
1. Evolution of Delivery Practices

2. Democratization of Application Delivery

3. Security Chaos Engineering

4. Value Stream Mapping
Agenda
Evolution of Delivery Practices
SRE
Agile
DevOps
Develop right things right
Deliver with speed
Deliver with Reliability
Evolving Application Delivery from Agile to DevOps
Continuous Integration Continuous Delivery
Shift Left Test
Shift Left Ops
Culture
Development SCM Build
Package
Repo Deploy Testing Staging Production FeedbackPlanning Manage
DevOps in a Nutshell:
1. Improve the Application/System being delivered

2. Improve the platform on which it is delivered 

3. Improve the processes by which it is being delivered

4. Improve the culture of the organization delivering it
DevOps
Why DevSecOps?
Security concerns and challenges
are growing
$57M
Google 

GDPR Fine
4700
Breaches 

in 2018
11 Bn
Records
exposed 2018
Becoming a
custodian of user
data is becoming
a differentiator
You are not our product. Our
products are iPhones and
iPads. We treasure your data.
We wanna help you keep it
private and keep it safe.
- Tim Cook, CEO, Apple
Democratization
1874 - Solid Wood 1947 - Laminated Wood 1968 – Steel
Racquet
1993 – Graphite Racquet
2008 – Aerodynamic
Racquet
Democratization of Technology
1. Self-service
2. Permission to act
3. Guardrails
4. Trust
Tenets of Democratizing of IT Services
DevOps: Democratizing the Application Delivery Pipeline
Democratize Infrastructure
Democratize Software Delivery
Democratize Data
Democratize Security
Application Delivery
Practitioners
Democratizing Infrastructure with Cloud
Become Technology Stack
Agnostic
Self-service Provisioning and
Configuration
Infrastructure as Code (IaaC)
Elastic Services for on-demand
scale
Role Based Access Control
Democratize Infrastructure
1. Improve the platform 

2. Improve the processes 

3. Improve the culture
Democratizing Software Delivery with DevSecOps
Become Technology Stack
Agnostic
Make DevSecOps capabilities
Self Service
Integrated end-to-end toolchain
Automated Testing and Validation
Include Security in the
DevSecOps toolchain
Democratize
Software Delivery
1. Improve the Application/System 

2. Improve the processes 

3. Improve the culture
Democratizing Data
Democratize Data
Become Data Source Agnostic
Make Data Available Self
Service
Manage Data Like Code
Mitigate Data Privacy &
Compliance Risks
Include Data Management in
the DevSecOps toolchain
1. Improve the Application/System 

2. Improve the platform 

3. Improve the processes 

4. Improve the culture
Democratizing Security
Become Technology Stack
Agnostic
Make Security* Self Service
Manage Security* Like Code
Automate Mitigation of Security &
Compliance Risks
Include Security* in the DevOps
toolchain
Democratize Security
* Security Implementation, Validation and Enforcement
1. Secure the Application/System 

2. Secure the platform 

3. Secure the processes 

4. Secure the culture
Business Initiatives:
Create New Revenue Streams
Improve Quality
Accelerate Time to Market
Comply with Regulations
The Challenge :
High Complexity
High Cost
Multiple Demands
High Complexity
- Multiple Technology stacks

- On Premises and Cloud

- Departmental Silos

- Legacy, Cloud-native, SaaS
applications and services

- Open-source sprawl
High Cost
- Compliance & Governance
Policies

- Regulatory overhead

- Audit and Compliance
overhead

- Cybersecurity threat
preparedness
Multiple Demands
- Business: Innovation and
Monetization

- Developers: Continuous Delivery

- Analytics Teams: Massive,
diverse data sets

- Security Teams: Lack of talent
and technology expertise
Security Chaos Engineering
One way to make sure you can deal
with a flat tire on the freeway, in the
rain, in the middle of the night is to
poke a hole in your tire once a week
in your driveway on a Sunday
afternoon and go through the drill
of replacing it.
Chaos Engineering
Antifragile: Things that are
neither fragile or robust,
but rather thrive in chaos.
Achieving Antifragility
The Chaos is Real
https://www.sophos.com/en-us/medialibrary/PDFs/Whitepaper/sophos-exposed-cyberattacks-on-cloud-honeypots-wp.pdf
Security Chaos Engineering
Security Chaos Engineering is the
discipline of instrumentation, identification,
and remediation of failure within security
controls through proactive experimentation
to build confidence in the system's ability to
defend against malicious conditions in
production.
Security Chaos Engineering implementation
1. End-to-end Continuous Instrumentation
2. Continuous Readiness Assessment
3. Continuous Security Gap Analysis
4. Automation to identify, detect, and remediate security failures
5. Focus on vulnerability and failure identification
6. Continuous improvement of Operational Readiness
Value Stream Mapping
Idea/Feature/Bug Fix/
Enhancement
Production
Development Build QA SIT UAT Prod
PMO
Requirements/
Analyst
Developer
CustomersLine of Business
Build
Engineer
QA Team Integration Tester User/Tester Operations
Artifact Repository
Deployment Engineer
Release Management
Code Repository
Deploy
Get Feedback
Infrastructure as Code/
Cloud Patterns
Feedback
Customer or
Customer Surrogate
Data
Tasks
Artifacts
Value Stream Mapping
to Identify:
• Waste
• Wait-States
• Rework
Value Stream Mapping to Develop an Adoption Roadmap
• Review the current state
o Business goals, IT goals, current
initiatives
o Requirements
o Environments
o Repositories
o Data Sources/Architecture
o Roles / Organization
o Metrics
o Other
• Prioritize Waste, Wait states and
Rework
• Create a first pass at a roadmap to
address inefficiencies
Next Step: DevOps Value Stream Mapping Workshop
Sanjeev Sharma
sanjeev@accelst.com
@sd_architect
http://sdarchitect.blog
http://accelST.com
Contact
KNOWLEDGE WANTS TO BE FREE
COPYRIGHT © 2020 ACCELERATED STRATEGIES GROUP, INC. ALL RIGHTS RESERVED

More Related Content

PDF
My code, my environment, and yes, my data
PDF
DeliverAgile2018 - from Apollo 13 to Google SRE
PDF
The Muda, Mura and Muri of DevOps
PDF
From Apollo 13 to Google SRE
PDF
Cloud expo 2018: From Apollo 13 to Google SRE - When DevOps meets SRE
PDF
How NBCUniversal Adopted DevOps
PDF
Security and DevOps - Managing Security in a DevOps Enterprise
PPTX
Applying DevOps, PaaS and cloud for better citizen service outcomes - IBM Fe...
My code, my environment, and yes, my data
DeliverAgile2018 - from Apollo 13 to Google SRE
The Muda, Mura and Muri of DevOps
From Apollo 13 to Google SRE
Cloud expo 2018: From Apollo 13 to Google SRE - When DevOps meets SRE
How NBCUniversal Adopted DevOps
Security and DevOps - Managing Security in a DevOps Enterprise
Applying DevOps, PaaS and cloud for better citizen service outcomes - IBM Fe...

What's hot (20)

PDF
Hybrid Cloud DevOps with Apprenda and UrbanCode Deploy
PDF
A DevOps adoption playbook- achieving business value at scale
PDF
Mastering DevOps Automation: Webinar
PDF
DevOps in the Hybrid Cloud
PDF
The Future of DevOps and UrbanCode
PDF
Bluemix DevOps Meetup
PPTX
Gartner EA Architecting for DevOps and Hybrid Cloud
PPTX
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
PDF
DevOps Thinking for the Line of Business
PDF
Elevate Your Continuous Delivery Strategy Above the Rolling Clouds (Interconn...
PDF
Cloud Native Operations
PPTX
Troubleshooting App Health and Performance with PCF Metrics 1.2
PPTX
Cloud With DevOps Enabling Rapid Business Development
PDF
Metrics That Matter: How to Measure Digital Transformation Success
PPTX
DevOps For Everyone: Bringing DevOps Success to Every App and Every Role in y...
PDF
Continuous Delivery for cloud - scenarios and scope
PDF
Lo Scenario Cloud-Native (Pivotal Cloud-Native Workshop: Milan)
PDF
Accelerating Time to Market
PDF
IBM DevOps Workshops at IBM InterConnect 2017
PDF
Keynote: Architecting for Continuous Delivery (Pivotal Cloud Platform Roadshow)
Hybrid Cloud DevOps with Apprenda and UrbanCode Deploy
A DevOps adoption playbook- achieving business value at scale
Mastering DevOps Automation: Webinar
DevOps in the Hybrid Cloud
The Future of DevOps and UrbanCode
Bluemix DevOps Meetup
Gartner EA Architecting for DevOps and Hybrid Cloud
Driving Enterprise Architecture Redesign: Cloud-Native Platforms, APIs, and D...
DevOps Thinking for the Line of Business
Elevate Your Continuous Delivery Strategy Above the Rolling Clouds (Interconn...
Cloud Native Operations
Troubleshooting App Health and Performance with PCF Metrics 1.2
Cloud With DevOps Enabling Rapid Business Development
Metrics That Matter: How to Measure Digital Transformation Success
DevOps For Everyone: Bringing DevOps Success to Every App and Every Role in y...
Continuous Delivery for cloud - scenarios and scope
Lo Scenario Cloud-Native (Pivotal Cloud-Native Workshop: Milan)
Accelerating Time to Market
IBM DevOps Workshops at IBM InterConnect 2017
Keynote: Architecting for Continuous Delivery (Pivotal Cloud Platform Roadshow)
Ad

Similar to Democratizing security (20)

PDF
The What, Why, and How of DevSecOps
PPTX
Achieving Secure DevOps: Overcoming the Risks of Modern Service Delivery
PDF
Introduction to DevOps slides.pdf
PPTX
DevSecOps Story with added security controls
PPTX
Shift Left for More Secure Apps with F5 NGINX
PDF
Velocity Conference NYC 2014 - Real World DevOps
PDF
Protecting Agile Transformation through Secure DevOps (DevSecOps)
PDF
The Rise of DevSecOps in CI_CD Workflows.pdf
PDF
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
PPTX
State of DevSecOps - DevSecOpsDays 2019
PPTX
Data Agility for Enterprise DevOps Adoption
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
PDF
Devops, Secops, Opsec, DevSec *ops *.* ?
PPTX
Devsec ops
PPT
Applying DevOps for more reliable Public Sector Software Delivery
PDF
2021-10-14 The Critical Role of Security in DevOps.pdf
PPTX
Introduction to DevSecOps
PDF
IBM Innovate - Uderstanding DevOps
PDF
DevSecOps - The big picture
PDF
DevSecOps - The big picture
The What, Why, and How of DevSecOps
Achieving Secure DevOps: Overcoming the Risks of Modern Service Delivery
Introduction to DevOps slides.pdf
DevSecOps Story with added security controls
Shift Left for More Secure Apps with F5 NGINX
Velocity Conference NYC 2014 - Real World DevOps
Protecting Agile Transformation through Secure DevOps (DevSecOps)
The Rise of DevSecOps in CI_CD Workflows.pdf
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
State of DevSecOps - DevSecOpsDays 2019
Data Agility for Enterprise DevOps Adoption
Why Security Engineer Need Shift-Left to DevSecOps?
Devops, Secops, Opsec, DevSec *ops *.* ?
Devsec ops
Applying DevOps for more reliable Public Sector Software Delivery
2021-10-14 The Critical Role of Security in DevOps.pdf
Introduction to DevSecOps
IBM Innovate - Uderstanding DevOps
DevSecOps - The big picture
DevSecOps - The big picture
Ad

More from Sanjeev Sharma (18)

PDF
From DevOps to DevSecOps: 2 Dimensions of Security for DevOps
PDF
Unicorns on an Aircraft Carrier: CDSummit London and Stockholm Keynote
PDF
IBM InterConnect 2016: Security for DevOps in an Enterprise
PDF
DevOps adoption in the enterprise
PDF
dev@InterConnect workshop - Lean and DevOps
PPTX
OpenTechSummit InterConnect2015 DevOps
PDF
DTS-1778 Understanding DevOps - IBM InterConnect Session
PDF
Mobile to Mainframe - En-to-end transformation
PDF
DevOps and Application Delivery for Hybrid Cloud - DevOpsSummit session
PDF
Using Lean Thinking to identify and address Delivery Pipeline bottlenecks
PPTX
DevOps 101 - IBM Impact 2014
PPT
Enabling DevOps in the cloud - Federal Cloud Innovation Center
PPT
Continuous Delivery to the cloud - Innovate 2014
PDF
CampDevOps keynote - DevOps: Using 'Lean' to eliminate Bottlenecks
PPT
IBM Pulse session 2727: Continuous delivery -accelerated with DevOps
PPTX
Mobile to mainframe - Enterprise DevOps - MoDevEast Slides
PPT
(Japanese) From Continuous Integration to DevOps - Japan Innovate 2013
PPTX
From Continuous Integration to DevOps - Japan Innovate 2013
From DevOps to DevSecOps: 2 Dimensions of Security for DevOps
Unicorns on an Aircraft Carrier: CDSummit London and Stockholm Keynote
IBM InterConnect 2016: Security for DevOps in an Enterprise
DevOps adoption in the enterprise
dev@InterConnect workshop - Lean and DevOps
OpenTechSummit InterConnect2015 DevOps
DTS-1778 Understanding DevOps - IBM InterConnect Session
Mobile to Mainframe - En-to-end transformation
DevOps and Application Delivery for Hybrid Cloud - DevOpsSummit session
Using Lean Thinking to identify and address Delivery Pipeline bottlenecks
DevOps 101 - IBM Impact 2014
Enabling DevOps in the cloud - Federal Cloud Innovation Center
Continuous Delivery to the cloud - Innovate 2014
CampDevOps keynote - DevOps: Using 'Lean' to eliminate Bottlenecks
IBM Pulse session 2727: Continuous delivery -accelerated with DevOps
Mobile to mainframe - Enterprise DevOps - MoDevEast Slides
(Japanese) From Continuous Integration to DevOps - Japan Innovate 2013
From Continuous Integration to DevOps - Japan Innovate 2013

Recently uploaded (20)

PDF
Modernizing your data center with Dell and AMD
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Advanced IT Governance
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Approach and Philosophy of On baking technology
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
cuic standard and advanced reporting.pdf
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
Big Data Technologies - Introduction.pptx
PDF
Empathic Computing: Creating Shared Understanding
PDF
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...
Modernizing your data center with Dell and AMD
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Chapter 3 Spatial Domain Image Processing.pdf
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Advanced IT Governance
Dropbox Q2 2025 Financial Results & Investor Presentation
Approach and Philosophy of On baking technology
Review of recent advances in non-invasive hemoglobin estimation
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Diabetes mellitus diagnosis method based random forest with bat algorithm
“AI and Expert System Decision Support & Business Intelligence Systems”
20250228 LYD VKU AI Blended-Learning.pptx
cuic standard and advanced reporting.pdf
GamePlan Trading System Review: Professional Trader's Honest Take
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Big Data Technologies - Introduction.pptx
Empathic Computing: Creating Shared Understanding
GDG Cloud Iasi [PUBLIC] Florian Blaga - Unveiling the Evolution of Cybersecur...

Democratizing security

  • 1. COPYRIGHT © 2020 ACCELERATED STRATEGIES GROUP, INC. ALL RIGHTS RESERVED. Democratizing Security - the next frontier for DevSecOps adoption in the Enterprise Sanjeev Sharma, Principal Analyst
  • 2. • 20+ Years experience in Software Development and Delivery, Cloud Adoption and Data Modernization • Led the Data Modernization Practice at Delphix • Driving the definition of ‘DataOps’ for Application Delivery, and AI and Machine Learning • IBM Distinguished Engineer, and IBM’s 1st CTO for DevOps Adoption owning the DevOps practice • Chair of the Architecture Review Board for IBM’s response to the DoD’s JEDI RFP • Conference Keynote speaker, Blogger, Podcaster and Vlogger • Author of two bestseller books: • DevOps For Dummies: https://ibm.biz/BdsPMX • The DevOps Adoption Playbook: http://amzn.to/2hH7rt2 All about me - Sanjeev Sharma
  • 3. 1. Evolution of Delivery Practices 2. Democratization of Application Delivery 3. Security Chaos Engineering 4. Value Stream Mapping Agenda
  • 5. SRE Agile DevOps Develop right things right Deliver with speed Deliver with Reliability Evolving Application Delivery from Agile to DevOps
  • 6. Continuous Integration Continuous Delivery Shift Left Test Shift Left Ops Culture Development SCM Build Package Repo Deploy Testing Staging Production FeedbackPlanning Manage DevOps in a Nutshell: 1. Improve the Application/System being delivered 2. Improve the platform on which it is delivered 3. Improve the processes by which it is being delivered 4. Improve the culture of the organization delivering it DevOps
  • 7. Why DevSecOps? Security concerns and challenges are growing $57M Google GDPR Fine 4700 Breaches in 2018 11 Bn Records exposed 2018 Becoming a custodian of user data is becoming a differentiator You are not our product. Our products are iPhones and iPads. We treasure your data. We wanna help you keep it private and keep it safe. - Tim Cook, CEO, Apple
  • 9. 1874 - Solid Wood 1947 - Laminated Wood 1968 – Steel Racquet 1993 – Graphite Racquet 2008 – Aerodynamic Racquet Democratization of Technology
  • 10. 1. Self-service 2. Permission to act 3. Guardrails 4. Trust Tenets of Democratizing of IT Services
  • 11. DevOps: Democratizing the Application Delivery Pipeline Democratize Infrastructure Democratize Software Delivery Democratize Data Democratize Security Application Delivery Practitioners
  • 12. Democratizing Infrastructure with Cloud Become Technology Stack Agnostic Self-service Provisioning and Configuration Infrastructure as Code (IaaC) Elastic Services for on-demand scale Role Based Access Control Democratize Infrastructure 1. Improve the platform 2. Improve the processes 3. Improve the culture
  • 13. Democratizing Software Delivery with DevSecOps Become Technology Stack Agnostic Make DevSecOps capabilities Self Service Integrated end-to-end toolchain Automated Testing and Validation Include Security in the DevSecOps toolchain Democratize Software Delivery 1. Improve the Application/System 2. Improve the processes 3. Improve the culture
  • 14. Democratizing Data Democratize Data Become Data Source Agnostic Make Data Available Self Service Manage Data Like Code Mitigate Data Privacy & Compliance Risks Include Data Management in the DevSecOps toolchain 1. Improve the Application/System 2. Improve the platform 3. Improve the processes 4. Improve the culture
  • 15. Democratizing Security Become Technology Stack Agnostic Make Security* Self Service Manage Security* Like Code Automate Mitigation of Security & Compliance Risks Include Security* in the DevOps toolchain Democratize Security * Security Implementation, Validation and Enforcement 1. Secure the Application/System 2. Secure the platform 3. Secure the processes 4. Secure the culture
  • 16. Business Initiatives: Create New Revenue Streams Improve Quality Accelerate Time to Market Comply with Regulations The Challenge : High Complexity High Cost Multiple Demands High Complexity - Multiple Technology stacks - On Premises and Cloud - Departmental Silos - Legacy, Cloud-native, SaaS applications and services - Open-source sprawl High Cost - Compliance & Governance Policies - Regulatory overhead - Audit and Compliance overhead - Cybersecurity threat preparedness Multiple Demands - Business: Innovation and Monetization - Developers: Continuous Delivery - Analytics Teams: Massive, diverse data sets - Security Teams: Lack of talent and technology expertise
  • 18. One way to make sure you can deal with a flat tire on the freeway, in the rain, in the middle of the night is to poke a hole in your tire once a week in your driveway on a Sunday afternoon and go through the drill of replacing it. Chaos Engineering
  • 19. Antifragile: Things that are neither fragile or robust, but rather thrive in chaos. Achieving Antifragility
  • 20. The Chaos is Real https://www.sophos.com/en-us/medialibrary/PDFs/Whitepaper/sophos-exposed-cyberattacks-on-cloud-honeypots-wp.pdf
  • 21. Security Chaos Engineering Security Chaos Engineering is the discipline of instrumentation, identification, and remediation of failure within security controls through proactive experimentation to build confidence in the system's ability to defend against malicious conditions in production.
  • 22. Security Chaos Engineering implementation 1. End-to-end Continuous Instrumentation 2. Continuous Readiness Assessment 3. Continuous Security Gap Analysis 4. Automation to identify, detect, and remediate security failures 5. Focus on vulnerability and failure identification 6. Continuous improvement of Operational Readiness
  • 24. Idea/Feature/Bug Fix/ Enhancement Production Development Build QA SIT UAT Prod PMO Requirements/ Analyst Developer CustomersLine of Business Build Engineer QA Team Integration Tester User/Tester Operations Artifact Repository Deployment Engineer Release Management Code Repository Deploy Get Feedback Infrastructure as Code/ Cloud Patterns Feedback Customer or Customer Surrogate Data Tasks Artifacts Value Stream Mapping to Identify: • Waste • Wait-States • Rework Value Stream Mapping to Develop an Adoption Roadmap
  • 25. • Review the current state o Business goals, IT goals, current initiatives o Requirements o Environments o Repositories o Data Sources/Architecture o Roles / Organization o Metrics o Other • Prioritize Waste, Wait states and Rework • Create a first pass at a roadmap to address inefficiencies Next Step: DevOps Value Stream Mapping Workshop
  • 27. KNOWLEDGE WANTS TO BE FREE COPYRIGHT © 2020 ACCELERATED STRATEGIES GROUP, INC. ALL RIGHTS RESERVED