SlideShare a Scribd company logo
DevOps and the Future of Information
Security
Darin Morris
@techdevdari
n
in/darinmorris
2018
In General:
What we’re going talk about
2. How “doing DevOps” affects how we
secure Data and Computer-centric
Information Systems
In Particular:
1. What it really means to do DevOps
Thoughts I’ve had around DevOps and Security
Motivation for this talk
• I want “information technology practitioners” to become more professional, more productive and
happier at work.
Many reasons, but some of the more major reasons are:
• Information systems need to be of higher quality and delivered faster – we need to really
understand the DevOps philosophy to do that well.
• Security is often an afterthought in the IT systems lifecycle – that needs to change.
• We need a common, meaningful language – not buzzwords!
DevOps and the Future of Information Security
DevOps and Security are
very broad domains!
So can we cover enough in
only 35 minutes?!
SOMEONE ONCE TOLD ME NOT TO BITE
OFF MORE THAN I COULD CHEW…
I said I’d rather
CHOKE ON GREATNESS
THAN NIBBLE ON
MEDIOCRITY.
Let’s get to know each
other a little better!
Sales or Relationship
Management
Does this sound like your role?
Marketing Finance Leadership (C-Suite)
Human Resources
Business Analyst / Big
Data Analyst General Administrator In-house Legal
Project Manager or
Coordinator Product Manager/Owner Software Architect Software Engineer
Test Engineer
Provision and Manage
IT Infrastructure (IT Ops)
Does this sound like your role?
Dedicated Security or
Compliance Something else?
?
OK! Less about you.
More about me!
Fun facts about me
Most used programming languages:
C#, JavaScript
“SiliconCape Native”
First PC: Pentium 1 with
Windows 95
First programming language: Java (JDK 1.3)
Professional background
• I’m a self-taught “Technologist” and I solve problems using
technology.
• I've been a founder, manager, team lead and software engineer,
in various sectors, and in teams of different shapes and sizes.
• Microsoft Certified Professional
• Certified ScrumMaster
• In the process of completing CSSLP, ITIL and ISTQB certifications.
• Member of a number of professional IT associations and
bodies i.e. OWASP, ISACA, IITPSA
• Fulltime full stack software engineer for the past 13 years,
primarily focussed on web and cloud-native software.
Let’s play a game!
True or False?
DevOps is only done by
technical staff.
Question #1
True or False?
DevOps is a Role.
Question #2
True or False?
DevOps is a way of thinking
about how we do work.
Question #3
What is DevOps really?
DevOps and the Future of Information Security
• DevOps Principles and Practices are compatible with Agile
• DevOps is a logical continuation of Agile
• Agile serves as an effective enabler of DevOps
Myth #1: DevOps replaces Agile
• Can be made compatible - many
areas just become automated.
Myth #2: DevOps is incompatible with ITIL
• Controls are
integrated into
every stage of
daily work of the
SDLC resulting in
better quality and
security and
compliance
outcomes.
Myth #3: DevOps is incompatible with InfoSec and Compliance
Image credit: Checkmarx Software Exposure platform (www.checkmarx.com)
• Rarely the case. Nature of IT Operations work just
changes.
• Collaborates far earlier in SDLC with development.
• Enables developer productivity through APIs and
self-service platforms that create environments, test
and deploy code, monitor and display production
telemetry, etc.
• IT Ops become more like Development
• i.e. engaged in product development for developers.
Myth #4: DevOps means eliminating IT Operations
• “DevOps isn’t about
automation, just as astronomy
isn’t about telescopes” -
Christopher Little
Myth #5: DevOps is just Infrastructure as Code
DevOps is about Team Work
that enables efficient creation of value
What DevOp really boils down to
So, how is Security
affected?
Security and DevOps - DevSecOps?
• Security is fundamentally about mitigating risk
(you’ll never be 100% secure).
• Mitigating risk is enabled by maintaining
integrity, availability and confidentially.
• Security principles haven’t changed, the way
we implement security has.
Security
Fail Securely
Minimize attack
surface
Least
Privilege
Integrity
Auditing
Keep Things Simple
(Economy of mechanism)
Separation of
duties/privilege
Confidentiality
Psychological
Acceptability
Availability
Single Point of
Failure
Defense in
Depth
Leverage Existing
Components
Open Design
Complete
Mediation
Security Principles and Concepts
That’s a wrap!
@techdevdarin
in/darinmorris
Connect with me:

More Related Content

PPTX
DevSecOps with Microsoft Tech
PPTX
DevOps and the Future of InfoSec
PPTX
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
PDF
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
PDF
AWS Innovate 2016 : Closing Keynote - Glenn Gore
PDF
Silver Lining for Miles: DevOps for Building Security Solutions
PPTX
The Journey to DevSecOps
PPTX
451 AppSense Webinar - Why blame the user?
DevSecOps with Microsoft Tech
DevOps and the Future of InfoSec
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
AWS Innovate 2016 : Closing Keynote - Glenn Gore
Silver Lining for Miles: DevOps for Building Security Solutions
The Journey to DevSecOps
451 AppSense Webinar - Why blame the user?

What's hot (20)

PPTX
Turning security into code by Jeff Williams
PPTX
Amy DeMartine - 7 Habits of Rugged DevOps
PPTX
Build reliable Svelte applications using Cypress
PPTX
The Teams Behind DevSecOps
PPTX
2016 virus bulletin
PDF
Continuous Delivery in the World of Enterprise PHP
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
PDF
Just4Meeting 2012 - How to protect your web applications
PDF
Nick Drage & Fraser Scott - Epic battle devops vs security
PPTX
Cloud, DevOps and the New Security Practitioner
PPTX
Shifting security all day dev ops
PDF
DevSecOps - The big picture
PPTX
The R.O.A.D to DevOps
PPTX
Lessons learned from Detroit to Deming by Derek Weeks
PDF
BHack 2012 - How to protect your web applications
PDF
3 florin coada - sast in the days of dev ops
PDF
Got Myth? Myths in Software Engineering
PPTX
A beginner's guide for Java.pptx
PPTX
Failure is inevitable but it isn't permanent
PDF
The Security Pro's Guide to DevSecOps: How to Get Developers To Write Secure ...
Turning security into code by Jeff Williams
Amy DeMartine - 7 Habits of Rugged DevOps
Build reliable Svelte applications using Cypress
The Teams Behind DevSecOps
2016 virus bulletin
Continuous Delivery in the World of Enterprise PHP
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Just4Meeting 2012 - How to protect your web applications
Nick Drage & Fraser Scott - Epic battle devops vs security
Cloud, DevOps and the New Security Practitioner
Shifting security all day dev ops
DevSecOps - The big picture
The R.O.A.D to DevOps
Lessons learned from Detroit to Deming by Derek Weeks
BHack 2012 - How to protect your web applications
3 florin coada - sast in the days of dev ops
Got Myth? Myths in Software Engineering
A beginner's guide for Java.pptx
Failure is inevitable but it isn't permanent
The Security Pro's Guide to DevSecOps: How to Get Developers To Write Secure ...
Ad

Similar to DevOps and the Future of Information Security (20)

PPT
DevOps in 2014
PPTX
Security and DevOps Overview
PPTX
DevOps DevSecOps Based on Training Materials
PDF
Securing DevOps Lifecycle
PDF
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective
PPTX
DevOps Introduction
PPTX
DevOps.pptx
PPTX
PDF
Why DevSecOps Is Necessary For Your SDLC Pipeline?
PPTX
Introduction to DevSecOps OWASP Ahmedabad
PDF
The Rise of DevSecOps in CI_CD Workflows.pdf
PPTX
DevOps
PDF
DevOps vs DevSecOps_ What CTOs Must Know Before Scaling Securely.pdf
PPTX
Is DevOps Braking Your Company?
PDF
What is DevOps? History, Present and the Future
PDF
Strengthen and Scale Security for a dollar or less
PDF
From DevOps to DevSecOps: Evolution of Secure Software Development
DOCX
DevSecOps – The Importance of DevOps Security in 2023.docx
DevOps in 2014
Security and DevOps Overview
DevOps DevSecOps Based on Training Materials
Securing DevOps Lifecycle
DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective
DevOps Introduction
DevOps.pptx
Why DevSecOps Is Necessary For Your SDLC Pipeline?
Introduction to DevSecOps OWASP Ahmedabad
The Rise of DevSecOps in CI_CD Workflows.pdf
DevOps
DevOps vs DevSecOps_ What CTOs Must Know Before Scaling Securely.pdf
Is DevOps Braking Your Company?
What is DevOps? History, Present and the Future
Strengthen and Scale Security for a dollar or less
From DevOps to DevSecOps: Evolution of Secure Software Development
DevSecOps – The Importance of DevOps Security in 2023.docx
Ad

Recently uploaded (20)

PPTX
chapter8-180915055454bycuufucdghrwtrt.pptx
DOC
学位双硕士UTAS毕业证,墨尔本理工学院毕业证留学硕士毕业证
PPTX
Primary and secondary sources, and history
PPTX
Self management and self evaluation presentation
PPTX
lesson6-211001025531lesson plan ppt.pptx
PPT
First Aid Training Presentation Slides.ppt
PDF
Parts of Speech Prepositions Presentation in Colorful Cute Style_20250724_230...
PPTX
The Effect of Human Resource Management Practice on Organizational Performanc...
PPTX
Anesthesia and it's stage with mnemonic and images
PPTX
water for all cao bang - a charity project
PPTX
Introduction-to-Food-Packaging-and-packaging -materials.pptx
PDF
oil_refinery_presentation_v1 sllfmfls.pdf
PDF
natwest.pdf company description and business model
PPTX
AcademyNaturalLanguageProcessing-EN-ILT-M02-Introduction.pptx
PDF
Swiggy’s Playbook: UX, Logistics & Monetization
PPTX
fundraisepro pitch deck elegant and modern
PDF
Presentation1 [Autosaved].pdf diagnosiss
PPTX
Presentation for DGJV QMS (PQP)_12.03.2025.pptx
PPTX
Tour Presentation Educational Activity.pptx
PPTX
Effective_Handling_Information_Presentation.pptx
chapter8-180915055454bycuufucdghrwtrt.pptx
学位双硕士UTAS毕业证,墨尔本理工学院毕业证留学硕士毕业证
Primary and secondary sources, and history
Self management and self evaluation presentation
lesson6-211001025531lesson plan ppt.pptx
First Aid Training Presentation Slides.ppt
Parts of Speech Prepositions Presentation in Colorful Cute Style_20250724_230...
The Effect of Human Resource Management Practice on Organizational Performanc...
Anesthesia and it's stage with mnemonic and images
water for all cao bang - a charity project
Introduction-to-Food-Packaging-and-packaging -materials.pptx
oil_refinery_presentation_v1 sllfmfls.pdf
natwest.pdf company description and business model
AcademyNaturalLanguageProcessing-EN-ILT-M02-Introduction.pptx
Swiggy’s Playbook: UX, Logistics & Monetization
fundraisepro pitch deck elegant and modern
Presentation1 [Autosaved].pdf diagnosiss
Presentation for DGJV QMS (PQP)_12.03.2025.pptx
Tour Presentation Educational Activity.pptx
Effective_Handling_Information_Presentation.pptx

DevOps and the Future of Information Security

  • 1. DevOps and the Future of Information Security Darin Morris @techdevdari n in/darinmorris 2018
  • 2. In General: What we’re going talk about 2. How “doing DevOps” affects how we secure Data and Computer-centric Information Systems In Particular: 1. What it really means to do DevOps Thoughts I’ve had around DevOps and Security
  • 3. Motivation for this talk • I want “information technology practitioners” to become more professional, more productive and happier at work. Many reasons, but some of the more major reasons are: • Information systems need to be of higher quality and delivered faster – we need to really understand the DevOps philosophy to do that well. • Security is often an afterthought in the IT systems lifecycle – that needs to change. • We need a common, meaningful language – not buzzwords!
  • 5. DevOps and Security are very broad domains!
  • 6. So can we cover enough in only 35 minutes?!
  • 7. SOMEONE ONCE TOLD ME NOT TO BITE OFF MORE THAN I COULD CHEW… I said I’d rather CHOKE ON GREATNESS THAN NIBBLE ON MEDIOCRITY.
  • 8. Let’s get to know each other a little better!
  • 9. Sales or Relationship Management Does this sound like your role? Marketing Finance Leadership (C-Suite) Human Resources Business Analyst / Big Data Analyst General Administrator In-house Legal
  • 10. Project Manager or Coordinator Product Manager/Owner Software Architect Software Engineer Test Engineer Provision and Manage IT Infrastructure (IT Ops) Does this sound like your role? Dedicated Security or Compliance Something else? ?
  • 11. OK! Less about you. More about me!
  • 12. Fun facts about me Most used programming languages: C#, JavaScript “SiliconCape Native” First PC: Pentium 1 with Windows 95 First programming language: Java (JDK 1.3)
  • 13. Professional background • I’m a self-taught “Technologist” and I solve problems using technology. • I've been a founder, manager, team lead and software engineer, in various sectors, and in teams of different shapes and sizes. • Microsoft Certified Professional • Certified ScrumMaster • In the process of completing CSSLP, ITIL and ISTQB certifications. • Member of a number of professional IT associations and bodies i.e. OWASP, ISACA, IITPSA • Fulltime full stack software engineer for the past 13 years, primarily focussed on web and cloud-native software.
  • 14. Let’s play a game!
  • 15. True or False? DevOps is only done by technical staff. Question #1
  • 16. True or False? DevOps is a Role. Question #2
  • 17. True or False? DevOps is a way of thinking about how we do work. Question #3
  • 18. What is DevOps really?
  • 20. • DevOps Principles and Practices are compatible with Agile • DevOps is a logical continuation of Agile • Agile serves as an effective enabler of DevOps Myth #1: DevOps replaces Agile
  • 21. • Can be made compatible - many areas just become automated. Myth #2: DevOps is incompatible with ITIL
  • 22. • Controls are integrated into every stage of daily work of the SDLC resulting in better quality and security and compliance outcomes. Myth #3: DevOps is incompatible with InfoSec and Compliance Image credit: Checkmarx Software Exposure platform (www.checkmarx.com)
  • 23. • Rarely the case. Nature of IT Operations work just changes. • Collaborates far earlier in SDLC with development. • Enables developer productivity through APIs and self-service platforms that create environments, test and deploy code, monitor and display production telemetry, etc. • IT Ops become more like Development • i.e. engaged in product development for developers. Myth #4: DevOps means eliminating IT Operations
  • 24. • “DevOps isn’t about automation, just as astronomy isn’t about telescopes” - Christopher Little Myth #5: DevOps is just Infrastructure as Code
  • 25. DevOps is about Team Work that enables efficient creation of value What DevOp really boils down to
  • 26. So, how is Security affected?
  • 27. Security and DevOps - DevSecOps? • Security is fundamentally about mitigating risk (you’ll never be 100% secure). • Mitigating risk is enabled by maintaining integrity, availability and confidentially. • Security principles haven’t changed, the way we implement security has.
  • 28. Security Fail Securely Minimize attack surface Least Privilege Integrity Auditing Keep Things Simple (Economy of mechanism) Separation of duties/privilege Confidentiality Psychological Acceptability Availability Single Point of Failure Defense in Depth Leverage Existing Components Open Design Complete Mediation Security Principles and Concepts

Editor's Notes

  • #3: Aims: 1.1. Cover key principles. 1.2. Take audience on a journey to my AHA moment. 2. Delve into the impact of DevOps on security Clarify Terms and Concepts (Information Technology, Technology, DevOps, QA, Security) Provoke reflection on the way the audience currently does work and thought about what can be done better. Drive home the importance of security in software
  • #4: Is a pen and paper information technology?
  • #5: Disclaimer 1: I may be biased – I’m a software developer I’ve been thinking about this stuff a lot lately, but I’m probably ignorant to something. There is enough content to write about, never mind a short talk.
  • #6: Disclaimer 2: There is potentially a lot we could cover, but we have very little time.
  • #7: Disclaimer 2: There is potentially a lot we could cover, but we have very little time.
  • #8: I make joke. Har har.
  • #16: Answer: False Reason: DevOps isn't any single person's job. It's everyone's job.
  • #17: Answer: False Reason: DevOps isn't any single person's job. It's everyone's job.
  • #18: Answer: False Reason: DevOps isn't any single person's job. It's everyone's job.
  • #20: DevOps is a lot like the Standard Model of particle physics.
  • #21: Agile Toronto Conference 2008 Patrick Debois coined to the term DevOps when he organized the first DevOpsDays conference in 2009.
  • #29: DevOps is a lot like the Standard Model of particle physics