SlideShare a Scribd company logo
The big picture
Culture, Processes and Technologies on a high level
Stefan Streichsbier
Company: Vantage Point
Twitter: @s_streichsbier
Why?
DevSecOps - The big picture
A Brief
History of
DevOps
In the beginning there was…
Source: https://www.flickr.com/photos/37186408@N05/12162302775
Waterfall
• Long release cycles
• A lot of “WIP”
• Functional silos
• Incredibly rigid
…then there was Agile
Source: https://i.ytimg.com/vi/8Hedq2d1H44/maxresdefault.jpg
Agile
• Shorter release cycles
• Smaller batch sizes
• Cross-functional teams
• “Incredibly” agile
Suddenly Ops was the bottleneck
Agile Ops Anyone?
2 major related trends:
1. Agile Operations/Infrastructure
2. Collaboration between dev and ops
Ultimately led to the first DevOpsDays in 2009…
So, what is DevOps?
• Set of principles and practices for efficient
communication and collaboration. (Culture)
• Automated deployment pipeline. (Processes)
• Supporting tool chain (Technologies)
”[…]it seems as though the problems are
just between dev and ops, but test is in
there, and you have security objectives.
These are top-level concerns of
Management […] and have become part of
the DevOps picture.
In other words, when you hear "DevOps"
today, you should probably be thinking
DevOpsQATestInfoSec."
- Gene Kim
DevSecOps
Target State
DevSecOps enables organisations to
deliver inherently secure software at
DevOps speed.
Security challenges in DevOps
• It is clear why companies are moving to DevOps
…but how can security keep up with this?
Source: https://xebialabs.com/assets/files/whitepapers/ITRev_DevOps_Guide_5_2015.pdf
3 key categories
of DevSecOps
1. Culture
2. Processes
3. Technologies
Culture
Culture
• Communication and transparency
• High-trust environment “blameless postmortem”
• Continuous improvement
• Everyone is responsible for security
• Automate as much as possible
• Everything as code
Culture:
Open Space Ideas
• How did your org switch to Dev(Sec)Ops?
• Continuous Improvement (Kaizen)
• What are you automating at the moment?
Processes
Processes
1. Secure SDLC
2. Security Pipelines
Processes:
Secure SDLC
1. Training
2. Requirements
3. Architecture & Design
4. Coding
5. Testing
6. Deployment
7. Post Deployment
Processes:
Sec Pipelines
• Opt. critical resource
• Reduce friction
• Increase visibility
• Each step repeatable
• Drive up consistency
Security Pipelines
Processes:
Open Space Ideas
• How are you managing security requirements?
• How are you building security into the SDLC?
• AppSec Pipelines in the wild
• ChatSecOps
TechnologiesDevOps is not supposed to be about “tools”
DevSecOps
Technologies
1. Requirements
2. Code: IDE Plugins, SAST
3. Test: Gauntlt, *AST
4. Configure: Sec as Code
5. Maintenance:
Patch Management
6. Monitor: Auditing, Attack
visibility, RASP
Warning about *AST
Technologies:
Open Space Ideas
• Scaling security requirements
• TDD and security in testing
• Which *AST technologies have you been using?
• Experience with IDE Plugins
• Environment management (Dev/Prod parity)
• Configuration management (configuration drift)
• Patch Management and deployment strategies
(e.g. Phoenix)
Summary
• DevSecOps enable organisations to deliver inherently
secure software at DevOps speed.
Questions?
Inspirations
• http://itrevolution.com/heres-how-the-amazing-twitter-infosec-team-helps-devops/
• http://techbeacon.com/devsecops-9-ways-devops-automation-bolster-security-compliance
• https://www.checkmarx.com/2015/11/13/devsecops-4-best-practices-the-pros-teach-us-about-
security-and-devops/
• http://www.slideshare.net/zanelackey/effective-approaches-to-web-application-security
• http://searchdatacenter.techtarget.com/feature/How-to-adopt-a-successful-DevOps-enterprise
• https://opensource.com/business/14/7/devops-red-hat
• http://www.infoq.com/news/2014/03/etsy-deploy-50-times-a-day
• http://www.slideshare.net/mtesauro/taking-appsec-to-11-appsec-pipeline-devops-and-making-
things-better
• https://www.owasp.org/index.php/OWASP_AppSec_Pipeline

More Related Content

PDF
DevSecOps Implementation Journey
PPTX
DevOps Introduction
PDF
DevSecOps in Baby Steps
PDF
The State of DevSecOps
PDF
Introduction to DevSecOps
PDF
DevSecOps
DevSecOps Implementation Journey
DevOps Introduction
DevSecOps in Baby Steps
The State of DevSecOps
Introduction to DevSecOps
DevSecOps

What's hot (20)

PPTX
Introduction to DevOps
PDF
DevSecOps: What Why and How : Blackhat 2019
PPTX
DevSecOps
PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
PPTX
DevOps Overview
PDF
DevSecOps What Why and How
PDF
Slide DevSecOps Microservices
PDF
How to implement DevOps in your Organization
PDF
DevOps Powerpoint Presentation Slides
PPTX
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
PPTX
DevOps to DevSecOps Journey..
PPTX
DEVSECOPS.pptx
PPSX
PPTX
DevOps & Security: Here & Now
PPTX
Devops online training ppt
PPTX
CICD Pipeline - AWS Azure
PDF
Demystifying DevSecOps
PPTX
How to Get Started with DevSecOps
PDF
The What, Why, and How of DevSecOps
PDF
DevOps
Introduction to DevOps
DevSecOps: What Why and How : Blackhat 2019
DevSecOps
[DevSecOps Live] DevSecOps: Challenges and Opportunities
DevOps Overview
DevSecOps What Why and How
Slide DevSecOps Microservices
How to implement DevOps in your Organization
DevOps Powerpoint Presentation Slides
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
DevOps to DevSecOps Journey..
DEVSECOPS.pptx
DevOps & Security: Here & Now
Devops online training ppt
CICD Pipeline - AWS Azure
Demystifying DevSecOps
How to Get Started with DevSecOps
The What, Why, and How of DevSecOps
DevOps
Ad

Viewers also liked (19)

PDF
DevSecOps - Building Rugged Software
PDF
Programming Language Selection
PDF
Building A Great API - Evan Cooke, Cloudstock, December 2010
KEY
2012: Putting your robots to work: security automation at Twitter
PDF
Introduction to devops 2016
PPTX
Introduction to DevOps
PDF
DevSecOps in Baby Steps
PDF
Application Security at DevOps Speed - DevOpsDays Singapore 2016
PDF
DevOps - A Gentle Introduction
PDF
Integrating DevOps and Security
PDF
DevSecCon Asia 2017 Fabian Lim: DevSecOps in the government
PPTX
Cloud Native Application Framework
PPTX
Why Everyone Needs DevOps Now: 15 Year Study Of High Performing Technology Orgs
PDF
DevSecOps: Taking a DevOps Approach to Security
PPT
Devops at Netflix (re:Invent)
PPTX
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
PDF
DevOps: A Culture Transformation, More than Technology
PPTX
Introducing DevOps
PPTX
DevOps 101
DevSecOps - Building Rugged Software
Programming Language Selection
Building A Great API - Evan Cooke, Cloudstock, December 2010
2012: Putting your robots to work: security automation at Twitter
Introduction to devops 2016
Introduction to DevOps
DevSecOps in Baby Steps
Application Security at DevOps Speed - DevOpsDays Singapore 2016
DevOps - A Gentle Introduction
Integrating DevOps and Security
DevSecCon Asia 2017 Fabian Lim: DevSecOps in the government
Cloud Native Application Framework
Why Everyone Needs DevOps Now: 15 Year Study Of High Performing Technology Orgs
DevSecOps: Taking a DevOps Approach to Security
Devops at Netflix (re:Invent)
DevOps and Continuous Delivery Reference Architectures (including Nexus and o...
DevOps: A Culture Transformation, More than Technology
Introducing DevOps
DevOps 101
Ad

Similar to DevSecOps - The big picture (20)

PPTX
Outpost24 webinar - application security in a dev ops world-08-2018
PPTX
Introduction to DevSecOps
PPTX
State of DevSecOps - GTACS 2019
PPTX
State of DevSecOps - DevSecOpsDays 2019
PPTX
DevSecOps Best Practices-Safeguarding Your Digital Landscape
PPTX
ISACA Ireland Keynote 2015
PDF
Scale security for a dollar or less
PPTX
DevOps DevSecOps Based on Training Materials
PPTX
State of DevSecOps - DevOpsDays Jakarta 2019
PDF
Security's DevOps Transformation
PDF
Outpost24 webinar: Turning DevOps and security into DevSecOps
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
PPTX
DevSecOps OWASP
PPTX
DevSecOps Story with added security controls
PDF
Pentest is yesterday, DevSecOps is tomorrow
PDF
To boldly go where no one has gone before: life after the DevSecOps transform...
PDF
Strengthen and Scale Security for a dollar or less
PDF
From DevOps to DevSecOps: Evolution of Secure Software Development
PDF
Protecting Agile Transformation through Secure DevOps (DevSecOps)
PDF
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
Outpost24 webinar - application security in a dev ops world-08-2018
Introduction to DevSecOps
State of DevSecOps - GTACS 2019
State of DevSecOps - DevSecOpsDays 2019
DevSecOps Best Practices-Safeguarding Your Digital Landscape
ISACA Ireland Keynote 2015
Scale security for a dollar or less
DevOps DevSecOps Based on Training Materials
State of DevSecOps - DevOpsDays Jakarta 2019
Security's DevOps Transformation
Outpost24 webinar: Turning DevOps and security into DevSecOps
Why Security Engineer Need Shift-Left to DevSecOps?
DevSecOps OWASP
DevSecOps Story with added security controls
Pentest is yesterday, DevSecOps is tomorrow
To boldly go where no one has gone before: life after the DevSecOps transform...
Strengthen and Scale Security for a dollar or less
From DevOps to DevSecOps: Evolution of Secure Software Development
Protecting Agile Transformation through Secure DevOps (DevSecOps)
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...

Recently uploaded (20)

PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Cloud computing and distributed systems.
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPT
Teaching material agriculture food technology
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
KodekX | Application Modernization Development
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Network Security Unit 5.pdf for BCA BBA.
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Electronic commerce courselecture one. Pdf
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
Per capita expenditure prediction using model stacking based on satellite ima...
Digital-Transformation-Roadmap-for-Companies.pptx
Encapsulation_ Review paper, used for researhc scholars
Chapter 3 Spatial Domain Image Processing.pdf
Cloud computing and distributed systems.
Understanding_Digital_Forensics_Presentation.pptx
Teaching material agriculture food technology
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Dropbox Q2 2025 Financial Results & Investor Presentation
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
KodekX | Application Modernization Development
CIFDAQ's Market Insight: SEC Turns Pro Crypto
20250228 LYD VKU AI Blended-Learning.pptx
Network Security Unit 5.pdf for BCA BBA.
“AI and Expert System Decision Support & Business Intelligence Systems”
Review of recent advances in non-invasive hemoglobin estimation
Building Integrated photovoltaic BIPV_UPV.pdf
The AUB Centre for AI in Media Proposal.docx
Electronic commerce courselecture one. Pdf
Reach Out and Touch Someone: Haptics and Empathic Computing

DevSecOps - The big picture