SlideShare a Scribd company logo
DevSecOps
The Evolution of
DevOps
Or how I learned to start
worrying and love security
@jamesbetteley
Who is this guy?
@jamesbetteley
What I’m going to talk about
What I mean by DevSecOps and how we messed up DevOps
What’ll inevitably happen next
How we can influence the future of DevSecOps
Who’s going to need DevSecOps?
How we’re doing it right now
The challenges we face
How we
messed up
DevOps
DevSecOps means...
“Developers, testers, security architects, infrastructure, DBAs
and many others collaborating to design, build, validate,
deploy, operate and maintain software in a rapid, reliable,
repeatable and secure fashion”
DevSecOps doesn’t
mean...
Compliance as code
Security testing in your CD pipeline
Where is
DevSecOps right
now...
What’ll happen
next...
DevSecOps tooling
DevSecOps engineers
DevSecOps as a service
DevSecOps frameworks
DevSecOps Handbook
The future of DevSecOps
“Our number one objective should be to educate the software
delivery community on the importance of Security, and to help
them adopt best practices for ensuring Security is baked into
our applications and processes”
DevSecOps isn’t necessary, it’s inevitable!
How we’re doing
DevSecOps
Contino’s approach to
applying DevSecOps in large,
regulated enterprises.
We look at...
➔ People changes
◆ Upskilling
◆ Communities of practice
◆ Leadership & Coaching
◆ Cross-functional delivery teams with security
SMEs embedded
➔ Process changes
◆ Security & Operability as first-class-citizens
◆ Security & Operability stories on backlog
◆ Security testing in dev domain
➔ Technology changes
◆ Security testing in CD pipeline
◆ IAST
◆ SAST & DAST
◆ Dependency scanning
DevSecOps The Evolution of DevOps
DevSecOps The Evolution of DevOps
Building DevSecOps teams
Who needs DevSecOps
Challenges...
Large, regulated organisations NEED
DevSecOps
This doesn’t mean they’re READY for
DevSecOps
Org structures make DevSecOps very
hard to achieve
Existing cultures and empires hard to
break down
It’s as hard as selling Agile and DevOps
On selling
DevSecOps...
● Cost reduction is achieved by detecting and fixing
security issues during the development phases.
● Speed of delivery is increased as security
bottlenecks are minimised or eliminated.
● Speed of recovery is enhanced
● Enhanced monitoring and auditing leads to
improved threat hunting
● Immutable infrastructure reduces attack vectors
● Immutable infrastructure improves overall security
by reducing vulnerabilities, and increasing code
coverage and automation.
● Ensures the ‘secure by design’ principle by using
automated security review of code
● Creates targeted customer value through secure
iterative innovation at speed and scale.
● Security is federated and becomes the
responsibility of everyone, not just a specialised
team, or even individual.
● DevSecOps fosters a culture of openness and
transparency from the earliest stages of
development.
● Increased sales as it is much easier to sell a
demonstrably secure product.

More Related Content

PDF
2019 DevSecOps Reference Architectures
PDF
DevSecOps Implementation Journey
PDF
DevSecOps What Why and How
PDF
Introduction to DevSecOps
PDF
DevSecOps
PDF
The State of DevSecOps
PPTX
ABN AMRO DevSecOps Journey
PDF
DevOps - A Gentle Introduction
2019 DevSecOps Reference Architectures
DevSecOps Implementation Journey
DevSecOps What Why and How
Introduction to DevSecOps
DevSecOps
The State of DevSecOps
ABN AMRO DevSecOps Journey
DevOps - A Gentle Introduction

What's hot (20)

PDF
Practical DevSecOps Course - Part 1
PPTX
DevSecOps reference architectures 2018
PPTX
Devops online training ppt
PDF
DevSecOps: What Why and How : Blackhat 2019
PPTX
About DevOps in simple steps
PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
PDF
Security Process in DevSecOps
PPTX
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
PDF
DevSecOps Jenkins Pipeline -Security
PPTX
Introduction to DevSecOps
PPTX
How to Get Started with DevSecOps
PDF
Practical DevSecOps - Arief Karfianto
PPTX
DevSecOps
PDF
DevOps
PPTX
DevOps Tutorial For Beginners | DevOps Tutorial | DevOps Tools | DevOps Train...
PPTX
DevOps introduction
PDF
The What, Why, and How of DevSecOps
PDF
Demystifying DevSecOps
Practical DevSecOps Course - Part 1
DevSecOps reference architectures 2018
Devops online training ppt
DevSecOps: What Why and How : Blackhat 2019
About DevOps in simple steps
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Security Process in DevSecOps
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
DevSecOps Jenkins Pipeline -Security
Introduction to DevSecOps
How to Get Started with DevSecOps
Practical DevSecOps - Arief Karfianto
DevSecOps
DevOps
DevOps Tutorial For Beginners | DevOps Tutorial | DevOps Tools | DevOps Train...
DevOps introduction
The What, Why, and How of DevSecOps
Demystifying DevSecOps
Ad

Similar to DevSecOps The Evolution of DevOps (20)

PDF
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
PPTX
Dev secops indonesia-devsecops as a service-Amien Harisen
PDF
Strengthen and Scale Security for a dollar or less
PDF
Understanding DevOps Security - Full Guide
PDF
understanding devops security - DevSecOps
PDF
Why DevSecOps Is Necessary For Your SDLC Pipeline?
PDF
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
PDF
DevSecOps Implement Making Security Central to Your DevOps Pipeline
PPTX
DevOps vs. DevSecOps Understanding the Differences.pptx
PPTX
DevOps vs. DevSecOps: Understanding the Differences
PDF
From DevOps to DevSecOps: Evolution of Secure Software Development
PDF
Scale security for a dollar or less
PPTX
DevSecOps: Security With DevOps
PPTX
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
PDF
Pentest is yesterday, DevSecOps is tomorrow
PDF
DevOps vs DevSecOps_ What CTOs Must Know Before Scaling Securely.pdf
PDF
The Rise of DevSecOps in CI_CD Workflows.pdf
PPTX
DevOps to DevSecOps Journey..
PPTX
DevSecOps: The Future of Secure Software Development
Complete DevSecOps handbook_ Key differences, tools, benefits & best practice...
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Dev secops indonesia-devsecops as a service-Amien Harisen
Strengthen and Scale Security for a dollar or less
Understanding DevOps Security - Full Guide
understanding devops security - DevSecOps
Why DevSecOps Is Necessary For Your SDLC Pipeline?
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
DevSecOps Implement Making Security Central to Your DevOps Pipeline
DevOps vs. DevSecOps Understanding the Differences.pptx
DevOps vs. DevSecOps: Understanding the Differences
From DevOps to DevSecOps: Evolution of Secure Software Development
Scale security for a dollar or less
DevSecOps: Security With DevOps
DevSecOps IT Modernization Training Bootcamp for Security Staff, IT Leadership
Pentest is yesterday, DevSecOps is tomorrow
DevOps vs DevSecOps_ What CTOs Must Know Before Scaling Securely.pdf
The Rise of DevSecOps in CI_CD Workflows.pdf
DevOps to DevSecOps Journey..
DevSecOps: The Future of Secure Software Development
Ad

More from Michael Man (20)

PPTX
5 things i wish i knew about sast (DSO-LG July 2021)
PDF
K8S Certifications - Exam Cram
PDF
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
PDF
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PPTX
Extract Oct 2019: DSO-LG Rolling Slides
PPTX
Sept 2019 - DSO-LG Tooling Examples
PPTX
DevSecOps Manchester - May 2019
PDF
Chris Rutter: Avoiding The Security Brick
PPTX
Extract: DevSecOps - London Gathering (March 2019)
PDF
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
PDF
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
PDF
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
PDF
August 2018: DevSecOps - London Gathering
PPTX
DevSecOps - London Gathering : June 2018
PDF
Continuous Security: From tins to containers - now what!
PDF
The mechanics behind how attackers exploit simple programming mistakes ...
PDF
Secret Management Journey - Here Be Dragons aka Secret Dragons
PPTX
DevSecOps March 2018 - Extract
PDF
Dynaminet -DevSecOps
5 things i wish i knew about sast (DSO-LG July 2021)
K8S Certifications - Exam Cram
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Extract Oct 2019: DSO-LG Rolling Slides
Sept 2019 - DSO-LG Tooling Examples
DevSecOps Manchester - May 2019
Chris Rutter: Avoiding The Security Brick
Extract: DevSecOps - London Gathering (March 2019)
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
August 2018: DevSecOps - London Gathering
DevSecOps - London Gathering : June 2018
Continuous Security: From tins to containers - now what!
The mechanics behind how attackers exploit simple programming mistakes ...
Secret Management Journey - Here Be Dragons aka Secret Dragons
DevSecOps March 2018 - Extract
Dynaminet -DevSecOps

Recently uploaded (20)

PDF
Encapsulation theory and applications.pdf
PDF
cuic standard and advanced reporting.pdf
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Approach and Philosophy of On baking technology
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PPTX
sap open course for s4hana steps from ECC to s4
PDF
KodekX | Application Modernization Development
PPTX
Cloud computing and distributed systems.
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Big Data Technologies - Introduction.pptx
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Encapsulation theory and applications.pdf
cuic standard and advanced reporting.pdf
Programs and apps: productivity, graphics, security and other tools
Approach and Philosophy of On baking technology
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
sap open course for s4hana steps from ECC to s4
KodekX | Application Modernization Development
Cloud computing and distributed systems.
Review of recent advances in non-invasive hemoglobin estimation
Dropbox Q2 2025 Financial Results & Investor Presentation
“AI and Expert System Decision Support & Business Intelligence Systems”
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Mobile App Security Testing_ A Comprehensive Guide.pdf
Encapsulation_ Review paper, used for researhc scholars
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Electronic commerce courselecture one. Pdf
Empathic Computing: Creating Shared Understanding
Big Data Technologies - Introduction.pptx
Spectral efficient network and resource selection model in 5G networks
How UI/UX Design Impacts User Retention in Mobile Apps.pdf

DevSecOps The Evolution of DevOps

  • 1. DevSecOps The Evolution of DevOps Or how I learned to start worrying and love security @jamesbetteley
  • 2. Who is this guy? @jamesbetteley
  • 3. What I’m going to talk about What I mean by DevSecOps and how we messed up DevOps What’ll inevitably happen next How we can influence the future of DevSecOps Who’s going to need DevSecOps? How we’re doing it right now The challenges we face
  • 5. DevSecOps means... “Developers, testers, security architects, infrastructure, DBAs and many others collaborating to design, build, validate, deploy, operate and maintain software in a rapid, reliable, repeatable and secure fashion”
  • 6. DevSecOps doesn’t mean... Compliance as code Security testing in your CD pipeline
  • 8. What’ll happen next... DevSecOps tooling DevSecOps engineers DevSecOps as a service DevSecOps frameworks DevSecOps Handbook
  • 9. The future of DevSecOps “Our number one objective should be to educate the software delivery community on the importance of Security, and to help them adopt best practices for ensuring Security is baked into our applications and processes”
  • 10. DevSecOps isn’t necessary, it’s inevitable!
  • 11. How we’re doing DevSecOps Contino’s approach to applying DevSecOps in large, regulated enterprises.
  • 12. We look at... ➔ People changes ◆ Upskilling ◆ Communities of practice ◆ Leadership & Coaching ◆ Cross-functional delivery teams with security SMEs embedded ➔ Process changes ◆ Security & Operability as first-class-citizens ◆ Security & Operability stories on backlog ◆ Security testing in dev domain ➔ Technology changes ◆ Security testing in CD pipeline ◆ IAST ◆ SAST & DAST ◆ Dependency scanning
  • 17. Challenges... Large, regulated organisations NEED DevSecOps This doesn’t mean they’re READY for DevSecOps Org structures make DevSecOps very hard to achieve Existing cultures and empires hard to break down It’s as hard as selling Agile and DevOps
  • 18. On selling DevSecOps... ● Cost reduction is achieved by detecting and fixing security issues during the development phases. ● Speed of delivery is increased as security bottlenecks are minimised or eliminated. ● Speed of recovery is enhanced ● Enhanced monitoring and auditing leads to improved threat hunting ● Immutable infrastructure reduces attack vectors ● Immutable infrastructure improves overall security by reducing vulnerabilities, and increasing code coverage and automation. ● Ensures the ‘secure by design’ principle by using automated security review of code ● Creates targeted customer value through secure iterative innovation at speed and scale. ● Security is federated and becomes the responsibility of everyone, not just a specialised team, or even individual. ● DevSecOps fosters a culture of openness and transparency from the earliest stages of development. ● Increased sales as it is much easier to sell a demonstrably secure product.