SlideShare a Scribd company logo
SecDevOps: The New Black of IT
Andrew Storms
CloudPassage
Director of DevOps
Alan Shimmel
DevOps.com
CEO & Co-founder
1994 1995 2009
Cloud or Not – Still the Same
• Infrastructure
• Data & Storage
• Identity & Access Controls
• Privacy
• Governance
• Audit & Compliance
3
Infrastructure as code
Instrumentation
What about DevOps?
Orchestration
Continuous everything
about
security
DevOps?
What
with
DevOps & Security Division
6
This is NOT how we do DevOps at CloudPassage.
Collaboration Division
DevOps Security
Plan Code Test Release Deploy Operate
SecDevOps
• Less division
– More collaboration
• Less silos
– More sharing
• Less pipeline
– More chains & links
• Less manual
– More automation
7
Security
Plan
Release
Code
Test
Operate
Deploy
Plan
• Release Sherpa
– Ops, Dev, QA
– See a release thru from start to finish
• Change risk management
– What infrastructure changes?
– Unexpected or large code changes?
– Security risk assessment
– Threat vector analysis
Security
Plan
Release
Code
Test
Operate
Deploy
Code
• Standards enforcement
– Rubocop, Food Critic, Knife-Spork
• Review Process
– Peer & code review
– Continuous application & infrastructure testing
• Git feature branching
– Change control & isolation
Security
Plan
Release
Code
Test
Operate
Deploy
Test
• Automated code testing
– Over 10k tests run automatically
at check in
– Over 10k QA assertions
– Over 130 smoke test suites
• All the modules & third party integrations
• Deploy verifications
• External automated testing
• External code review
Security
Plan
Release
Code
Test
Operate
Deploy
Release & Deploy
• Stakeholders approval
• Standardized tools
– Capistrano, Chef
• Deploy testing
– 2-man rule
• System segregation
– Only Ops has production access
Security
Plan
Release
Code
Test
Operate
Deploy
• Continuous compliance monitoring
– All systems (prod & non-prod)
– Hourly & daily
– Halo
• Infrastructure security orchestration
– Thousands of control/change points enforced hourly (Chef)
– Validated by Halo
• Continuous risk assessment
– Third-party vulnerability testing of all systems
Operate
Security
Plan
Release
Code
Test
Operate
Deploy
JIRAgitChefCapistranoHalo
Initiate Approve
Implement
Audit
Records
Deploy
(Infrastructure)
Audit
Records
Deploy
(App Code)
Audit
Records
Audit
Records
Update
Baselines
Continuous
Monitoring
Audit
Records
End to end audit trail, built into the agile process…
“AGILE ASSURANCE”
Practical SecDevOps Examples
• Security automation potential
– Cloud APIs have exploded
• Latch on to DevOps momentum
– Take advantage of change
– Make Dev and Ops security stakeholders
• Use IFTTT thinking
– Channels, Triggers, Actions, Ingredients
 Recipes
14
Practical SecDevOps Automation
15
Practical SecDevOps Automation
16
git-push
Practical SecDevOps Automation
17
Practical SecDevOps Automation
18
SecDevOps in Summary
19
Old is new
Still solving the same problems,
but in new ways
SecDevOps
Automation
DevOps is here
SecDevOps is required
Security automation is here
And is required in the cloud
More Resources
20
Explore: www.DevOps.com
Learn: blog.cloudpassage.com
Start: www.cloudpassage.com/halo
Thank you!
21
Q&A

More Related Content

PDF
Embracing the Rise of SecDevOps
PPTX
we45 SecDevOps Presentation - ISACA Chennai
PDF
we45 - SecDevOps Concept Presentation
KEY
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
PDF
Integrating DevOps and Security
PDF
Continuous Security Testing - DevSecCon
PPTX
Automating security tests for Continuous Integration
PDF
A Secure DevOps Journey
Embracing the Rise of SecDevOps
we45 SecDevOps Presentation - ISACA Chennai
we45 - SecDevOps Concept Presentation
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
Integrating DevOps and Security
Continuous Security Testing - DevSecCon
Automating security tests for Continuous Integration
A Secure DevOps Journey

What's hot (20)

PPTX
OWASP AppSec EU - SecDevOps, a view from the trenches - Abhay Bhargav
PDF
Security DevOps - Staying secure in agile projects // OWASP AppSecEU 2015 - A...
PPTX
Integrating Security into DevOps
PDF
DevSecCon London 2017: Shift happens ... by Colin Domoney
PDF
we45 DEFCON Workshop - Building AppSec Automation with Python
PDF
Proactive Security AppSec Case Study
PDF
T23 HTML5 Security Testing at Spotify
PPTX
DevSecCon London 2017: when good containers go bad by Tim Mackey
PDF
Devops, Secops, Opsec, DevSec *ops *.* ?
PDF
we45 - Infrastructure Penetration Testing with LeanBeast Case Study
PDF
SecDevOps Risk Workflow - v0.6
PPTX
DevOps & Security: Here & Now
PDF
Ast in CI/CD by Ofer Maor
PPTX
Continuous Security Testing with Devops - OWASP EU 2014
PPTX
Continuous Security Testing in a Devops World #OWASPHelsinki
PDF
Security in a Continuous Delivery World
PPTX
DevSecOps
PDF
SecDevOps
PPTX
Integrating security into Continuous Delivery
PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
OWASP AppSec EU - SecDevOps, a view from the trenches - Abhay Bhargav
Security DevOps - Staying secure in agile projects // OWASP AppSecEU 2015 - A...
Integrating Security into DevOps
DevSecCon London 2017: Shift happens ... by Colin Domoney
we45 DEFCON Workshop - Building AppSec Automation with Python
Proactive Security AppSec Case Study
T23 HTML5 Security Testing at Spotify
DevSecCon London 2017: when good containers go bad by Tim Mackey
Devops, Secops, Opsec, DevSec *ops *.* ?
we45 - Infrastructure Penetration Testing with LeanBeast Case Study
SecDevOps Risk Workflow - v0.6
DevOps & Security: Here & Now
Ast in CI/CD by Ofer Maor
Continuous Security Testing with Devops - OWASP EU 2014
Continuous Security Testing in a Devops World #OWASPHelsinki
Security in a Continuous Delivery World
DevSecOps
SecDevOps
Integrating security into Continuous Delivery
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Ad

Similar to SecDevOps: The New Black of IT (20)

PPTX
Secure DevOPS Implementation Guidance
PPTX
DevOps to DevSecOps Journey..
PPTX
Are your DevOps and Security teams friends or foes?
PDF
The Rise of DevSecOps in CI_CD Workflows.pdf
PPTX
You Build It, You Secure It: Introduction to DevSecOps
PDF
From DevOps to DevSecOps: Evolution of Secure Software Development
PDF
Strengthen and Scale Security for a dollar or less
PPTX
DevSecOps Best Practices-Safeguarding Your Digital Landscape
PDF
Dev secops opsec, devsec, devops ?
PPTX
What_is_DevOps_how_it's_very_useful_in_daily_Life.
PPTX
What is DevOps And How It Is Useful In Real life.
PPTX
How to get the best out of DevSecOps - an operations perspective
PDF
Scale security for a dollar or less
PPTX
What_is_DevOps.pptx
PDF
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
PDF
How DevOps Development Companies Streamline Operations.pdf
PDF
DevOps Automation: Boosting Efficiency and Productivity
PDF
You build it - Cyber Chicago Keynote
PDF
Divine and felonios cyber security devopsdays austin 2018
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Secure DevOPS Implementation Guidance
DevOps to DevSecOps Journey..
Are your DevOps and Security teams friends or foes?
The Rise of DevSecOps in CI_CD Workflows.pdf
You Build It, You Secure It: Introduction to DevSecOps
From DevOps to DevSecOps: Evolution of Secure Software Development
Strengthen and Scale Security for a dollar or less
DevSecOps Best Practices-Safeguarding Your Digital Landscape
Dev secops opsec, devsec, devops ?
What_is_DevOps_how_it's_very_useful_in_daily_Life.
What is DevOps And How It Is Useful In Real life.
How to get the best out of DevSecOps - an operations perspective
Scale security for a dollar or less
What_is_DevOps.pptx
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
How DevOps Development Companies Streamline Operations.pdf
DevOps Automation: Boosting Efficiency and Productivity
You build it - Cyber Chicago Keynote
Divine and felonios cyber security devopsdays austin 2018
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Ad

More from CloudPassage (20)

PDF
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
PPTX
CloudPassage Careers
PPTX
Transforming the CSO Role to Business Enabler
PPTX
Rethinking Security: The Cloud Infrastructure Effect
PPTX
Webinar compiled powerpoint
PPTX
Security and Compliance for Enterprise Cloud Infrastructure
PPTX
Technologies You Need to Safely Use the Cloud
PPT
Cloud Security: Make Your CISO Successful
PDF
Secure Cloud Development Resources with DevOps
PPTX
45 Minutes to PCI Compliance in the Cloud
PPTX
Comprehensive Cloud Security Requires an Automated Approach
PPTX
Security that works with, not against, your SaaS business
PDF
What You Need To Know About The New PCI Cloud Guidelines
PPTX
What You Haven't Heard (Yet) About Cloud Security
PPTX
Meeting PCI DSS Requirements with AWS and CloudPassage
PPTX
Delivering Secure OpenStack IaaS for SaaS Products
PPTX
CloudPassage Overview
PPTX
PCI and the Cloud
PDF
Halo Installfest Slides
PPTX
Automating Security for the Cloud - Make it Easy, Make it Safe
Best Practices for Workload Security: Securing Servers in Modern Data Center ...
CloudPassage Careers
Transforming the CSO Role to Business Enabler
Rethinking Security: The Cloud Infrastructure Effect
Webinar compiled powerpoint
Security and Compliance for Enterprise Cloud Infrastructure
Technologies You Need to Safely Use the Cloud
Cloud Security: Make Your CISO Successful
Secure Cloud Development Resources with DevOps
45 Minutes to PCI Compliance in the Cloud
Comprehensive Cloud Security Requires an Automated Approach
Security that works with, not against, your SaaS business
What You Need To Know About The New PCI Cloud Guidelines
What You Haven't Heard (Yet) About Cloud Security
Meeting PCI DSS Requirements with AWS and CloudPassage
Delivering Secure OpenStack IaaS for SaaS Products
CloudPassage Overview
PCI and the Cloud
Halo Installfest Slides
Automating Security for the Cloud - Make it Easy, Make it Safe

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
cuic standard and advanced reporting.pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Machine learning based COVID-19 study performance prediction
PPTX
A Presentation on Artificial Intelligence
PPTX
Understanding_Digital_Forensics_Presentation.pptx
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
KodekX | Application Modernization Development
NewMind AI Weekly Chronicles - August'25 Week I
“AI and Expert System Decision Support & Business Intelligence Systems”
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
The Rise and Fall of 3GPP – Time for a Sabbatical?
Building Integrated photovoltaic BIPV_UPV.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Encapsulation_ Review paper, used for researhc scholars
Unlocking AI with Model Context Protocol (MCP)
cuic standard and advanced reporting.pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
NewMind AI Monthly Chronicles - July 2025
Network Security Unit 5.pdf for BCA BBA.
20250228 LYD VKU AI Blended-Learning.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Machine learning based COVID-19 study performance prediction
A Presentation on Artificial Intelligence
Understanding_Digital_Forensics_Presentation.pptx
The AUB Centre for AI in Media Proposal.docx
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
KodekX | Application Modernization Development

SecDevOps: The New Black of IT

Editor's Notes

  • #16: Apply IFTTT thinking If This Then That Channels, Triggers, Actions, Ingredients Recipes (need a graphic here. Something like a funnel or other where Channels, Triggers, Actions, Ingredients converge to make a recipe)
  • #17: Examples (The same graphic from previous slide, but small) If code gets checked in, then run static analysis
  • #18: Examples If firewall policy changes, then initiate remote scanner
  • #19: Examples If breach, then quarantine
  • #21: Feel free to change these points to you sales next steps.
  • #22: Feel free to change these points to you sales next steps.