SlideShare a Scribd company logo
<—Shift Risk Left
Security Cloud Native Environments
Introduction
• Tony Hansmann (@997unix), Platform Architect at Pivotal
• Recently broke off a twenty year relationship with the pager
• Ops persons who accidentally landed at Pivotal, Agile Dev Central
• Trying hard to automate Ops away for the F500
• Security, Compliance, and Risk Management are the frontiers of Ops
• “Cloud” == getting compute resources from an API
• “Cloud Native” == App dev model that assumes APIs for all resources
• Apps get easier to push (46x between low and high perf orgs DORA 2017).
• We expect app counts to grow 2-4x other next five years
• The standard model of App security won’t support this app volume
Cloud Native, is that a real thing?
• The Left here is the path-to-prod pipeline
• Devs are the beginning of that pipeline and we believe they need feedback as
soon as possible
• The security/change approval process is a big impediment to Cloud Native
adoption (or it causes such a big slowdown, there is no point in going cloud)
We buy “Security is a process, not a destination”
• The worst feeling for an Ops persons is a failure they “should have” known about
• Black Duck gives Pivotal a huge advantage by making huge swaths of security
trivially knowable
• How are the F500 going to “know” about their hundreds of apps that don’t have dev
teams behind them?
• We’re going to also have to know decade-over-decade
• Knowing is a key capability, there’s no way off this wheel
• Security is going to Visit you, the only questions is on who’s terms will they visit you?
Security and Knowability
Black Duck integration with PCF
Meta-buildpackDeveloper
buildpacks
droplet
BLOB
STORE
PCF DEV
Operator
PCF
STAGING
PCF
PROD
Continuous Integration (CI)
Concourse, Jenkins, Bamboo, Team City, TFS/VSTS
decorators
cf push
cf push
cf push
Black Duck Service
Broker
(cf bind)
Black Duck CI Integrations
QA
• Our fellows who have suffered security breaches often knew all about their
exposure - knowing is not enough
• You’re going to need CI/CD at a minimum
• If you’re a Dev, help Ops and Security by adding Black Duck to your pipelines
• If your in Ops or Security, learn your CI/CD system to partner with devs
• Have policy in-place for what each team does in the event of CVE and then tie it
off with executives
• Risk compounds: if CI is red, take care of it vs. “assessing it as an acceptable
risk.” It’s not sustainable across hundreds of apps
When you encode you policy, you don’t have to talk to anyone when it’s green
• We run an industrialized Black Duck pipeline
• All upstream and Cloud Foundry produced components are run through a Black
Duck Pipeline
• Alerts are filtered and fed to a clearing house app (Davos - Pivotal internal)
where they are vetted and Tracker stories are assigned to dev teams (there are
66.)
• It is a closed loop systems, Davos get a notification when the story is accepted
• We run this over the last 3 ‘minor’ release (1.10, 1.11, 1.12)
Pivotal PCF Engineering Use Case
• Advocate from the “Shift Risk Left” perspective
• Any automation is a win. Value compounds over time
• Build visibility at the Dev level: If a Dev knows the first day they’ve got out of date,
risky, or dead project, that’ll solve a lot of issues
• Advocate for a policy enforcement processes like Netflix Conformity Monkey
• If security is process, long-term compliance means apps have to have owners. It
can’t be Ops, it needs to be customer facing org
• Advocate for a “Library update” test-set which allows Ops/Sec to test library update
without bothering Devs
• Security teams create and consult on compliance pipelines
Advocating for this model
Questions
Resources
• Concourse OSS Continuous Integration/Delivery
system
• DORA 2017 State of DevOps Report
• CI Conformity Graphic (no ref, but please visit
Martin Fowler for more info)
• Conformity Monkey image, @garrethbowle
• Question Mark graphic
Security in Cloud Native Environments
<— Shift Risk Left
Tony Hansmann (@997unix), Platform Architect at Pivotal

More Related Content

PPTX
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
PDF
Software Security Assurance for DevOps
PDF
Buyer and Seller Perspectives on Open Source in Tech Contracts
PPTX
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
PDF
DevSecOps: The Open Source Way
PPTX
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
PPTX
Leveraging Black Duck Hub to Maximize Focus - Entersekt’s Approach to Empower...
PPTX
Making the Strategic Shift to Open Source at Fujitsu Network Communication
Open Source Insight: Container Tech, Data Centre Security & 2018's Biggest Se...
Software Security Assurance for DevOps
Buyer and Seller Perspectives on Open Source in Tech Contracts
Open Source Insight: Black Duck Announces OpsSight for DevOps Open Source Sec...
DevSecOps: The Open Source Way
Open Source Insight: You Can’t Beat Hackers and the Pentagon Moves into Open...
Leveraging Black Duck Hub to Maximize Focus - Entersekt’s Approach to Empower...
Making the Strategic Shift to Open Source at Fujitsu Network Communication

What's hot (20)

PDF
Open Source Security for Newbies - Best Practices
PPTX
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
PDF
Integrating Black Duck into your Agile DevOps Environment
PDF
The Intersection Between Open Source and Cybersecurity
PDF
Managing Penetration Testing Programs and Vulnerability Time to Live with Thr...
PDF
Bridging the Security Testing Gap in Your CI/CD Pipeline
PDF
DevSecOps and the CI/CD Pipeline
PPTX
Secure application deployment in the age of continuous delivery
PPTX
The How and Why of Container Vulnerability Management
PPT
The Case for Continuous Open Source Management
PDF
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
PDF
Myths and Misperceptions of Open Source Security
PPTX
September 13, 2016: Security in the Age of Open Source:
PPTX
Security in the age of open source - Myths and misperceptions
PDF
Open Source in Application Security
PPTX
Open Source and Cyber Security: Open Source Software's Role in Government Cyb...
PPTX
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
PDF
Application Asset Management with ThreadFix
PPTX
Security in the Age of Open Source
PDF
Securing the container DevOps pipeline by William Henry
Open Source Security for Newbies - Best Practices
Open Source Insight: Black Duck Now Part of Synopsys, Tackling Container Secu...
Integrating Black Duck into your Agile DevOps Environment
The Intersection Between Open Source and Cybersecurity
Managing Penetration Testing Programs and Vulnerability Time to Live with Thr...
Bridging the Security Testing Gap in Your CI/CD Pipeline
DevSecOps and the CI/CD Pipeline
Secure application deployment in the age of continuous delivery
The How and Why of Container Vulnerability Management
The Case for Continuous Open Source Management
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
Myths and Misperceptions of Open Source Security
September 13, 2016: Security in the Age of Open Source:
Security in the age of open source - Myths and misperceptions
Open Source in Application Security
Open Source and Cyber Security: Open Source Software's Role in Government Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Application Asset Management with ThreadFix
Security in the Age of Open Source
Securing the container DevOps pipeline by William Henry
Ad

Similar to Shift Risk Left: Security Considerations When Migrating Apps to the Cloud (20)

PPTX
Shift Left for More Secure Apps with F5 NGINX
PDF
Evolving to Cloud-Native - Anand Rao
PDF
Security Across the Cloud Native Continuum with ESG and Palo Alto Networks
PDF
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
PPTX
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
PDF
Pragmatic Pipeline Security
PDF
The Emergent Cloud Security Toolchain for CI/CD
PPTX
Devops - Accelerating the Pace and Securing Along the Way - Thaddeus Walsh
PPTX
Cloud Native Summit 2019 Summary
PDF
Towards FutureOps: Stable, Repeatable environments from Dev to Prod
PPTX
Crossing the CI/CD/DevOps Chasm
PDF
DevSecOps: essential tooling to enable continuous security 2019-09-16
PDF
Securing a Cloud Migration
PDF
Securing a Cloud Migration
PDF
How to adapt the SDLC to the era of DevSecOps
PPTX
Software Security Assurance for Devops
PPTX
Software Security Assurance for DevOps
PDF
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
PDF
The Future of DevSecOps
PDF
The DevSecOps Builder’s Guide to the CI/CD Pipeline
Shift Left for More Secure Apps with F5 NGINX
Evolving to Cloud-Native - Anand Rao
Security Across the Cloud Native Continuum with ESG and Palo Alto Networks
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
Pragmatic Pipeline Security
The Emergent Cloud Security Toolchain for CI/CD
Devops - Accelerating the Pace and Securing Along the Way - Thaddeus Walsh
Cloud Native Summit 2019 Summary
Towards FutureOps: Stable, Repeatable environments from Dev to Prod
Crossing the CI/CD/DevOps Chasm
DevSecOps: essential tooling to enable continuous security 2019-09-16
Securing a Cloud Migration
Securing a Cloud Migration
How to adapt the SDLC to the era of DevSecOps
Software Security Assurance for Devops
Software Security Assurance for DevOps
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
The Future of DevSecOps
The DevSecOps Builder’s Guide to the CI/CD Pipeline
Ad

More from Black Duck by Synopsys (20)

PDF
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
PDF
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
PDF
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
PDF
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
PDF
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
PDF
Open-Source- Sicherheits- und Risikoanalyse 2018
PDF
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
PDF
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
PDF
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
PDF
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
PPT
FLIGHT Amsterdam Presentation - From Protex to Hub
PPTX
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
PDF
Open Source Rookies and Community
PPTX
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
PPTX
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
PPTX
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
PPTX
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
PPTX
Open Source Insight: Happy Birthday Open Source and Application Security for ...
PPTX
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
PDF
20 Billion Reasons for IoT Security
Flight WEST 2018 Presentation - A Buyer Investor Playbook for Successfully Na...
FLIGHT WEST 2018 Presentation - Continuous Monitoring of Open Source Componen...
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 - Presentation - SCA 101: How to Manage Open Source Security...
FLIGHT WEST 2018 Presentation - Integrating Security into Your Development an...
Open-Source- Sicherheits- und Risikoanalyse 2018
FLIGHT Amsterdam Presentation - Open Source, IP and Trade Secrets: An Impossi...
FLIGHT Amsterdam Presentation - Data Breaches and the Law: A Practical Guide
FLIGHT Amsterdam Presentation - Don’t Let Open Source Software Kill Your Deal
FLIGHT Amsterdam Presentation - Open Source License Management in the Black D...
FLIGHT Amsterdam Presentation - From Protex to Hub
Open Source Insight: GitHub Finds 4M Flaws, IAST Magic Quadrant, 2018 Open So...
Open Source Rookies and Community
Open Source Insight: Who Owns Linux? TRITON Attack, App Security Testing, Fut...
Open Source Insight: SCA for DevOps, DHS Security, Securing Open Source for G...
Open Source Insight: AppSec for DevOps, Open Source vs Proprietary, Malicious...
Open Source Insight: Big Data Breaches, Costly Cyberattacks, Vuln Detection f...
Open Source Insight: Happy Birthday Open Source and Application Security for ...
Open Source Insight: Security Breaches and Cryptocurrency Dominating News
20 Billion Reasons for IoT Security

Recently uploaded (20)

PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
Cloud computing and distributed systems.
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
MYSQL Presentation for SQL database connectivity
PDF
cuic standard and advanced reporting.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
MIND Revenue Release Quarter 2 2025 Press Release
Understanding_Digital_Forensics_Presentation.pptx
Machine learning based COVID-19 study performance prediction
Chapter 3 Spatial Domain Image Processing.pdf
Electronic commerce courselecture one. Pdf
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Mobile App Security Testing_ A Comprehensive Guide.pdf
Cloud computing and distributed systems.
The AUB Centre for AI in Media Proposal.docx
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
MYSQL Presentation for SQL database connectivity
cuic standard and advanced reporting.pdf
Encapsulation_ Review paper, used for researhc scholars
Empathic Computing: Creating Shared Understanding
Digital-Transformation-Roadmap-for-Companies.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
Network Security Unit 5.pdf for BCA BBA.
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
MIND Revenue Release Quarter 2 2025 Press Release

Shift Risk Left: Security Considerations When Migrating Apps to the Cloud

  • 1. <—Shift Risk Left Security Cloud Native Environments
  • 2. Introduction • Tony Hansmann (@997unix), Platform Architect at Pivotal • Recently broke off a twenty year relationship with the pager • Ops persons who accidentally landed at Pivotal, Agile Dev Central • Trying hard to automate Ops away for the F500 • Security, Compliance, and Risk Management are the frontiers of Ops
  • 3. • “Cloud” == getting compute resources from an API • “Cloud Native” == App dev model that assumes APIs for all resources • Apps get easier to push (46x between low and high perf orgs DORA 2017). • We expect app counts to grow 2-4x other next five years • The standard model of App security won’t support this app volume Cloud Native, is that a real thing?
  • 4. • The Left here is the path-to-prod pipeline • Devs are the beginning of that pipeline and we believe they need feedback as soon as possible • The security/change approval process is a big impediment to Cloud Native adoption (or it causes such a big slowdown, there is no point in going cloud) We buy “Security is a process, not a destination”
  • 5. • The worst feeling for an Ops persons is a failure they “should have” known about • Black Duck gives Pivotal a huge advantage by making huge swaths of security trivially knowable • How are the F500 going to “know” about their hundreds of apps that don’t have dev teams behind them? • We’re going to also have to know decade-over-decade • Knowing is a key capability, there’s no way off this wheel • Security is going to Visit you, the only questions is on who’s terms will they visit you? Security and Knowability
  • 6. Black Duck integration with PCF Meta-buildpackDeveloper buildpacks droplet BLOB STORE PCF DEV Operator PCF STAGING PCF PROD Continuous Integration (CI) Concourse, Jenkins, Bamboo, Team City, TFS/VSTS decorators cf push cf push cf push Black Duck Service Broker (cf bind) Black Duck CI Integrations QA
  • 7. • Our fellows who have suffered security breaches often knew all about their exposure - knowing is not enough • You’re going to need CI/CD at a minimum • If you’re a Dev, help Ops and Security by adding Black Duck to your pipelines • If your in Ops or Security, learn your CI/CD system to partner with devs • Have policy in-place for what each team does in the event of CVE and then tie it off with executives • Risk compounds: if CI is red, take care of it vs. “assessing it as an acceptable risk.” It’s not sustainable across hundreds of apps When you encode you policy, you don’t have to talk to anyone when it’s green
  • 8. • We run an industrialized Black Duck pipeline • All upstream and Cloud Foundry produced components are run through a Black Duck Pipeline • Alerts are filtered and fed to a clearing house app (Davos - Pivotal internal) where they are vetted and Tracker stories are assigned to dev teams (there are 66.) • It is a closed loop systems, Davos get a notification when the story is accepted • We run this over the last 3 ‘minor’ release (1.10, 1.11, 1.12) Pivotal PCF Engineering Use Case
  • 9. • Advocate from the “Shift Risk Left” perspective • Any automation is a win. Value compounds over time • Build visibility at the Dev level: If a Dev knows the first day they’ve got out of date, risky, or dead project, that’ll solve a lot of issues • Advocate for a policy enforcement processes like Netflix Conformity Monkey • If security is process, long-term compliance means apps have to have owners. It can’t be Ops, it needs to be customer facing org • Advocate for a “Library update” test-set which allows Ops/Sec to test library update without bothering Devs • Security teams create and consult on compliance pipelines Advocating for this model
  • 11. Resources • Concourse OSS Continuous Integration/Delivery system • DORA 2017 State of DevOps Report • CI Conformity Graphic (no ref, but please visit Martin Fowler for more info) • Conformity Monkey image, @garrethbowle • Question Mark graphic
  • 12. Security in Cloud Native Environments <— Shift Risk Left
  • 13. Tony Hansmann (@997unix), Platform Architect at Pivotal