SlideShare a Scribd company logo
Why DevOps != the Wild
West and How Embracing
it Can Improve Security
Dan Cundiff (@pmotch)
Target Corporation
A true story about saying NO to DevOps
Empathizing with the wild west POV
Us vs them
&
The Local Optima problem
Dev incentive: speed of shipping
Ops incentive: availability
Ops thinks actions by Dev to
↑ speed of shipping
means availability ↓
Dev thinks actions by Ops to
↑ availability
means speed of shipping ↓
Security thinks actions by Dev to
↑ speed of shipping
means security ↓
Dev thinks actions by Security to
↑ security
means speed of shipping ↓
“A system of local optimums is not an
optimum system at all; it is a very
inefficient system.”
So how can we have both?
DevOps!
Dev + Ops + SecOps = DevOpsSec
Examples across CALMS spectrum:
Culture
Automation
Lean
Measurement
Sharing
continuous integration
+
code scanning
continuous integration
+
vulnerability scanning
CI encourages smaller changes, making it
easier to spot security issues
Social coding
=
Who changed what, when, and why;
git blame + pull request commentary
Social coding
=
A pull request is a code review
Social coding
=
PRs seeking +1s from security partners
Social coding
=
Ability to ask questions on any line of code
Security documentation as code
Security team’s processes and tools need to
be responsive to CI/CD
(e.g. FIM configurable
continuously vs quarterly)
Give security access to your backlogs;
tag commits with issue IDs
ChatOps, conversation-driven
development, stitching in security events,
security teams listening and talking, etc.
Dev and Ops sharing metrics/logs
Better coverage; melds silos of
responsibility
Blameless post mortems, even for security
https://codeascraft.com/2012/05/22/blameless-postmortems/
Infrastructure-as-code
=
fast testable mass patches
Infrastructure-as-code
=
knowing if a security change broke the app
Infrastructure-as-code
=
clear state of security config
We need APIs to security vendor products
http://devops.com/blogs/devops-a-wake-up-call-to-security-vendors/
Auditors like it.*
Reduced human involvement.
Share what you’re learning and doing
inside and outside of the company.
Leaders, think Kaisen. Value all employee’s
ideas across Dev and Sec/Ops.
Leaders, find the risk takers pioneering
this, and protect them.
Pioneers, find your forward-thinking
security partners and bring them along
with you.
We are hiring!
Thanks!
Dan Cundiff (@pmotch)
Target Corporation

More Related Content

PDF
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
PDF
DevSecCon Asia 2017 - Abhay Bhargav: Building an Application Vulnerability To...
PDF
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
PDF
Securing the container DevOps pipeline by William Henry
PPTX
Turning security into code by Jeff Williams
PPTX
Shifting left – embedding security into the devops pipeline by Mike d. Kail
PDF
Shifting Security Left - The Innovation of DevSecOps - AgileDC
PDF
DevSecCon Asia 2017 Ante Gulam: Integrating crowdsourced security into agile ...
DevSecCon Asia 2017 Ofer Maor: AppSec DevOps automation – real world cases
DevSecCon Asia 2017 - Abhay Bhargav: Building an Application Vulnerability To...
Shift Risk Left: Security Considerations When Migrating Apps to the Cloud
Securing the container DevOps pipeline by William Henry
Turning security into code by Jeff Williams
Shifting left – embedding security into the devops pipeline by Mike d. Kail
Shifting Security Left - The Innovation of DevSecOps - AgileDC
DevSecCon Asia 2017 Ante Gulam: Integrating crowdsourced security into agile ...

What's hot (20)

PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
PDF
DevSecCon Asia 2017 Pishu Mahtani: Adversarial Modelling
PPTX
Lessons learned from Detroit to Deming by Derek Weeks
PDF
EuroPython 2019: Modern Continuous Delivery for Python Developers
PDF
Renato Rodrigues - Security in the wild
PDF
DevSecOps and the CI/CD Pipeline
PDF
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
PPTX
Chefdevseccon2015
PPTX
Matt carroll - "Security patching system packages is fun" said no-one ever
PPTX
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
PPTX
Shifting Security Left from the Lean+Agile 2019 Conference
PDF
Henrique Dantas - API fuzzing using Swagger
PDF
Integrating DevOps and Security
PPTX
Integrating security into Continuous Delivery
PDF
Bridging the Security Testing Gap in Your CI/CD Pipeline
PPTX
ABN AMRO DevSecOps Journey
PDF
TechTalk 2021: Peran IT Security dalam Penerapan DevOps
PDF
Continuous Integration @ Haptik
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
DevSecCon Asia 2017 Pishu Mahtani: Adversarial Modelling
Lessons learned from Detroit to Deming by Derek Weeks
EuroPython 2019: Modern Continuous Delivery for Python Developers
Renato Rodrigues - Security in the wild
DevSecOps and the CI/CD Pipeline
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Chefdevseccon2015
Matt carroll - "Security patching system packages is fun" said no-one ever
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
Shifting Security Left from the Lean+Agile 2019 Conference
Henrique Dantas - API fuzzing using Swagger
Integrating DevOps and Security
Integrating security into Continuous Delivery
Bridging the Security Testing Gap in Your CI/CD Pipeline
ABN AMRO DevSecOps Journey
TechTalk 2021: Peran IT Security dalam Penerapan DevOps
Continuous Integration @ Haptik
Ad

Viewers also liked (8)

PDF
How to Build APIs - MHacks 2016
PDF
2016 State of DevOps
PDF
The DevOpsSec Dilemma | Lean Agile Scotland 2015
PPTX
Devopssecfail
PDF
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
PPTX
DevSecOps - CrikeyCon 2017
KEY
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
PDF
Adopting a security attitude in DevOps via DevOpsSec
How to Build APIs - MHacks 2016
2016 State of DevOps
The DevOpsSec Dilemma | Lean Agile Scotland 2015
Devopssecfail
2017-02-21 AFCEA West Building Continuous Integration & Deployment (CI/CD) Pi...
DevSecOps - CrikeyCon 2017
DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012
Adopting a security attitude in DevOps via DevOpsSec
Ad

Similar to Why DevOps != the Wild West and How Embracing it Can Improve Security - RSA Conference 2015 (20)

PPTX
Introduction to DevSecOps
PDF
Introduction to DevOps
PPTX
Threat Modeling All Day!
PDF
2021-10-14 The Critical Role of Security in DevOps.pdf
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
PPTX
Dev{sec}ops
PDF
Protecting Agile Transformation through Secure DevOps (DevSecOps)
PPTX
Introduction to DevOps in Cloud Computing.pptx
PPTX
DevOps Introduction
PDF
From DevOps to DevSecOps: Evolution of Secure Software Development
PPTX
DevSecOps : an Introduction
PDF
Zero to Ninety in Securing DevOps
DOCX
Is DevOps The Future of Software Development.docx
PDF
Strengthen and Scale Security for a dollar or less
PDF
How DevOps Development Companies Streamline Operations.pdf
PDF
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
PPTX
DevSecOps: Integrating Security Into DevOps! {Business Security}
PDF
Scale security for a dollar or less
PPTX
DevSecOps with Microsoft Tech
PPTX
From Continuous Integration to DevOps
Introduction to DevSecOps
Introduction to DevOps
Threat Modeling All Day!
2021-10-14 The Critical Role of Security in DevOps.pdf
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Dev{sec}ops
Protecting Agile Transformation through Secure DevOps (DevSecOps)
Introduction to DevOps in Cloud Computing.pptx
DevOps Introduction
From DevOps to DevSecOps: Evolution of Secure Software Development
DevSecOps : an Introduction
Zero to Ninety in Securing DevOps
Is DevOps The Future of Software Development.docx
Strengthen and Scale Security for a dollar or less
How DevOps Development Companies Streamline Operations.pdf
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
DevSecOps: Integrating Security Into DevOps! {Business Security}
Scale security for a dollar or less
DevSecOps with Microsoft Tech
From Continuous Integration to DevOps

More from Dan Cundiff (6)

PPTX
Governance to Guidance to Awesome Product - DOES 2018
PDF
How Target Made It Super Easy for Developers to Contribute to Open Source - L...
PDF
From No Git to 3000 GitHub Users and How to Keep Them Happy - GitHub Universe...
PDF
Jenkins User Conference 2014
PDF
Apache Cassandra at Target - Cassandra Summit 2014
PPTX
Splunk All the Things: Our First 3 Months Monitoring Web Service APIs - Splun...
Governance to Guidance to Awesome Product - DOES 2018
How Target Made It Super Easy for Developers to Contribute to Open Source - L...
From No Git to 3000 GitHub Users and How to Keep Them Happy - GitHub Universe...
Jenkins User Conference 2014
Apache Cassandra at Target - Cassandra Summit 2014
Splunk All the Things: Our First 3 Months Monitoring Web Service APIs - Splun...

Recently uploaded (20)

PDF
Adobe Illustrator 28.6 Crack My Vision of Vector Design
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PPTX
Introduction to Artificial Intelligence
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Understanding Forklifts - TECH EHS Solution
PDF
top salesforce developer skills in 2025.pdf
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Reimagine Home Health with the Power of Agentic AI​
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
L1 - Introduction to python Backend.pptx
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PPTX
history of c programming in notes for students .pptx
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
Adobe Illustrator 28.6 Crack My Vision of Vector Design
CHAPTER 2 - PM Management and IT Context
Which alternative to Crystal Reports is best for small or large businesses.pdf
Introduction to Artificial Intelligence
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Understanding Forklifts - TECH EHS Solution
top salesforce developer skills in 2025.pdf
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Wondershare Filmora 15 Crack With Activation Key [2025
Reimagine Home Health with the Power of Agentic AI​
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
L1 - Introduction to python Backend.pptx
Odoo Companies in India – Driving Business Transformation.pdf
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
history of c programming in notes for students .pptx
How to Choose the Right IT Partner for Your Business in Malaysia
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
VVF-Customer-Presentation2025-Ver1.9.pptx

Why DevOps != the Wild West and How Embracing it Can Improve Security - RSA Conference 2015