SlideShare a Scribd company logo
Application Security
Testing for the
DevOps Mindset
October 2018
DevOps Is Coming!
2
Some Security Teams Will Adapt, Others Will Not
3
Security Advantages: Auditability
4
Security Advantages: Automation
5
Security Advantages: Collaboration
6
Use This Transition to Your Advantage
7
Use This Transition to Your Advantage
8
Move Security to the Left and Get Buy-In
9
Better Security Insight, More Often
10
So What Does Application Security Want?
11
• Reduce Risk Exposure
• Introduce Fewer Vulnerabilities
• Find Vulnerabilities Early
• Fix Vulnerabilities Quickly
And What Do DevOps Teams Want?
12
How Do We Make This a Reality?
13
Application Security Testing in CI/CD Pipelines
14
Security People Love Policies
15
Effective Application Security Testing
16
• Reduce Noise
• Run Fast
Testing Tradeoffs
17
Decision-Making Factors
18
Reporting Recommendations
19
Hint: Not With These…
© confidential 20
ThreadFix Application Security Platform
ThreadFix helps enterprises manage application security vulnerabilities
Scanner
Integration
Vulnerability
Correlation
Faster
Vulnerability
Rem edition
ThreadFix Workflow
SAST, DAST,
IAST Scanner
Tools
Manual
Assessments
3rd Party Manual
Assessments
AppSec False Positive
Assessments
Reporting
& Analytics
Defect
Trackers
IDEs
GAC
Threadfix scanner
integrations
• ThreadFix creates a single
comprehensive view of the
security status of all applications
within an organization
• Provides a comprehensive view of
software security for an
organization by aggregating
vulnerability test results, scanning
tools, manual penetration and
code review
• Integrates security into
development workflow
• Provides automation for
application security assessment
• Helps prioritize vulnerabilities and
enable higher level risk decision
• ThreadFix infrastructure integrates
security and DevOps
environments
• The platform allows organizations
to embed security into
organizations’ Continuous
Integration / Continuous Delivery
(CI/CD) pipelines
ThreadFix Integrates Security into DevOps
Development
Defect
Tracker
CI/CD
SAST
DAST
IAST
Risk Management &
Compliance World
Code/Apps to Test
CI/CD Security
Policy
Defects
Code
Repositor
y
GRC
Capabilities of Integration
§ Create a consolidated view of applications and
vulnerabilities
§ Prioritize vulnerabilities to enable decision
making
§ Streamline remediation by translating
vulnerability data for developers in the tools they
already use
Metrics
Penetration Testing
Vulnerability Testing
3rd Party Reviews
Security
Application
Vulnerabilities
Orchestration & Automation
Risk&Compliance
© confidential 22
Case Study: Secure DevOps with ThreadFix in Financial Services
Vulnerability consolidation and
reporting using Jira
Integrates AppSec in
to CI/CD pipelines
Earlier knowledge of security
issues and increased fix rate
ThreadFix platform used to both manage results from DevOps CI/CD pipeline application security
testing as well as more comprehensive application security testing efforts, providing a single centralized
view of all application security testing activities
Applying In Your Organization
23
Next week you should:
• Pick a DevOps team and take the development manager to lunch – talk about their
tools and processes
In the first three months following this presentation you should:
• Enumerate the DevOps teams in your organization and the applications they are
building
• Craft a couple of policies that are appropriate for different types of applications in your
environment
• Integrate application security testing into one CI/CD pipeline
Within six months you should:
• Have a schedule to get application security testing spread across your portfolio
Thank you
for your time

More Related Content

What's hot (20)

PPTX
DevSecOps - It can change your life (cycle)
Qualitest
 
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Puppet
 
PPTX
AppSec++ Take the best of Agile, DevOps and CI/CD into your AppSec Program
Matt Tesauro
 
PPTX
The End of Security as We Know It - Shannon Lietz
SeniorStoryteller
 
PDF
Blending Automated and Manual Testing
Denim Group
 
ODP
Building an Open Source AppSec Pipeline - 2015 Texas Linux Fest
Matt Tesauro
 
ODP
Matt tesauro Lessons from DevOps: Taking DevOps practices into your AppSec Li...
Matt Tesauro
 
PPTX
DevOps is for Everyone - DevOps East
Chris Riley ☁
 
PDF
From rogue one to rebel alliance by Peter Chestna
DevSecCon
 
PDF
Ast in CI/CD by Ofer Maor
DevSecCon
 
PDF
Devops: A History
Nell Shamrell-Harrington
 
PPTX
DevOps Transformations
Ernest Mueller
 
PDF
Devops: Security's big opportunity by Peter Chestna
DevSecCon
 
PDF
A Secure DevOps Journey
Sonatype
 
PDF
SDLC & DevSecOps
Irina Kostina
 
PDF
DevOps: A Culture Transformation, More than Technology
CA Technologies
 
PDF
Zen and the art of Security Testing
TEST Huddle
 
PDF
New Era of Software with modern Application Security v1.0
Dinis Cruz
 
PPTX
KEYNOTE | WHAT'S COMING IN THE NEXT 10 YEARS OF DEVOPS? // ELLEN CHISA, bolds...
DevOpsDays Tel Aviv
 
PDF
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
DevSecOpsSg
 
DevSecOps - It can change your life (cycle)
Qualitest
 
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Puppet
 
AppSec++ Take the best of Agile, DevOps and CI/CD into your AppSec Program
Matt Tesauro
 
The End of Security as We Know It - Shannon Lietz
SeniorStoryteller
 
Blending Automated and Manual Testing
Denim Group
 
Building an Open Source AppSec Pipeline - 2015 Texas Linux Fest
Matt Tesauro
 
Matt tesauro Lessons from DevOps: Taking DevOps practices into your AppSec Li...
Matt Tesauro
 
DevOps is for Everyone - DevOps East
Chris Riley ☁
 
From rogue one to rebel alliance by Peter Chestna
DevSecCon
 
Ast in CI/CD by Ofer Maor
DevSecCon
 
Devops: A History
Nell Shamrell-Harrington
 
DevOps Transformations
Ernest Mueller
 
Devops: Security's big opportunity by Peter Chestna
DevSecCon
 
A Secure DevOps Journey
Sonatype
 
SDLC & DevSecOps
Irina Kostina
 
DevOps: A Culture Transformation, More than Technology
CA Technologies
 
Zen and the art of Security Testing
TEST Huddle
 
New Era of Software with modern Application Security v1.0
Dinis Cruz
 
KEYNOTE | WHAT'S COMING IN THE NEXT 10 YEARS OF DEVOPS? // ELLEN CHISA, bolds...
DevOpsDays Tel Aviv
 
The Rise of DevSecOps - Fabian Lim - DevSecOpsSg
DevSecOpsSg
 

Similar to Application Security Testing for a DevOps Mindset (20)

PDF
ThreadFix 2.5 Webinar
Denim Group
 
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
PPTX
DevSecOps without DevOps is Just Security
Kevin Fealey
 
PDF
Security at the Speed of Software Development
DevOps.com
 
PDF
Introduction to DevSecOps
Setu Parimi
 
PPTX
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
PPTX
State of DevSecOps - GTACS 2019
Stefan Streichsbier
 
PDF
DevSecOps: essential tooling to enable continuous security 2019-09-16
Rich Mills
 
PDF
Top 20 DevSecOps Interview Questions and Answers
priyanshamadhwal2
 
PDF
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
PDF
𝐓𝐨𝐩 𝟐𝟎 𝐃𝐞𝐯𝐒𝐞𝐜𝐎𝐩𝐬 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
InfosecTrain
 
PDF
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
PDF
🚨 𝐀𝐫𝐞 𝐘𝐨𝐮 𝐑𝐞𝐚𝐝𝐲 𝐭𝐨 𝐀𝐜𝐞 𝐘𝐨𝐮𝐫 𝐃𝐞𝐯𝐒𝐞𝐜𝐎𝐩𝐬 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰? 🚨
Mansi Kandari
 
PDF
Are You Ready to Ace Your DevSecOps Interview?
Azpirantz Technologies
 
PDF
Top 20 DevsecOps Interview Questions.pdf
infosecTrain
 
PDF
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
PDF
Security's DevOps Transformation
Michele Chubirka
 
PPTX
DevOps to DevSecOps: Enhancing Software Security Throughout The Development L...
Anowar Hossain
 
PPTX
Introduction to DevSecOps
abhimanyubhogwan
 
PDF
Webinar–Creating a Modern AppSec Toolchain to Quantify Service Risks
Synopsys Software Integrity Group
 
ThreadFix 2.5 Webinar
Denim Group
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
DevSecOps without DevOps is Just Security
Kevin Fealey
 
Security at the Speed of Software Development
DevOps.com
 
Introduction to DevSecOps
Setu Parimi
 
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
State of DevSecOps - GTACS 2019
Stefan Streichsbier
 
DevSecOps: essential tooling to enable continuous security 2019-09-16
Rich Mills
 
Top 20 DevSecOps Interview Questions and Answers
priyanshamadhwal2
 
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
𝐓𝐨𝐩 𝟐𝟎 𝐃𝐞𝐯𝐒𝐞𝐜𝐎𝐩𝐬 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
InfosecTrain
 
Top 20 DevSecOps Interview Questions.pdf
infosec train
 
🚨 𝐀𝐫𝐞 𝐘𝐨𝐮 𝐑𝐞𝐚𝐝𝐲 𝐭𝐨 𝐀𝐜𝐞 𝐘𝐨𝐮𝐫 𝐃𝐞𝐯𝐒𝐞𝐜𝐎𝐩𝐬 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰? 🚨
Mansi Kandari
 
Are You Ready to Ace Your DevSecOps Interview?
Azpirantz Technologies
 
Top 20 DevsecOps Interview Questions.pdf
infosecTrain
 
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
Security's DevOps Transformation
Michele Chubirka
 
DevOps to DevSecOps: Enhancing Software Security Throughout The Development L...
Anowar Hossain
 
Introduction to DevSecOps
abhimanyubhogwan
 
Webinar–Creating a Modern AppSec Toolchain to Quantify Service Risks
Synopsys Software Integrity Group
 
Ad

More from Denim Group (20)

PDF
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
Denim Group
 
PDF
Optimizing Security Velocity in Your DevSecOps Pipeline at Scale
Denim Group
 
PDF
Application Asset Management with ThreadFix
Denim Group
 
PDF
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
Denim Group
 
PDF
Using Collaboration to Make Application Vulnerability Management a Team Sport
Denim Group
 
PDF
Managing Penetration Testing Programs and Vulnerability Time to Live with Thr...
Denim Group
 
PDF
Security Champions: Pushing Security Expertise to the Edges of Your Organization
Denim Group
 
PDF
The As, Bs, and Four Cs of Testing Cloud-Native Applications
Denim Group
 
PDF
An Updated Take: Threat Modeling for IoT Systems
Denim Group
 
PPTX
Continuous Authority to Operate (ATO) with ThreadFix – Bringing Commercial In...
Denim Group
 
PDF
A New View of Your Application Security Program with Snyk and ThreadFix
Denim Group
 
PDF
Enabling Developers in Your Application Security Program With Coverity and Th...
Denim Group
 
PDF
AppSec in a World of Digital Transformation
Denim Group
 
PDF
The As, Bs, and Four Cs of Testing Cloud-Native Applications
Denim Group
 
PDF
Enabling Developers in Your Application Security Program With Coverity and Th...
Denim Group
 
PDF
AppSec in a World of Digital Transformation
Denim Group
 
PDF
Enumerating Enterprise Attack Surface
Denim Group
 
PDF
Enumerating Enterprise Attack Surface
Denim Group
 
PDF
Assessing Business Operations Risk With Unified Vulnerability Management in T...
Denim Group
 
PDF
An OWASP SAMM Perspective on Serverless Computing
Denim Group
 
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
Denim Group
 
Optimizing Security Velocity in Your DevSecOps Pipeline at Scale
Denim Group
 
Application Asset Management with ThreadFix
Denim Group
 
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
Denim Group
 
Using Collaboration to Make Application Vulnerability Management a Team Sport
Denim Group
 
Managing Penetration Testing Programs and Vulnerability Time to Live with Thr...
Denim Group
 
Security Champions: Pushing Security Expertise to the Edges of Your Organization
Denim Group
 
The As, Bs, and Four Cs of Testing Cloud-Native Applications
Denim Group
 
An Updated Take: Threat Modeling for IoT Systems
Denim Group
 
Continuous Authority to Operate (ATO) with ThreadFix – Bringing Commercial In...
Denim Group
 
A New View of Your Application Security Program with Snyk and ThreadFix
Denim Group
 
Enabling Developers in Your Application Security Program With Coverity and Th...
Denim Group
 
AppSec in a World of Digital Transformation
Denim Group
 
The As, Bs, and Four Cs of Testing Cloud-Native Applications
Denim Group
 
Enabling Developers in Your Application Security Program With Coverity and Th...
Denim Group
 
AppSec in a World of Digital Transformation
Denim Group
 
Enumerating Enterprise Attack Surface
Denim Group
 
Enumerating Enterprise Attack Surface
Denim Group
 
Assessing Business Operations Risk With Unified Vulnerability Management in T...
Denim Group
 
An OWASP SAMM Perspective on Serverless Computing
Denim Group
 
Ad

Recently uploaded (20)

PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
PDF
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PPTX
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
PDF
Python basic programing language for automation
DanialHabibi2
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
PDF
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
PPTX
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PDF
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
From Code to Challenge: Crafting Skill-Based Games That Engage and Reward
aiyshauae
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
Python basic programing language for automation
DanialHabibi2
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
Achieving Consistent and Reliable AI Code Generation - Medusa AI
medusaaico
 
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 

Application Security Testing for a DevOps Mindset

  • 1. Application Security Testing for the DevOps Mindset October 2018
  • 3. Some Security Teams Will Adapt, Others Will Not 3
  • 7. Use This Transition to Your Advantage 7
  • 8. Use This Transition to Your Advantage 8
  • 9. Move Security to the Left and Get Buy-In 9
  • 10. Better Security Insight, More Often 10
  • 11. So What Does Application Security Want? 11 • Reduce Risk Exposure • Introduce Fewer Vulnerabilities • Find Vulnerabilities Early • Fix Vulnerabilities Quickly
  • 12. And What Do DevOps Teams Want? 12
  • 13. How Do We Make This a Reality? 13
  • 14. Application Security Testing in CI/CD Pipelines 14
  • 15. Security People Love Policies 15
  • 16. Effective Application Security Testing 16 • Reduce Noise • Run Fast
  • 20. © confidential 20 ThreadFix Application Security Platform ThreadFix helps enterprises manage application security vulnerabilities Scanner Integration Vulnerability Correlation Faster Vulnerability Rem edition ThreadFix Workflow SAST, DAST, IAST Scanner Tools Manual Assessments 3rd Party Manual Assessments AppSec False Positive Assessments Reporting & Analytics Defect Trackers IDEs GAC Threadfix scanner integrations • ThreadFix creates a single comprehensive view of the security status of all applications within an organization • Provides a comprehensive view of software security for an organization by aggregating vulnerability test results, scanning tools, manual penetration and code review • Integrates security into development workflow • Provides automation for application security assessment • Helps prioritize vulnerabilities and enable higher level risk decision • ThreadFix infrastructure integrates security and DevOps environments • The platform allows organizations to embed security into organizations’ Continuous Integration / Continuous Delivery (CI/CD) pipelines
  • 21. ThreadFix Integrates Security into DevOps Development Defect Tracker CI/CD SAST DAST IAST Risk Management & Compliance World Code/Apps to Test CI/CD Security Policy Defects Code Repositor y GRC Capabilities of Integration § Create a consolidated view of applications and vulnerabilities § Prioritize vulnerabilities to enable decision making § Streamline remediation by translating vulnerability data for developers in the tools they already use Metrics Penetration Testing Vulnerability Testing 3rd Party Reviews Security Application Vulnerabilities Orchestration & Automation Risk&Compliance
  • 22. © confidential 22 Case Study: Secure DevOps with ThreadFix in Financial Services Vulnerability consolidation and reporting using Jira Integrates AppSec in to CI/CD pipelines Earlier knowledge of security issues and increased fix rate ThreadFix platform used to both manage results from DevOps CI/CD pipeline application security testing as well as more comprehensive application security testing efforts, providing a single centralized view of all application security testing activities
  • 23. Applying In Your Organization 23 Next week you should: • Pick a DevOps team and take the development manager to lunch – talk about their tools and processes In the first three months following this presentation you should: • Enumerate the DevOps teams in your organization and the applications they are building • Craft a couple of policies that are appropriate for different types of applications in your environment • Integrate application security testing into one CI/CD pipeline Within six months you should: • Have a schedule to get application security testing spread across your portfolio