SlideShare a Scribd company logo
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Common causes of technical debt
Insufficient up-
front definition
Business pressures
Lack of process or
understanding
Tightly-coupled
components
Lack of
documentation
Last minute
specification
changes
Cost of an error
0
5
10
15
20
25
30
35
Concept Design Develop Test Release
A real-world example of
catching a bug in production is
the Samsung Note 7 fiasco.
This bug fix cost them nearly
$17 billion. Had the company
caught the issue earlier, they
could have saved a lot of
money and headaches, as well
as their reputation.
DevOps
Design
Code
BuildDeploy
Monitor
=> DevSecOps
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Define “secure”
0 ? 1 ?0.X ?
The Open Web
Application
Security Project is a
nonprofit
foundation that
works to improve
the security of
software.
OWASP
• https://owasp.org/www-project-top-ten/
• https://owasp.org/www-project-mobile-top-10/
• https://owasp.org/www-project-zap/
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
STRIDE
• AuthenticitySpoofing
• IntegrityTampering
• Non-repudiabilityRepudiation
• ConfidentialityInformation disclosure
• AvailabilityDenial of Service
• AuthorizationElevation of Privilege
Microsoft threat modeling tool
https://www.microsoft.com/en-us/securityengineering/sdl/threatmodeling
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Azure KeyVault
Azure Key Vault is a
tool for securely
storing and accessing
secrets.
A secret is anything
that you want to
tightly control access
to, such as API keys,
passwords, or
certificates.
A vault is a logical
group of secrets.
Azure VM
Code
MSI extension
Credentials
Azure AD
Azure KeyVault
Azure platform
1
2
3
Azure KeyVault
https://docs.microsoft.com/en-us/aspnet/core/security/key-vault-configuration
Azure Key Vault is a
tool for securely
storing and accessing
secrets.
A secret is anything
that you want to
tightly control access
to, such as API keys,
passwords, or
certificates.
A vault is a logical
group of secrets.
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
WhiteSource Bolt
https://whitesourcesoftware.com
https://bolt.whitesourcesoftware.com
Shyk
https://snyk.io
SonarQube
https://sonarqube.org
https://sonarcloud.io
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Azure Security Toolkit
https://azsk.azurewebsites.net
https://github.com/azsk
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"
Azure Security Center
https://azure.microsoft.com/en-us/services/security-center/
https://docs.microsoft.com/en-us/azure/security-center/
Questions?
Anton Boyko
Microsoft Azure MVP
me@boykoant.pro

More Related Content

PPTX
Mark Rendle ".NET Is Dead. Long Live .NET!"
Fwdays
 
PDF
Sergii Bielskyi "Azure Logic App and building modern cloud native apps"
Fwdays
 
PPTX
Integration-Monday-Logic-Apps-Tips-Tricks
BizTalk360
 
PPTX
"Project Tye to Tie .NET Microservices", Oleg Karasik
Fwdays
 
PPTX
Welcome to the microsoft madness
명신 김
 
PDF
Connect(); 2016 한시간 총정리
명신 김
 
PDF
GitLab Commit: Enhance your Compliance with Policy-Based CI/CD
Nico Meisenzahl
 
PPTX
Create a Windows 8 App in minutes
Frank La Vigne
 
Mark Rendle ".NET Is Dead. Long Live .NET!"
Fwdays
 
Sergii Bielskyi "Azure Logic App and building modern cloud native apps"
Fwdays
 
Integration-Monday-Logic-Apps-Tips-Tricks
BizTalk360
 
"Project Tye to Tie .NET Microservices", Oleg Karasik
Fwdays
 
Welcome to the microsoft madness
명신 김
 
Connect(); 2016 한시간 총정리
명신 김
 
GitLab Commit: Enhance your Compliance with Policy-Based CI/CD
Nico Meisenzahl
 
Create a Windows 8 App in minutes
Frank La Vigne
 

What's hot (20)

PPTX
Integration Monday - Logic Apps: Development Experiences
BizTalk360
 
PPTX
Serverless Minimalism: How to architect your apps to save 98% on your Azure b...
BizTalk360
 
PDF
Was ist ein Service Mesh und wie funktioniert es?
Cloud Native Rosenheim Meetup
 
PPTX
Microservices with Minimal APi and .NET 6
Miguel Angel Teheran Garcia
 
PDF
GitLab Commit DevOps: How GitLab Can Save your Kubernetes environment from Be...
Nico Meisenzahl
 
PDF
The building blocks of the next web, from Customer Journey to UI Components. ...
Codemotion
 
PDF
Web is the New Mobile: Building Progressive Web Apps - Erica Stanley - Codemo...
Codemotion
 
PDF
Azure Saturday Hamburg: Containerize Your .NET Microservice - the Right Way!
Nico Meisenzahl
 
PPTX
All Around Azure: DevOps with GitHub - Managing the Flow of Work
Davide Benvegnù
 
PDF
Die Evolution von Container Image Builds
Nico Meisenzahl
 
PDF
Your own kubernetes castle
LibbySchulze
 
PDF
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
 
PDF
DevOpsCon Berlin: Helm vs Operators – Do I Need to Decide?
Nico Meisenzahl
 
PDF
Monitoring the #DevOps way
Theo Schlossnagle
 
PPTX
FestiveTechCalendar2021 - Have Yourself An​ Azure Container Registry
Philip Welz
 
PDF
ChatOps in Action
Todd Kaplinger
 
PPTX
Building The Wix SDK
David Zuckerman
 
PDF
Azure Meetup Hamburg: Production-Ready Terraform Deployments on Azure
Nico Meisenzahl
 
PDF
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
 
PDF
Create A Mapping Web Part
Tom Resing
 
Integration Monday - Logic Apps: Development Experiences
BizTalk360
 
Serverless Minimalism: How to architect your apps to save 98% on your Azure b...
BizTalk360
 
Was ist ein Service Mesh und wie funktioniert es?
Cloud Native Rosenheim Meetup
 
Microservices with Minimal APi and .NET 6
Miguel Angel Teheran Garcia
 
GitLab Commit DevOps: How GitLab Can Save your Kubernetes environment from Be...
Nico Meisenzahl
 
The building blocks of the next web, from Customer Journey to UI Components. ...
Codemotion
 
Web is the New Mobile: Building Progressive Web Apps - Erica Stanley - Codemo...
Codemotion
 
Azure Saturday Hamburg: Containerize Your .NET Microservice - the Right Way!
Nico Meisenzahl
 
All Around Azure: DevOps with GitHub - Managing the Flow of Work
Davide Benvegnù
 
Die Evolution von Container Image Builds
Nico Meisenzahl
 
Your own kubernetes castle
LibbySchulze
 
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
 
DevOpsCon Berlin: Helm vs Operators – Do I Need to Decide?
Nico Meisenzahl
 
Monitoring the #DevOps way
Theo Schlossnagle
 
FestiveTechCalendar2021 - Have Yourself An​ Azure Container Registry
Philip Welz
 
ChatOps in Action
Todd Kaplinger
 
Building The Wix SDK
David Zuckerman
 
Azure Meetup Hamburg: Production-Ready Terraform Deployments on Azure
Nico Meisenzahl
 
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
 
Create A Mapping Web Part
Tom Resing
 
Ad

Similar to Anton Boyko "DevSecOps for developers – why it’s important and how to get started?" (9)

PPTX
Azure Key Vault - Getting Started
Taswar Bhatti
 
PPTX
Managing your secrets in a cloud environment
Taswar Bhatti
 
PPTX
DevSecOps: Securing Applications with DevOps
Wouter de Kort
 
PDF
New Era of Software with modern Application Security (v0.6)
Dinis Cruz
 
PDF
Secretsth-Azure-KeyVault-and-Azure-App.pdf
s87j3
 
PDF
Secretsth-Azure-KeyVault-and-Azure-App.pdf
s87j3
 
PDF
Secure Your Code Implement DevSecOps in Azure
kloia
 
PDF
Vault and Security as a Service
Patrick Shields
 
PPTX
Azure Low Lands 2019 - Building secure cloud applications with Azure Key Vault
Tom Kerkhove
 
Azure Key Vault - Getting Started
Taswar Bhatti
 
Managing your secrets in a cloud environment
Taswar Bhatti
 
DevSecOps: Securing Applications with DevOps
Wouter de Kort
 
New Era of Software with modern Application Security (v0.6)
Dinis Cruz
 
Secretsth-Azure-KeyVault-and-Azure-App.pdf
s87j3
 
Secretsth-Azure-KeyVault-and-Azure-App.pdf
s87j3
 
Secure Your Code Implement DevSecOps in Azure
kloia
 
Vault and Security as a Service
Patrick Shields
 
Azure Low Lands 2019 - Building secure cloud applications with Azure Key Vault
Tom Kerkhove
 
Ad

More from Fwdays (20)

PDF
"Mastering UI Complexity: State Machines and Reactive Patterns at Grammarly",...
Fwdays
 
PDF
"Effect, Fiber & Schema: tactical and technical characteristics of Effect.ts"...
Fwdays
 
PPTX
"Computer Use Agents: From SFT to Classic RL", Maksym Shamrai
Fwdays
 
PPTX
"Як ми переписали Сільпо на Angular", Євген Русаков
Fwdays
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
"Validation and Observability of AI Agents", Oleksandr Denisyuk
Fwdays
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PDF
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
PPTX
"Co-Authoring with a Machine: What I Learned from Writing a Book on Generativ...
Fwdays
 
PPTX
"Human-AI Collaboration Models for Better Decisions, Faster Workflows, and Cr...
Fwdays
 
PDF
"AI is already here. What will happen to your team (and your role) tomorrow?"...
Fwdays
 
PPTX
"Is it worth investing in AI in 2025?", Alexander Sharko
Fwdays
 
PDF
''Taming Explosive Growth: Building Resilience in a Hyper-Scaled Financial Pl...
Fwdays
 
PDF
"Scaling in space and time with Temporal", Andriy Lupa.pdf
Fwdays
 
PDF
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
 
PDF
"Scaling in space and time with Temporal", Andriy Lupa .pdf
Fwdays
 
PPTX
"Provisioning via DOT-Chain: from catering to drone marketplaces", Volodymyr ...
Fwdays
 
PPTX
" Observability with Elasticsearch: Best Practices for High-Load Platform", A...
Fwdays
 
PPTX
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
Fwdays
 
PPTX
"Istio Ambient Mesh in production: our way from Sidecar to Sidecar-less",Hlib...
Fwdays
 
"Mastering UI Complexity: State Machines and Reactive Patterns at Grammarly",...
Fwdays
 
"Effect, Fiber & Schema: tactical and technical characteristics of Effect.ts"...
Fwdays
 
"Computer Use Agents: From SFT to Classic RL", Maksym Shamrai
Fwdays
 
"Як ми переписали Сільпо на Angular", Євген Русаков
Fwdays
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
"Validation and Observability of AI Agents", Oleksandr Denisyuk
Fwdays
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
"Beyond English: Navigating the Challenges of Building a Ukrainian-language R...
Fwdays
 
"Co-Authoring with a Machine: What I Learned from Writing a Book on Generativ...
Fwdays
 
"Human-AI Collaboration Models for Better Decisions, Faster Workflows, and Cr...
Fwdays
 
"AI is already here. What will happen to your team (and your role) tomorrow?"...
Fwdays
 
"Is it worth investing in AI in 2025?", Alexander Sharko
Fwdays
 
''Taming Explosive Growth: Building Resilience in a Hyper-Scaled Financial Pl...
Fwdays
 
"Scaling in space and time with Temporal", Andriy Lupa.pdf
Fwdays
 
"Database isolation: how we deal with hundreds of direct connections to the d...
Fwdays
 
"Scaling in space and time with Temporal", Andriy Lupa .pdf
Fwdays
 
"Provisioning via DOT-Chain: from catering to drone marketplaces", Volodymyr ...
Fwdays
 
" Observability with Elasticsearch: Best Practices for High-Load Platform", A...
Fwdays
 
"How to survive Black Friday: preparing e-commerce for a peak season", Yurii ...
Fwdays
 
"Istio Ambient Mesh in production: our way from Sidecar to Sidecar-less",Hlib...
Fwdays
 

Recently uploaded (20)

PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PPTX
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PPTX
Coupa-Overview _Assumptions presentation
annapureddyn
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PPTX
IoT Sensor Integration 2025 Powering Smart Tech and Industrial Automation.pptx
Rejig Digital
 
PDF
Beyond Automation: The Role of IoT Sensor Integration in Next-Gen Industries
Rejig Digital
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PPT
Coupa-Kickoff-Meeting-Template presentai
annapureddyn
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PDF
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
PPTX
How to Build a Scalable Micro-Investing Platform in 2025 - A Founder’s Guide ...
Third Rock Techkno
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PPTX
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
PDF
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
PDF
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
ChatGPT's Deck on The Enduring Legacy of Fax Machines
Greg Swan
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
Coupa-Overview _Assumptions presentation
annapureddyn
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
A Day in the Life of Location Data - Turning Where into How.pdf
Precisely
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
IoT Sensor Integration 2025 Powering Smart Tech and Industrial Automation.pptx
Rejig Digital
 
Beyond Automation: The Role of IoT Sensor Integration in Next-Gen Industries
Rejig Digital
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Coupa-Kickoff-Meeting-Template presentai
annapureddyn
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
Accelerating Oracle Database 23ai Troubleshooting with Oracle AHF Fleet Insig...
Sandesh Rao
 
How to Build a Scalable Micro-Investing Platform in 2025 - A Founder’s Guide ...
Third Rock Techkno
 
Software Development Methodologies in 2025
KodekX
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Comunidade Salesforce São Paulo - Desmistificando o Omnistudio (Vlocity)
Francisco Vieira Júnior
 
How-Cloud-Computing-Impacts-Businesses-in-2025-and-Beyond.pdf
Artjoker Software Development Company
 
BLW VOCATIONAL TRAINING SUMMER INTERNSHIP REPORT
codernjn73
 

Anton Boyko "DevSecOps for developers – why it’s important and how to get started?"