SlideShare a Scribd company logo
Copyright © 2015 evident.io1
THE MARRIAGE OF SECOPS AND DEVOPS
Adapted from material presented by DevOps.com and Evident.io
Sebastian Taphanel, CISSP-ISSEP
Principal Solutions Architect
September 29th, 2016
Copyright © 2015 evident.io2
Alan Shimel, Founder and Editor-In-Chief at DevOps.com, is an often-cited personality in the
security and technology community and a sought-after speaker at industry and government
events, Alan has helped build several successful technology companies by combining a strong
business background with a deep knowledge of technology.
CEO Tim Prendergast co-founded Evident.io to help others avoid the pain he endured when
helping Adobe adopt the cloud at a massive level. After years of building, operating, and securing
services in AWS, he set out to make security approachable and repeatable for companies of all
sizes. Tim led technology teams at Adobe, Ingenuity, Ticketmaster, and McAfee.
Original Contributors:
.
Gene Kim is a multiple award winning CTO, researcher and author. He was founder and CTO
of Tripwire for 13 years. He has written three books, including The Phoenix Project: A Novel
About IT, DevOps, and Helping Your Business Win and the upcoming DevOps Handbook. He
has worked with some of the top Internet companies on improving deployment flow and
increasing the rigor around IT operational processes.
Shannon Lietz has over two decades of experience pursuing advanced security defenses and
next generation security solutions. Ms. Lietz is currently the DevSecOps Leader for Intuit where
she is responsible for setting and driving the company’s cloud security strategy, roadmap and
implementation in support of corporate innovation. Previous to joining Intuit, Ms. Lietz worked
for ServiceNow, Sony, and consulted for many Fortune 500 organizations.
Copyright © 2015 evident.io3
…DevSecOps is an Evolving Story
Copyright © 2015 evident.io4
CLOUD SECURITY THEN AND NOW
From:
To:
Copyright © 2015 evident.io5
DEVSECOPS: INNOVATIVE SOLUTIONS
Issues:
• DevOps Requires Continuous Deployments
• Fast Decision Making is Critical to Success
• Traditional Security Doesn’t Scale or Move Fast Enough
DevSecOps Solutions:
• Security Automation
• Security to Scale
• Objective Criteria
• Proactive Security Monitoring
• Continuous Detection & Response
Copyright © 2015 evident.io6
THE DEVSECOPS MANIFESTO
• Leaning in vs. Saying “No”
• Data & Security Science vs. FUD
• Open Collaboration vs. Security-Only Requirements
• Security Services with APIs vs. Mandated Controls
• Business Driven Security vs. Rubber Stamp Security
• Red & Blue Team Exploit Testing vs. Theoretical Vulnerabilities
• 24x7 Proactive Security vs. Reacting
• Shared Threat Intelligence vs. Silos
• Compliance Operations vs. Checklists
Via: http://www.devsecops.org
Copyright © 2015 evident.io7
SECURITY AS CODE
The code that describes the infrastructure should inherit the
same values applied to application code:
• Not JUST Revision Control
• Make Use of Bug Tracking/Ticketing Systems
• Peer Reviews of Changes Before They Happen
• Establish Infrastructure Code Patterns/Designs
• Test Infrastructure Changes Like Code Changes Security as Code
VS.
Page 3 of 433
Copyright © 2015 evident.io8
Copyright © 2015 evident.io9
Copyright © 2015 evident.io10
Copyright © 2015 evident.io11
Copyright © 2015 evident.io12
SECURITY VIA API’S
• Programmatically Test Environments
• Determine State at a Specific Point in Time
• Repeatable Processes
• Scalable Operations
• Easy Automation
• Repeatable
• Auditable
• Easy to Iterate
• Environmental Consistency
Copyright © 2015 evident.io13
DEVSECOPS IS A TEAM SPORT
Operations
Red Team
Blue Team
Developers
Security
Copyright © 2015 evident.io14
BE READY TO MAKE DECISIONS
Copyright © 2015 evident.io15
DEVSECOPS SUCCESS
Keys to Success:
• Detecting and Resolving Security Issues Quickly
• Using Native Security Capabilities When Possible
• Enlisting and Enabling the Organization
• Educating Inline with Bite-Size Chunks
Copyright © 2015 evident.io16
DEVSECOPS PRINCIPLES
• DevSecOps is a Journey, not a Destination
• Small Security Teams Can Have a Profound Impact
• Organize Around Self-Service and Enablement
• Translate Security for the Layperson
• Perfection is the Enemy… get Rugged
Copyright © 2015 evident.io17
Copyright © 2015 evident.io18
Copyright © 2015 evident.io19
Alan Shimel
• DevOps.com
• ashimmy@devops.com
• @ashimmy
Gene Kim
• genek@itrevolution.net
• @RealGeneKim
Tim Prendergast:
• Evident.io
• Tim@evident.io
• @auxome
Original
Contributors:
Shannon Lietz
• Intuit.com
• Shannon_Lietz@intuit.com
Copyright © 2015 evident.io20
Q & A - ANY QUESTIONS?
THANKS FOR PARTICIPATING!
SEBASTIAN@EVIDENT.IO
HTTPS://WWW.LINKEDIN.COM/IN/SEBASTIANTAPHANEL

More Related Content

PDF
Evident io Continuous Compliance - Mar 2017
Sebastian Taphanel CISSP-ISSEP
 
PPTX
CSS17: Dallas - Thawing the Frozen Middle
Alert Logic
 
PPTX
#ALSummit: Amazon Web Services: Understanding the Shared Security Model
Alert Logic
 
PDF
Securing The Cloud: Top Down and Bottom Up
DevOps.com
 
PPTX
Do You Trust Your DevSecOps Pipeline?
DevOps.com
 
PPTX
DevSecOps - CrikeyCon 2017
kieranjacobsen
 
PDF
DevSecOps, The Good, Bad, and Ugly
4ndersonLin
 
PDF
Dev week cloud world conf2021
Archana Joshi
 
Evident io Continuous Compliance - Mar 2017
Sebastian Taphanel CISSP-ISSEP
 
CSS17: Dallas - Thawing the Frozen Middle
Alert Logic
 
#ALSummit: Amazon Web Services: Understanding the Shared Security Model
Alert Logic
 
Securing The Cloud: Top Down and Bottom Up
DevOps.com
 
Do You Trust Your DevSecOps Pipeline?
DevOps.com
 
DevSecOps - CrikeyCon 2017
kieranjacobsen
 
DevSecOps, The Good, Bad, and Ugly
4ndersonLin
 
Dev week cloud world conf2021
Archana Joshi
 

What's hot (17)

PPTX
A journey from dev ops to devsecops
Veritis Group, Inc
 
PPTX
#ALSummit: Alert Logic & AWS - AWS Security Services
Alert Logic
 
PPTX
DevOps
Jeremiah Tillman
 
PPTX
Practical DevSecOps Using Security Instrumentation
VMware Tanzu
 
PPTX
#ALSummit: Realities of Security in the Cloud
Alert Logic
 
PPTX
Risk Analytics: One Intelligent View
Skybox Security
 
PPTX
DevSecOps in 10 minutes
kieranjacobsen
 
PPTX
#ALSummit: Architecting Security into your AWS Environment
Alert Logic
 
PPTX
Microsoft Azure News - April 2021
Daniel Toomey
 
PPTX
#ALSummit: SCOR Velogica's Journey to SOC2/TYPE2 Via AWS
Alert Logic
 
PPTX
Outpost24 webinar - Why security perfection is the enemy of DevSecOps
Outpost24
 
PDF
The 7 Rules of IT Disaster Recovery by Acronis
Acronis
 
PPTX
AWS Security Ideas - re:Invent 2016
2nd Sight Lab
 
PDF
Enterprise Security APIs
Adam Migus
 
PDF
Your Resolution for 2018: Five Principles For Securing DevOps
DevOps.com
 
PPTX
Threat Hunting on AWS using Azure Sentinel
Ashwin Patil, GCIH, GCIA, GCFE
 
PPTX
Connecting Your SIEM Tool with Akamai Security Events
Akamai Developers & Admins
 
A journey from dev ops to devsecops
Veritis Group, Inc
 
#ALSummit: Alert Logic & AWS - AWS Security Services
Alert Logic
 
Practical DevSecOps Using Security Instrumentation
VMware Tanzu
 
#ALSummit: Realities of Security in the Cloud
Alert Logic
 
Risk Analytics: One Intelligent View
Skybox Security
 
DevSecOps in 10 minutes
kieranjacobsen
 
#ALSummit: Architecting Security into your AWS Environment
Alert Logic
 
Microsoft Azure News - April 2021
Daniel Toomey
 
#ALSummit: SCOR Velogica's Journey to SOC2/TYPE2 Via AWS
Alert Logic
 
Outpost24 webinar - Why security perfection is the enemy of DevSecOps
Outpost24
 
The 7 Rules of IT Disaster Recovery by Acronis
Acronis
 
AWS Security Ideas - re:Invent 2016
2nd Sight Lab
 
Enterprise Security APIs
Adam Migus
 
Your Resolution for 2018: Five Principles For Securing DevOps
DevOps.com
 
Threat Hunting on AWS using Azure Sentinel
Ashwin Patil, GCIH, GCIA, GCFE
 
Connecting Your SIEM Tool with Akamai Security Events
Akamai Developers & Admins
 
Ad

Viewers also liked (7)

PDF
Implementing the Top 10 AWS Security Best Practices
Sebastian Taphanel CISSP-ISSEP
 
PPTX
James Whittaker, Microsoft - A Future Worth Wanting at SIC2013
Seattle Interactive Conference
 
PDF
Threat Hunting with Splunk
Splunk
 
PPTX
Compliance Automation with InSpec
Nathen Harvey
 
PDF
Modern Agile - Keynote at Agile2016
Joshua Kerievsky
 
PPTX
Revamping Development and Testing Using Docker – Transforming Enterprise IT b...
Docker, Inc.
 
PPTX
Threat Hunting with Splunk Hands-on
Splunk
 
Implementing the Top 10 AWS Security Best Practices
Sebastian Taphanel CISSP-ISSEP
 
James Whittaker, Microsoft - A Future Worth Wanting at SIC2013
Seattle Interactive Conference
 
Threat Hunting with Splunk
Splunk
 
Compliance Automation with InSpec
Nathen Harvey
 
Modern Agile - Keynote at Agile2016
Joshua Kerievsky
 
Revamping Development and Testing Using Docker – Transforming Enterprise IT b...
Docker, Inc.
 
Threat Hunting with Splunk Hands-on
Splunk
 
Ad

Similar to Developing a Rugged Dev Ops Approach to Cloud Security (Updated) (20)

PPTX
The End of Security as We Know It - Shannon Lietz
SeniorStoryteller
 
PPTX
Succeeding-Marriage-Cybersecurity-DevOps final
rkadayam
 
PPTX
ISACA Ireland Keynote 2015
Shannon Lietz
 
PDF
Pentest is yesterday, DevSecOps is tomorrow
Amien Harisen Rosyandino
 
PPTX
DevSecCon Keynote
Shannon Lietz
 
PPTX
DevSecCon KeyNote London 2015
Shannon Lietz
 
PDF
Securing DevOps Lifecycle
DevOps Indonesia
 
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
PPTX
The Importance of DevOps Security and the Emergence of DevSecOps
Dev Software
 
PPTX
Shifting security all day dev ops
Tom Stiehm
 
PPTX
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
PPTX
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
Turja Narayan Chaudhuri
 
PDF
Integrating Automated Testing into DevOps
TechWell
 
PPTX
2022 DOI SKILup Days_Your Developers Decide Your Security Posture_Not Your Se...
Turja Narayan Chaudhuri
 
PPTX
Devsec ops
VipinYadav257
 
PDF
Embrace DevSecOps and Enjoy a Significant Competitive Advantage!
DevOps.com
 
PPTX
Introduction to DevSecOps
abhimanyubhogwan
 
PPTX
2016 - Safely Removing the Last Roadblock to Continuous Delivery
devopsdaysaustin
 
PPTX
S360 2015 dev_secops_program
Shannon Lietz
 
The End of Security as We Know It - Shannon Lietz
SeniorStoryteller
 
Succeeding-Marriage-Cybersecurity-DevOps final
rkadayam
 
ISACA Ireland Keynote 2015
Shannon Lietz
 
Pentest is yesterday, DevSecOps is tomorrow
Amien Harisen Rosyandino
 
DevSecCon Keynote
Shannon Lietz
 
DevSecCon KeyNote London 2015
Shannon Lietz
 
Securing DevOps Lifecycle
DevOps Indonesia
 
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
The Importance of DevOps Security and the Emergence of DevSecOps
Dev Software
 
Shifting security all day dev ops
Tom Stiehm
 
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
Turja Narayan Chaudhuri
 
Integrating Automated Testing into DevOps
TechWell
 
2022 DOI SKILup Days_Your Developers Decide Your Security Posture_Not Your Se...
Turja Narayan Chaudhuri
 
Devsec ops
VipinYadav257
 
Embrace DevSecOps and Enjoy a Significant Competitive Advantage!
DevOps.com
 
Introduction to DevSecOps
abhimanyubhogwan
 
2016 - Safely Removing the Last Roadblock to Continuous Delivery
devopsdaysaustin
 
S360 2015 dev_secops_program
Shannon Lietz
 

Recently uploaded (20)

PDF
The Future of Artificial Intelligence (AI)
Mukul
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PDF
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
PDF
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
REPORT: Heating appliances market in Poland 2024
SPIUG
 
PDF
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PDF
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
PDF
Software Development Methodologies in 2025
KodekX
 
The Future of Artificial Intelligence (AI)
Mukul
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
Event Presentation Google Cloud Next Extended 2025
minhtrietgect
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
CIFDAQ's Market Wrap : Bears Back in Control?
CIFDAQ
 
Make GenAI investments go further with the Dell AI Factory
Principled Technologies
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
REPORT: Heating appliances market in Poland 2024
SPIUG
 
Oracle AI Vector Search- Getting Started and what's new in 2025- AIOUG Yatra ...
Sandesh Rao
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
The Evolution of KM Roles (Presented at Knowledge Summit Dublin 2025)
Enterprise Knowledge
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Trying to figure out MCP by actually building an app from scratch with open s...
Julien SIMON
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
The Future of Mobile Is Context-Aware—Are You Ready?
iProgrammer Solutions Private Limited
 
Software Development Methodologies in 2025
KodekX
 

Developing a Rugged Dev Ops Approach to Cloud Security (Updated)

  • 1. Copyright © 2015 evident.io1 THE MARRIAGE OF SECOPS AND DEVOPS Adapted from material presented by DevOps.com and Evident.io Sebastian Taphanel, CISSP-ISSEP Principal Solutions Architect September 29th, 2016
  • 2. Copyright © 2015 evident.io2 Alan Shimel, Founder and Editor-In-Chief at DevOps.com, is an often-cited personality in the security and technology community and a sought-after speaker at industry and government events, Alan has helped build several successful technology companies by combining a strong business background with a deep knowledge of technology. CEO Tim Prendergast co-founded Evident.io to help others avoid the pain he endured when helping Adobe adopt the cloud at a massive level. After years of building, operating, and securing services in AWS, he set out to make security approachable and repeatable for companies of all sizes. Tim led technology teams at Adobe, Ingenuity, Ticketmaster, and McAfee. Original Contributors: . Gene Kim is a multiple award winning CTO, researcher and author. He was founder and CTO of Tripwire for 13 years. He has written three books, including The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win and the upcoming DevOps Handbook. He has worked with some of the top Internet companies on improving deployment flow and increasing the rigor around IT operational processes. Shannon Lietz has over two decades of experience pursuing advanced security defenses and next generation security solutions. Ms. Lietz is currently the DevSecOps Leader for Intuit where she is responsible for setting and driving the company’s cloud security strategy, roadmap and implementation in support of corporate innovation. Previous to joining Intuit, Ms. Lietz worked for ServiceNow, Sony, and consulted for many Fortune 500 organizations.
  • 3. Copyright © 2015 evident.io3 …DevSecOps is an Evolving Story
  • 4. Copyright © 2015 evident.io4 CLOUD SECURITY THEN AND NOW From: To:
  • 5. Copyright © 2015 evident.io5 DEVSECOPS: INNOVATIVE SOLUTIONS Issues: • DevOps Requires Continuous Deployments • Fast Decision Making is Critical to Success • Traditional Security Doesn’t Scale or Move Fast Enough DevSecOps Solutions: • Security Automation • Security to Scale • Objective Criteria • Proactive Security Monitoring • Continuous Detection & Response
  • 6. Copyright © 2015 evident.io6 THE DEVSECOPS MANIFESTO • Leaning in vs. Saying “No” • Data & Security Science vs. FUD • Open Collaboration vs. Security-Only Requirements • Security Services with APIs vs. Mandated Controls • Business Driven Security vs. Rubber Stamp Security • Red & Blue Team Exploit Testing vs. Theoretical Vulnerabilities • 24x7 Proactive Security vs. Reacting • Shared Threat Intelligence vs. Silos • Compliance Operations vs. Checklists Via: http://www.devsecops.org
  • 7. Copyright © 2015 evident.io7 SECURITY AS CODE The code that describes the infrastructure should inherit the same values applied to application code: • Not JUST Revision Control • Make Use of Bug Tracking/Ticketing Systems • Peer Reviews of Changes Before They Happen • Establish Infrastructure Code Patterns/Designs • Test Infrastructure Changes Like Code Changes Security as Code VS. Page 3 of 433
  • 8. Copyright © 2015 evident.io8
  • 9. Copyright © 2015 evident.io9
  • 10. Copyright © 2015 evident.io10
  • 11. Copyright © 2015 evident.io11
  • 12. Copyright © 2015 evident.io12 SECURITY VIA API’S • Programmatically Test Environments • Determine State at a Specific Point in Time • Repeatable Processes • Scalable Operations • Easy Automation • Repeatable • Auditable • Easy to Iterate • Environmental Consistency
  • 13. Copyright © 2015 evident.io13 DEVSECOPS IS A TEAM SPORT Operations Red Team Blue Team Developers Security
  • 14. Copyright © 2015 evident.io14 BE READY TO MAKE DECISIONS
  • 15. Copyright © 2015 evident.io15 DEVSECOPS SUCCESS Keys to Success: • Detecting and Resolving Security Issues Quickly • Using Native Security Capabilities When Possible • Enlisting and Enabling the Organization • Educating Inline with Bite-Size Chunks
  • 16. Copyright © 2015 evident.io16 DEVSECOPS PRINCIPLES • DevSecOps is a Journey, not a Destination • Small Security Teams Can Have a Profound Impact • Organize Around Self-Service and Enablement • Translate Security for the Layperson • Perfection is the Enemy… get Rugged
  • 17. Copyright © 2015 evident.io17
  • 18. Copyright © 2015 evident.io18
  • 19. Copyright © 2015 evident.io19 Alan Shimel • DevOps.com • [email protected] • @ashimmy Gene Kim • [email protected] • @RealGeneKim Tim Prendergast: • Evident.io • [email protected] • @auxome Original Contributors: Shannon Lietz • Intuit.com • [email protected]
  • 20. Copyright © 2015 evident.io20 Q & A - ANY QUESTIONS?