SlideShare a Scribd company logo
DevSecOops
Illia Lubenets
What is common?
Security is important
Security is important
• Average data breach cost – 4$ millions
• Attacks rose in 2020 – 600%
• Ukraine government is on 5th place of target attacks
• 70% of small business can’t deal with cyber attack
• 16% of healthcare providers are ready to prevent attack
DevSecOps
DevSecOps
• Collective Responsibility
• Collaboration and Integration
• Pragmatic Implementation
• Bridging Compliance and Development
• Automation
• Measure, Monitor, Report and Action
DevSecOps architecture sample
Tooling
Github security tooling
• Code scanning
• Dependabot
• Vulnerability management
Code scaning
• SonarQube
• WhiteSource
• Github
• Code scanning
• Dependabot
• Vulnerability management
• Coverity
• BlackDuck
Threat modeling
• Microsoft Threat Modeling Tool
• Threat Modeler
• Threat Dragon
Dynamic Application Security Testing
• Checkmarx
• Fortify
• ZAP
Infrastructure security tools
• Nessus
• Azure Security Center
• AWS Cloud Security
Conclusion
Security should be proper
Illia Lubenets
• Solution architect
• Microsoft Azure MVP
• https://twitter.com/L0ndra_
• https://t.me/procrastinationselfflagellation
ІЛЛЯ ЛУБЕНЕЦЬ «DevSecOps наступний етап розвитку DevOps»  GO DevOps

More Related Content

What's hot (20)

PPTX
Alex Michael - 2017/2018 Cyber Threat Report in an Enterprise Mobile World
Pro Mrkt
 
PDF
Cloud Security Architecture - a different approach
EC-Council
 
PDF
Outpost24 webinar: Security Analytics: what's in a risk score
Outpost24
 
PDF
The Cyber Attack Risk
Skyport Systems
 
PPTX
AWS User Group August Edition
Andreas Wasita
 
PPTX
David Tweedale - The Evolving Threat Landscape #midscybersecurity18
Pro Mrkt
 
PDF
Top 5 Cloud Security Predictions for 2016
Alert Logic
 
PDF
Outpost24 Webinar - Creating a sustainable application security program to dr...
Outpost24
 
PPTX
NTXISSACSC2 - Top Ten Trends in TRM by Jon Murphy
North Texas Chapter of the ISSA
 
POTX
Ransomware: Why Are Backup Vendors Trying To Scare You?
marketingunitrends
 
PDF
Acronis True Image 3rd Party Speed & Ransomware Tests, Apr 2017 from MRG Effitas
Acronis
 
PPTX
Darren Rawlinson - Dealing with Cyber Threats in an Enterprise Mobile World
Pro Mrkt
 
PDF
Introduction to Threat Modeling
InMobi Technology
 
PDF
Azure for Education Ktadeka UCL Cloud Event 2013
Lee Stott
 
PDF
Jul outlook malware18
Setia Juli Irzal Ismail
 
PPTX
The Case for EDR: What's In Your Toolkit
Dawn Yankeelov
 
PPTX
Outpost24 webinar: Risk-based approach to security assessments
Outpost24
 
PPTX
Outpost24 webinar - Enhance user security to stop the cyber-attack cycle
Outpost24
 
PPTX
The Top 7 Causes of Major Security Breaches
Kaseya
 
PDF
The Current ICS Threat Landscape
Dragos, Inc.
 
Alex Michael - 2017/2018 Cyber Threat Report in an Enterprise Mobile World
Pro Mrkt
 
Cloud Security Architecture - a different approach
EC-Council
 
Outpost24 webinar: Security Analytics: what's in a risk score
Outpost24
 
The Cyber Attack Risk
Skyport Systems
 
AWS User Group August Edition
Andreas Wasita
 
David Tweedale - The Evolving Threat Landscape #midscybersecurity18
Pro Mrkt
 
Top 5 Cloud Security Predictions for 2016
Alert Logic
 
Outpost24 Webinar - Creating a sustainable application security program to dr...
Outpost24
 
NTXISSACSC2 - Top Ten Trends in TRM by Jon Murphy
North Texas Chapter of the ISSA
 
Ransomware: Why Are Backup Vendors Trying To Scare You?
marketingunitrends
 
Acronis True Image 3rd Party Speed & Ransomware Tests, Apr 2017 from MRG Effitas
Acronis
 
Darren Rawlinson - Dealing with Cyber Threats in an Enterprise Mobile World
Pro Mrkt
 
Introduction to Threat Modeling
InMobi Technology
 
Azure for Education Ktadeka UCL Cloud Event 2013
Lee Stott
 
Jul outlook malware18
Setia Juli Irzal Ismail
 
The Case for EDR: What's In Your Toolkit
Dawn Yankeelov
 
Outpost24 webinar: Risk-based approach to security assessments
Outpost24
 
Outpost24 webinar - Enhance user security to stop the cyber-attack cycle
Outpost24
 
The Top 7 Causes of Major Security Breaches
Kaseya
 
The Current ICS Threat Landscape
Dragos, Inc.
 

Similar to ІЛЛЯ ЛУБЕНЕЦЬ «DevSecOps наступний етап розвитку DevOps» GO DevOps (20)

PPTX
Outpost24 webinar - The new CISO imperative: connecting technical vulnerabili...
Outpost24
 
PPTX
Moving Security to the Left
Javier Godinez
 
PDF
The Changing Landscape of Information Security
DevSecOpsSg
 
PDF
The state of web applications (in)security @ ITDays 2016
Tudor Damian
 
PPTX
Application Hackers Have A Handbook. Why Shouldn't You?
London School of Cyber Security
 
KEY
EISA Considerations for Web Application Security
Larry Ball
 
PPTX
Cyber Security Solution Empowering Digital Safety
Astarios
 
PPTX
Solnet dev secops meetup
pbink
 
PDF
DevSecCon Asia 2017 Ante Gulam: Integrating crowdsourced security into agile ...
DevSecCon
 
PPTX
Cloud_Security_and_Emerging_Technologies_Presentation.pptx
youngvision99
 
PPTX
Top Application Security Trends of 2012
DaveEdwards12
 
PPTX
Security in an Interconnected and Complex World of Software
Michael Coates
 
PPTX
2013 michael coates-javaone
Michael Coates
 
PPTX
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
PPTX
Secure application deployment in the age of continuous delivery
Tim Mackey
 
PPTX
Secure application deployment in the age of continuous delivery
Black Duck by Synopsys
 
PDF
Journey to the Cloud: Securing Your AWS Applications - April 2015
Alert Logic
 
PPTX
Keeping Secrets on the Internet of Things - Mobile Web Application Security
Kelly Robertson
 
PPTX
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
PPTX
Started In Security Now I'm Here
Christopher Grayson
 
Outpost24 webinar - The new CISO imperative: connecting technical vulnerabili...
Outpost24
 
Moving Security to the Left
Javier Godinez
 
The Changing Landscape of Information Security
DevSecOpsSg
 
The state of web applications (in)security @ ITDays 2016
Tudor Damian
 
Application Hackers Have A Handbook. Why Shouldn't You?
London School of Cyber Security
 
EISA Considerations for Web Application Security
Larry Ball
 
Cyber Security Solution Empowering Digital Safety
Astarios
 
Solnet dev secops meetup
pbink
 
DevSecCon Asia 2017 Ante Gulam: Integrating crowdsourced security into agile ...
DevSecCon
 
Cloud_Security_and_Emerging_Technologies_Presentation.pptx
youngvision99
 
Top Application Security Trends of 2012
DaveEdwards12
 
Security in an Interconnected and Complex World of Software
Michael Coates
 
2013 michael coates-javaone
Michael Coates
 
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
Secure application deployment in the age of continuous delivery
Tim Mackey
 
Secure application deployment in the age of continuous delivery
Black Duck by Synopsys
 
Journey to the Cloud: Securing Your AWS Applications - April 2015
Alert Logic
 
Keeping Secrets on the Internet of Things - Mobile Web Application Security
Kelly Robertson
 
Security in the age of open source - Myths and misperceptions
Tim Mackey
 
Started In Security Now I'm Here
Christopher Grayson
 
Ad

More from UA DevOps Conference (10)

PPTX
ОЛЕКСАНДР СНІГОВИЙ «Continuous Deployment: Challenges, Solutions, and Lesson...
UA DevOps Conference
 
PDF
АРТЕМ КОБРІН «Achieve Networking at Scale with a Self-Service Network Solutio...
UA DevOps Conference
 
PDF
ОЛЕКСАНДР СИРОТЕНКО «DataKernel: майструючи український фреймворк для highloa...
UA DevOps Conference
 
PDF
ЯРОСЛАВ РАВЛІНКО «Data Science at scale. Next generation data processing plat...
UA DevOps Conference
 
PPTX
ОЛЕКСАНДР ВІЛЬЧИНСЬКИЙ «DevOps culture» Lviv DevOps Conference 2019
UA DevOps Conference
 
PDF
КОСТЯНТИН СЕВЕРЕНЧУК «Monitoring and Automation in DevTestSecOps world» Lviv ...
UA DevOps Conference
 
PPTX
ДЕНИС КЛЕПIКОВ «Long Term storage for Prometheus» Lviv DevOps Conference 2019
UA DevOps Conference
 
PPTX
ОЛЕКСАНДР СНІГОВИЙ «Extension of DevOps: Policy as Code» Lviv DevOps Confere...
UA DevOps Conference
 
PPTX
СТАНІСЛАВ КОЛЕНКІН «Cilium – Network security for microservices. Let’s see ho...
UA DevOps Conference
 
PDF
ОЛЕГ МАЦЬКІВ «Crash course on Operator Framework» Lviv DevOps Conference 2019
UA DevOps Conference
 
ОЛЕКСАНДР СНІГОВИЙ «Continuous Deployment: Challenges, Solutions, and Lesson...
UA DevOps Conference
 
АРТЕМ КОБРІН «Achieve Networking at Scale with a Self-Service Network Solutio...
UA DevOps Conference
 
ОЛЕКСАНДР СИРОТЕНКО «DataKernel: майструючи український фреймворк для highloa...
UA DevOps Conference
 
ЯРОСЛАВ РАВЛІНКО «Data Science at scale. Next generation data processing plat...
UA DevOps Conference
 
ОЛЕКСАНДР ВІЛЬЧИНСЬКИЙ «DevOps culture» Lviv DevOps Conference 2019
UA DevOps Conference
 
КОСТЯНТИН СЕВЕРЕНЧУК «Monitoring and Automation in DevTestSecOps world» Lviv ...
UA DevOps Conference
 
ДЕНИС КЛЕПIКОВ «Long Term storage for Prometheus» Lviv DevOps Conference 2019
UA DevOps Conference
 
ОЛЕКСАНДР СНІГОВИЙ «Extension of DevOps: Policy as Code» Lviv DevOps Confere...
UA DevOps Conference
 
СТАНІСЛАВ КОЛЕНКІН «Cilium – Network security for microservices. Let’s see ho...
UA DevOps Conference
 
ОЛЕГ МАЦЬКІВ «Crash course on Operator Framework» Lviv DevOps Conference 2019
UA DevOps Conference
 
Ad

Recently uploaded (20)

PDF
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
PDF
Blockchain Transactions Explained For Everyone
CIFDAQ
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PDF
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
PDF
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PDF
Python basic programing language for automation
DanialHabibi2
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PPTX
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 
PPT
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
PDF
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
PDF
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PPTX
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
PDF
July Patch Tuesday
Ivanti
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 
CIFDAQ Market Insights for July 7th 2025
CIFDAQ
 
Blockchain Transactions Explained For Everyone
CIFDAQ
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
Empower Inclusion Through Accessible Java Applications
Ana-Maria Mihalceanu
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
Python basic programing language for automation
DanialHabibi2
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
Webinar: Introduction to LF Energy EVerest
DanBrown980551
 
July Patch Tuesday
Ivanti
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
[Newgen] NewgenONE Marvin Brochure 1.pdf
darshakparmar
 

ІЛЛЯ ЛУБЕНЕЦЬ «DevSecOps наступний етап розвитку DevOps» GO DevOps