DevSecOps – London Gathering
May 2019
THE JOURNEY …
• Venue (s)
• Do you need support from vendors
• Speakers
• What content
• Defining a theme
• Recordings; Streaming
• Give-aways (not prizes)
• Format of meetup
• How long
• Networking
• Collaboration
WAYS TO STAY IN TOUCH
https://www.meetup.com/DevSecOps-London-Gathering
https://twitter.com/DevSecOps_LG
https://www.linkedin.com/company/devsecops-london-gathering
https://github.com/DevSecOps-LondonGathering
https://www.youtube.com/channel/UCR4oVMkRjNN2OQaWMiBcfJA
SLIDES & REFERENCES
https://www.vr-security.com/references
https://www.vr-security.com/presentations
SHOUT OUT
*** Meetups ***
OWASP London Chapter
www.meetup.com/OWASP-London/
OWASP WIA
www.meetup.com/womeninappsec/
DevSecOps Manchester
www.meetup.com/DevSecOps-Manchester/
DevSecOps – Netherlands
www.meetup.com/DevSecOps-Netherlands/
LLHS
www.meetup.com/LLHS-Ladies-of-London-Hacking-Society/
*** Technology Specific ***
Istio London
www.meetup.com/Istio-London/
Kubernetes London
www.meetup.com/Kubernetes-London/
Threat Modeling
www.meetup.com/The-Threat-Modeling-Meetup/
Docker London
www.meetup.com/Docker-London/
SHOUT OUT
*** Conferences ***
DevSecCon London
https://www.devseccon.com/london-2019/
Open Security Summit
https://open-security-summit.org/
Bsides London
https://www.securitybsides.org.uk/
DEVSECOPS – LONDON GATHERING
ANNIVERSARY EVENT 2019
Date: Wednesday 11th September
Venue: Near St Paul’s
Speakers so far:
• Dr. Helen Thackray
Topics:
• Rounding up a few vendors to show us
how they conduct secure development.
• Playing back what hiring has been like the
last year.
Sponsorship/Support so far:
DevSecOps – People & Culture
• Break down the silo; no change here, just like the original DevOps movement
• Not aware of what is going on – likely you are not part of the “DevSecOps” team; leave your
ivory tower and build relationships
• Conduct a Value Stream Mapping exercise to optimize your delivery (rinse and repeat)
• Drill down and sketch out the details of each workflow before solutionising
• Try new checks/controls as part of the pipeline
IDE Static Code
Analysis
SCM
Dynamic
Analysis
Open Source
Software Security
Security Testing
Framework
Binary
Repository
Define
Security Test
CasesThreat
Modeling
Security
Standards
Automation
Tools: Passing
Criteria
Risk
Management
Out of Band
Security
Testing
Security
Champions
DevSecOps
Engineer
Security Audit
Artifacts
CI Build Server
DevSecOps – Tooling & Assurance Examples (May 2019)
curl
nmap
sslyze
sqlmap
Interactive
Testing
Infrastructure
Assurance
Threat
Modeling Container
Security
Dev Workstation Build Server
Centralize Report (Vulnerability Management) Server
SCM
Static Code Analysis
(SAST)
Dynamic Testing
(DAST)
Interactive Testing
(IAST)
Open Source Component Security
Manual Penetration Testing – Out of Band
Scope: Application and Network layer – White/Black box
Defect
Management
AUTOMATION
INTEGRATION POINTS
SECURITYASSURANCEMODEL
Updated: May 2019
Container Security
Infrastructure Scanning

More Related Content

PPTX
Apereo portlet showcase 2017
PDF
Getting Started with SharePoint solutions and GitHub
PPTX
Extract: DevSecOps - London Gathering (March 2019)
PDF
IAN Stack: Ionic, Angular and Nest.js
PDF
How to Grow and Measure Your API Program - I ♥ APIs 2015
PPTX
Devoxx 2016 Using Jenkins, Gerrit and Spark for Continuous Delivery Analytics
PDF
Leaflet-IIIF: Plugins and Extensibility with IIIF
PDF
Waltz-Controls presentation for Canadian Light Source
Apereo portlet showcase 2017
Getting Started with SharePoint solutions and GitHub
Extract: DevSecOps - London Gathering (March 2019)
IAN Stack: Ionic, Angular and Nest.js
How to Grow and Measure Your API Program - I ♥ APIs 2015
Devoxx 2016 Using Jenkins, Gerrit and Spark for Continuous Delivery Analytics
Leaflet-IIIF: Plugins and Extensibility with IIIF
Waltz-Controls presentation for Canadian Light Source

More from Michael Man (20)

PPTX
5 things i wish i knew about sast (DSO-LG July 2021)
PDF
K8S Certifications - Exam Cram
PDF
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
PDF
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PPTX
Extract Oct 2019: DSO-LG Rolling Slides
PPTX
Sept 2019 - DSO-LG Tooling Examples
PDF
Chris Rutter: Avoiding The Security Brick
PDF
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
PDF
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
PDF
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
PDF
August 2018: DevSecOps - London Gathering
PPTX
DevSecOps - London Gathering : June 2018
PDF
Continuous Security: From tins to containers - now what!
PDF
The mechanics behind how attackers exploit simple programming mistakes ...
PDF
Secret Management Journey - Here Be Dragons aka Secret Dragons
PPTX
DevSecOps March 2018 - Extract
PDF
DevSecOps The Evolution of DevOps
PDF
Dynaminet -DevSecOps
PPTX
DevSecOps: Test Automation
5 things i wish i knew about sast (DSO-LG July 2021)
K8S Certifications - Exam Cram
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Extract Oct 2019: DSO-LG Rolling Slides
Sept 2019 - DSO-LG Tooling Examples
Chris Rutter: Avoiding The Security Brick
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
August 2018: DevSecOps - London Gathering
DevSecOps - London Gathering : June 2018
Continuous Security: From tins to containers - now what!
The mechanics behind how attackers exploit simple programming mistakes ...
Secret Management Journey - Here Be Dragons aka Secret Dragons
DevSecOps March 2018 - Extract
DevSecOps The Evolution of DevOps
Dynaminet -DevSecOps
DevSecOps: Test Automation
Ad

Recently uploaded (20)

PDF
Comparative analysis of machine learning models for fake news detection in so...
PDF
Connector Corner: Transform Unstructured Documents with Agentic Automation
PDF
Data Virtualization in Action: Scaling APIs and Apps with FME
PPTX
future_of_ai_comprehensive_20250822032121.pptx
PDF
A symptom-driven medical diagnosis support model based on machine learning te...
PDF
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
PPTX
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
PDF
giants, standing on the shoulders of - by Daniel Stenberg
PDF
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
PDF
Introduction to MCP and A2A Protocols: Enabling Agent Communication
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
PPTX
Training Program for knowledge in solar cell and solar industry
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PDF
Lung cancer patients survival prediction using outlier detection and optimize...
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PDF
Co-training pseudo-labeling for text classification with support vector machi...
PDF
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
PDF
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
PDF
SaaS reusability assessment using machine learning techniques
Comparative analysis of machine learning models for fake news detection in so...
Connector Corner: Transform Unstructured Documents with Agentic Automation
Data Virtualization in Action: Scaling APIs and Apps with FME
future_of_ai_comprehensive_20250822032121.pptx
A symptom-driven medical diagnosis support model based on machine learning te...
Transform-Quality-Engineering-with-AI-A-60-Day-Blueprint-for-Digital-Success.pdf
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
giants, standing on the shoulders of - by Daniel Stenberg
The-Future-of-Automotive-Quality-is-Here-AI-Driven-Engineering.pdf
Introduction to MCP and A2A Protocols: Enabling Agent Communication
Improvisation in detection of pomegranate leaf disease using transfer learni...
AI.gov: A Trojan Horse in the Age of Artificial Intelligence
Training Program for knowledge in solar cell and solar industry
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
Lung cancer patients survival prediction using outlier detection and optimize...
Early detection and classification of bone marrow changes in lumbar vertebrae...
Co-training pseudo-labeling for text classification with support vector machi...
CXOs-Are-you-still-doing-manual-DevOps-in-the-age-of-AI.pdf
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
SaaS reusability assessment using machine learning techniques
Ad

DevSecOps Manchester - May 2019

  • 1. DevSecOps – London Gathering May 2019
  • 2. THE JOURNEY … • Venue (s) • Do you need support from vendors • Speakers • What content • Defining a theme • Recordings; Streaming • Give-aways (not prizes) • Format of meetup • How long • Networking • Collaboration
  • 3. WAYS TO STAY IN TOUCH https://www.meetup.com/DevSecOps-London-Gathering https://twitter.com/DevSecOps_LG https://www.linkedin.com/company/devsecops-london-gathering https://github.com/DevSecOps-LondonGathering https://www.youtube.com/channel/UCR4oVMkRjNN2OQaWMiBcfJA
  • 5. SHOUT OUT *** Meetups *** OWASP London Chapter www.meetup.com/OWASP-London/ OWASP WIA www.meetup.com/womeninappsec/ DevSecOps Manchester www.meetup.com/DevSecOps-Manchester/ DevSecOps – Netherlands www.meetup.com/DevSecOps-Netherlands/ LLHS www.meetup.com/LLHS-Ladies-of-London-Hacking-Society/ *** Technology Specific *** Istio London www.meetup.com/Istio-London/ Kubernetes London www.meetup.com/Kubernetes-London/ Threat Modeling www.meetup.com/The-Threat-Modeling-Meetup/ Docker London www.meetup.com/Docker-London/
  • 6. SHOUT OUT *** Conferences *** DevSecCon London https://www.devseccon.com/london-2019/ Open Security Summit https://open-security-summit.org/ Bsides London https://www.securitybsides.org.uk/
  • 7. DEVSECOPS – LONDON GATHERING ANNIVERSARY EVENT 2019 Date: Wednesday 11th September Venue: Near St Paul’s Speakers so far: • Dr. Helen Thackray Topics: • Rounding up a few vendors to show us how they conduct secure development. • Playing back what hiring has been like the last year. Sponsorship/Support so far:
  • 8. DevSecOps – People & Culture • Break down the silo; no change here, just like the original DevOps movement • Not aware of what is going on – likely you are not part of the “DevSecOps” team; leave your ivory tower and build relationships • Conduct a Value Stream Mapping exercise to optimize your delivery (rinse and repeat) • Drill down and sketch out the details of each workflow before solutionising • Try new checks/controls as part of the pipeline
  • 9. IDE Static Code Analysis SCM Dynamic Analysis Open Source Software Security Security Testing Framework Binary Repository Define Security Test CasesThreat Modeling Security Standards Automation Tools: Passing Criteria Risk Management Out of Band Security Testing Security Champions DevSecOps Engineer Security Audit Artifacts CI Build Server DevSecOps – Tooling & Assurance Examples (May 2019) curl nmap sslyze sqlmap Interactive Testing Infrastructure Assurance Threat Modeling Container Security
  • 10. Dev Workstation Build Server Centralize Report (Vulnerability Management) Server SCM Static Code Analysis (SAST) Dynamic Testing (DAST) Interactive Testing (IAST) Open Source Component Security Manual Penetration Testing – Out of Band Scope: Application and Network layer – White/Black box Defect Management AUTOMATION INTEGRATION POINTS SECURITYASSURANCEMODEL Updated: May 2019 Container Security Infrastructure Scanning