SlideShare a Scribd company logo
DevOps and Security: It’s Happening. Right Now.
Helen Bravo
Director of Product Management at Checkmarx
Helen.bravo@checkmarx.com
Agenda
• Intro to DevOps
• Integrating security within DevOps

– Problems with traditional controls
– Steps to DevOps security
What is DevOps About?
An unstoppable deployment process
… in small chunks of time
DevOps is Happening

Companies that have adopted DevOps
Can TRADITIONAL
web application
security controls fit
in…

… a DevOps environment?!
Traditional Web Application Security Controls
• Penetration Testing
• WAF (Web Application Firewall)

• Code Analysis
Penetration Testing- Takes Time!
Penetration Testing
– 300 pages report

– 3 weeks assessment time
– 2 weeks to get it into development
Web Application Firewall (WAF)
Thinking Continuous
Deployment?

Think Continuous
Configuration!
Code Analysis
• Setup time
• Running time
• Analysis time

… just too slow!
DevOps & Security: Here & Now
… Do Nothing?
Required: A New Secure SDLC Approach
Step by Step
Step 1: Plan for Security
Step 1: Plan for Security
• Identify unsecured APIs and frameworks
• Map security sensitive code portions. E.g. password
changes mechanism, user authentication
mechanism.
• Anticipate regulatory problems, plan for it.
Step 2: Engage the Developers.

And Be Engaged
Step 2: Engage the Developers. And Be Engaged
• Connect developers to security
– Going to OWASP? Bring a developer with you!

• Is your house on fire? Share the details with your
developers.
• Have an open door approach
• Set up an online collaboration platform E.g. Jive,
Confluence etc.
Step 3: Arm the Developers
Step 3: Arm the Developer
• Secure frameworks:
– Use a secure framework such as Spring Security, JAAS, Apache
Shiro, Symfony2

– ESAPI is a very useful OWASP security framework
• SCA tools that can provide security feedback on pre-commit stage.
– Rapid response

– Small chunks
Step 3: Automate the Process
Step 3: Automate the Process
• Integrate within your build (Jenkins, Bamboo,
TeamCity, etc.)
– SAST
– DAST

• Fail the build if security does not pass the bar.
Continuous Deployment
Unit Tests

Develop

Code
Commit

Source
Control

Build
Trigger

Deploy to
Test Env

Report
&
Notify

Publish to
release
repository

Deploy
to
Production
Security within Continuous Deployment

Tests

Develop

Code
Commit

Source
Control

Build
Trigger

Deploy
to Test
Env
SCA
Test

Publish to

Automatic Report release
security
repository
&
test
Notify

Deploy
to
Production
Step 5: Use Old Tools Wisely
Step 5: Use Old Tools Wisely
• Periodic pen testing
• WAF on main functions
• Code review for security sensitive code portions.
Summary
Summary
• DevOps is happening. Right Now.
– During the time of this talk, Amazon has released

75 features and bug fixes.
• Security should not be compromised
• Don’t be overwhelmed. Start small
The 3 Takeaways
1. Plan from the ground

2. Engage with your developers
3. Integrate security into automatic build
process.
Questions?
Thank you
Helen.bravo@checkmarx.com

More Related Content

What's hot (20)

PDF
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Mohammed A. Imran
 
PPTX
DevOps to DevSecOps Journey..
Siddharth Joshi
 
PPT
CI and CD with Jenkins
Martin Málek
 
PPTX
Git/Github & Salesforce
Gordon Bockus
 
PDF
DevSecOps: Taking a DevOps Approach to Security
Alert Logic
 
PDF
DevOps - A Gentle Introduction
CodeOps Technologies LLP
 
PDF
DevSecOps and the CI/CD Pipeline
James Wickett
 
PPTX
How To Become A DevOps Engineer | Who Is A DevOps Engineer? | DevOps Engineer...
Simplilearn
 
PPTX
Introducing DevOps
Nishanth K Hydru
 
PPTX
Scaling Push Messaging for Millions of Netflix Devices
Susheel Aroskar
 
PDF
DevOps and AWS
Shiva Narayanaswamy
 
PDF
DevSecOps - The big picture
Stefan Streichsbier
 
PPTX
DevOps 101 - an Introduction to DevOps
Red Gate Software
 
PPTX
AWS Lambda Tutorial For Beginners | What is AWS Lambda? | AWS Tutorial For Be...
Simplilearn
 
PPSX
Microservices, DevOps & SRE
Araf Karsh Hamid
 
PPTX
Postman Introduction
Rahul Agarwal
 
PPTX
DevOps introduction
Mettje Heegstra
 
PPTX
What is DevOps? | DevOps Introduction | DevOps Tools | DevOps Tutorial For Be...
Simplilearn
 
[DevSecOps Live] DevSecOps: Challenges and Opportunities
Mohammed A. Imran
 
DevOps to DevSecOps Journey..
Siddharth Joshi
 
CI and CD with Jenkins
Martin Málek
 
Git/Github & Salesforce
Gordon Bockus
 
DevSecOps: Taking a DevOps Approach to Security
Alert Logic
 
DevOps - A Gentle Introduction
CodeOps Technologies LLP
 
DevSecOps and the CI/CD Pipeline
James Wickett
 
How To Become A DevOps Engineer | Who Is A DevOps Engineer? | DevOps Engineer...
Simplilearn
 
Introducing DevOps
Nishanth K Hydru
 
Scaling Push Messaging for Millions of Netflix Devices
Susheel Aroskar
 
DevOps and AWS
Shiva Narayanaswamy
 
DevSecOps - The big picture
Stefan Streichsbier
 
DevOps 101 - an Introduction to DevOps
Red Gate Software
 
AWS Lambda Tutorial For Beginners | What is AWS Lambda? | AWS Tutorial For Be...
Simplilearn
 
Microservices, DevOps & SRE
Araf Karsh Hamid
 
Postman Introduction
Rahul Agarwal
 
DevOps introduction
Mettje Heegstra
 
What is DevOps? | DevOps Introduction | DevOps Tools | DevOps Tutorial For Be...
Simplilearn
 

Viewers also liked (13)

PDF
Application Security Guide for Beginners
Checkmarx
 
PPTX
Implementing an Application Security Pipeline in Jenkins
Suman Sourav
 
PDF
DevSecOps Singapore 2017 - Security in the Delivery Pipeline
James Wickett
 
PDF
Devops security-An Insight into Secure-SDLC
Suman Sourav
 
PDF
Security Tests as Part of CI - Nir Koren, SAP - DevOpsDays Tel Aviv 2015
DevOpsDays Tel Aviv
 
PDF
A Successful SAST Tool Implementation
Checkmarx
 
PDF
DevSecOps in Baby Steps
Priyanka Aash
 
PDF
Bringing Security Testing to Development: How to Enable Developers to Act as ...
Achim D. Brucker
 
PDF
Happy New Year!
Checkmarx
 
PDF
Application Security Management with ThreadFix
Virtual Forge
 
PPTX
DEVSECOPS: Coding DevSecOps journey
Jason Suttie
 
PPTX
Graph Visualization - OWASP NYC Chapter
Checkmarx
 
PDF
[ITAS.VN]CxSuite Enterprise Edition
ITAS VIETNAM
 
Application Security Guide for Beginners
Checkmarx
 
Implementing an Application Security Pipeline in Jenkins
Suman Sourav
 
DevSecOps Singapore 2017 - Security in the Delivery Pipeline
James Wickett
 
Devops security-An Insight into Secure-SDLC
Suman Sourav
 
Security Tests as Part of CI - Nir Koren, SAP - DevOpsDays Tel Aviv 2015
DevOpsDays Tel Aviv
 
A Successful SAST Tool Implementation
Checkmarx
 
DevSecOps in Baby Steps
Priyanka Aash
 
Bringing Security Testing to Development: How to Enable Developers to Act as ...
Achim D. Brucker
 
Happy New Year!
Checkmarx
 
Application Security Management with ThreadFix
Virtual Forge
 
DEVSECOPS: Coding DevSecOps journey
Jason Suttie
 
Graph Visualization - OWASP NYC Chapter
Checkmarx
 
[ITAS.VN]CxSuite Enterprise Edition
ITAS VIETNAM
 
Ad

Similar to DevOps & Security: Here & Now (20)

PPTX
Dev opsandsecurity owasp
Helen Bravo
 
PPTX
You Build It, You Secure It: Introduction to DevSecOps
Sumo Logic
 
PPTX
Secure DevOPS Implementation Guidance
Tej Luthra
 
PDF
Scale security for a dollar or less
Mohammed A. Imran
 
PDF
AppSec How-To: Achieving Security in DevOps
Checkmarx
 
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
PDF
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
PPTX
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
ellan12
 
PPTX
DevSecOps and Drupal: Securing your applications in a modern IT landscape
Will Hall
 
PPTX
Introduction to DevSecOps
abhimanyubhogwan
 
PPTX
Secure DevOps - Evolution or Revolution?
Security Innovation
 
PPTX
DevSecOps : an Introduction
Prashanth B. P.
 
PDF
You build it - Cyber Chicago Keynote
John Willis
 
PPTX
DevSecCon KeyNote London 2015
Shannon Lietz
 
PPTX
DevSecCon Keynote
Shannon Lietz
 
PDF
DevOps or DevSecOps
Michelangelo van Dam
 
PPTX
Introduction to DevSecOps OWASP Ahmedabad
kunwaratul hax0r
 
PDF
2021-10-14 The Critical Role of Security in DevOps.pdf
Savinder Puri
 
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
PPTX
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Puppet
 
Dev opsandsecurity owasp
Helen Bravo
 
You Build It, You Secure It: Introduction to DevSecOps
Sumo Logic
 
Secure DevOPS Implementation Guidance
Tej Luthra
 
Scale security for a dollar or less
Mohammed A. Imran
 
AppSec How-To: Achieving Security in DevOps
Checkmarx
 
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
ellan12
 
DevSecOps and Drupal: Securing your applications in a modern IT landscape
Will Hall
 
Introduction to DevSecOps
abhimanyubhogwan
 
Secure DevOps - Evolution or Revolution?
Security Innovation
 
DevSecOps : an Introduction
Prashanth B. P.
 
You build it - Cyber Chicago Keynote
John Willis
 
DevSecCon KeyNote London 2015
Shannon Lietz
 
DevSecCon Keynote
Shannon Lietz
 
DevOps or DevSecOps
Michelangelo van Dam
 
Introduction to DevSecOps OWASP Ahmedabad
kunwaratul hax0r
 
2021-10-14 The Critical Role of Security in DevOps.pdf
Savinder Puri
 
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
Security & DevOps- Ways To Make Sure Your Apps & Infrastructure Are Secure
Puppet
 
Ad

More from Checkmarx (9)

PDF
The Web AppSec How-To: The Defender's Toolbox
Checkmarx
 
PDF
10 Tips to Keep Your Software a Step Ahead of the Hackers
Checkmarx
 
PDF
The 5 Biggest Benefits of Source Code Analysis
Checkmarx
 
PDF
A Platform for Application Risk Intelligence
Checkmarx
 
PDF
How Virtual Compilation Transforms Static Code Analysis
Checkmarx
 
PDF
Source Code vs. Binary Code Analysis
Checkmarx
 
PDF
The App Sec How-To: Choosing a SAST Tool
Checkmarx
 
PDF
The Security State of The Most Popular WordPress Plug-Ins
Checkmarx
 
PDF
10 Steps To Secure Agile Development
Checkmarx
 
The Web AppSec How-To: The Defender's Toolbox
Checkmarx
 
10 Tips to Keep Your Software a Step Ahead of the Hackers
Checkmarx
 
The 5 Biggest Benefits of Source Code Analysis
Checkmarx
 
A Platform for Application Risk Intelligence
Checkmarx
 
How Virtual Compilation Transforms Static Code Analysis
Checkmarx
 
Source Code vs. Binary Code Analysis
Checkmarx
 
The App Sec How-To: Choosing a SAST Tool
Checkmarx
 
The Security State of The Most Popular WordPress Plug-Ins
Checkmarx
 
10 Steps To Secure Agile Development
Checkmarx
 

Recently uploaded (20)

PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PPTX
Seamless Tech Experiences Showcasing Cross-Platform App Design.pptx
presentifyai
 
PDF
Peak of Data & AI Encore AI-Enhanced Workflows for the Real World
Safe Software
 
PPTX
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PPTX
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
PDF
What’s my job again? Slides from Mark Simos talk at 2025 Tampa BSides
Mark Simos
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PDF
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PDF
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
PDF
Transcript: Book industry state of the nation 2025 - Tech Forum 2025
BookNet Canada
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
POV_ Why Enterprises Need to Find Value in ZERO.pdf
darshakparmar
 
PPTX
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
PDF
The 2025 InfraRed Report - Redpoint Ventures
Razin Mustafiz
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
Seamless Tech Experiences Showcasing Cross-Platform App Design.pptx
presentifyai
 
Peak of Data & AI Encore AI-Enhanced Workflows for the Real World
Safe Software
 
From Sci-Fi to Reality: Exploring AI Evolution
Svetlana Meissner
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
What’s my job again? Slides from Mark Simos talk at 2025 Tampa BSides
Mark Simos
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
Newgen 2022-Forrester Newgen TEI_13 05 2022-The-Total-Economic-Impact-Newgen-...
darshakparmar
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
Transcript: Book industry state of the nation 2025 - Tech Forum 2025
BookNet Canada
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
POV_ Why Enterprises Need to Find Value in ZERO.pdf
darshakparmar
 
OpenID AuthZEN - Analyst Briefing July 2025
David Brossard
 
The 2025 InfraRed Report - Redpoint Ventures
Razin Mustafiz
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 

DevOps & Security: Here & Now