SlideShare a Scribd company logo
1 of 21
Lean Security
A framework of security activities and design factors for
DevSecOps
Research performed under the guidance
of:
Dennis Verslegers
Strategic Advisor Application Security
Orange CyberDefense
Motivation
Approaches based on iterations over small units of work
promoting fast feedback and room for experimentation is
the best approach to build complex systems
Security is too often treated as an afterthought
Which security activities are relevant to DevSecOps and
how do we approach them (differently)?
Problem statement
Integrate security
assurance in DevOps
without increasing delay
Culture
Automation
Measurement
Sharing
Increasing regulatory
compliance requirements
Potential impact of breaches on
market value and reputation
Security is seen as an obstacle for
DevOps adoption
Mohan, Othmane, 2016
Tashi, 2009
Goel, Shawky, 2009
Sinanaj, Muntermann, 2015
Relies on experts
Documentation driven
Performed on finished product
Convential sequential security
activities create detering delays
between critically short iterations
and inflate development budgets
Beznosov, Kruchten, 2004
Increased speed of response
Auditability
Repeatability
Automation improves security
Forsgren, Smith, Humble, Frazelle, 2019
Doing DevOps well enables you to do
security well
Forsgren, Smith, Humble, Frazelle, 2019
Research approach
Integrate security
assurance in DevOps
without increasing delay
RQ1a: Definition of DevOps?
RQ1b: Definition of DevSecOps?
RQ2: Which set of security activities and
design factors relevant to DevOps
processes can be distinguished from
academic literature?
RQ3: How do the identified security
activities rank in terms of effectiveness
and delay from a practitioner point of
view?
Literature
review
Literature
review
Thematic
analysis
Expert survey
Expert survey
2 definitions
33 activities
87 design
factors
GSS session Prioritised list of
activities
Effectiveness
Delay
Financial
IQR
1
1
1
Research outcomes
CODE
BUILD
TEST
DEPLOY
OPERATE
MONITOR
Manage digital supply chain
Automated Software
Composition Analysis
Automated Container Image
Scanning
Scan artifact and source
code repositories
Threat modeling
Security Requirements
Security SLA cloud providers
Risk Analysis
Automated Security Testing
Automated Static Testing
Integrate security tests
with unit testing
Run-Time application
security testing
Establish Security Mindset Perform Security Training
Establish Security Satellites Perform Continuous Assurance
Manual Security Testing
Manual Penetration Testing
Manual Security
Verifications
Secrets management
Security Configuration
Automation
Automated Remediation
Practice Incident Response
Continuous Monitoring
Security Controls
Application behaviour
Ci/CD security metrics
System metrics
Security SLAs
Centralised dashboards
Self-service capabilities for
dev and ops
Continuous feedback from
prod to dev
Secure the Ci/CD pipeline
Prioritised list of
activities
Effectiveness
Delay
Financial
IQR
1
1
1
Effectiveness
Delay
Financial
IQR
1
1
1
Relevance
8 of 10 experts
Number of experts who
perceive the activity as
relevant to DevSecOps Inter-Quartile Range of
the expert scores
Rounded median score on effectiveness
(higher = more effective)
Rounded median score on delay
(higher = less delay)
Rounded median score on financial
impact
(higher = less impact)
Automated Security Testing
Leverage SecaaS by using cloud provided self-
managed, automated and scalable security services
Integrate the security tools in an automated
deployment pipeline
Automate as many security controls and verifications
as possible
Ensure the team and management understands and
supports the security validations integrated in the
automated deployment pipeline
Added by expert
Fail fast when security validations do not pass Added by expert
Integrate the validations in the Definition of Done Added by expert
Ensure APIs (of security verifications) align with
organisational processes allowing the implementation
to remain easy to understand
Added by expert
Automated testing is geared towards finding
implementation bugs but generally not suited to spot
design flaws
Added by expert
Usage and key takeaways
Integrate security
assurance in DevOps
without increasing delay
Framework
delay
effectiveness
financial
&
Tailor Model Assess
DevSecOps
roadmap
Provides a toolbox of what
(activities) and how (design factors)
for DevSecOps
Establish a security engineering mindset
Integrate security
assurance in DevOps
without increasing delay
Framework
DevSecOps is not so much about doing different things as it is about
doing things differently
DEV OPS
flow
Feedback loops
Continual experimentation and learning
Share security learning experiences and create a security
engineering mindset
Shift security responsibility to the teams and create
supporting mechanisms to get the job done
Leverage security automation capabilities wherever
possible
Establish security measurements to gain insights and create
learning opportunities
Favor reducing delay over other aspects (cost, licensing, …)
SAMM
Why + Objectives
Lean security
What + How
Potential next steps
Develop a reference implementation leveraging the existing
set of OWASP tools
Combine the results of this research with research
performed on the relationship between DevSecOps and
compliance
Develop a periodic table of the DevSecOps tooling
landscape
Executive Master in IT Risk & Cyber Security Management @
Antwerp Management School
https://www.lean-security.org
Thank you
Research performed under the guidance
of:
Dennis Verslegers
Strategic Advisor Application Security
Orange CyberDefense

More Related Content

Similar to Lean_Security.pptx

Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdfResolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdfMobibizIndia1
 
Achieving Security and Compliance in DevOps Best Strategies.pdf
Achieving Security and Compliance in DevOps Best Strategies.pdfAchieving Security and Compliance in DevOps Best Strategies.pdf
Achieving Security and Compliance in DevOps Best Strategies.pdfUrolime Technologies
 
DevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdfDevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdfTechugo
 
Shift Left Save Resources DevSecOps and the CICD Pipeline
Shift Left Save Resources DevSecOps and the CICD PipelineShift Left Save Resources DevSecOps and the CICD Pipeline
Shift Left Save Resources DevSecOps and the CICD PipelineCloudZenix LLC
 
DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.Techugo
 
How DevSecOps Can Help You Deliver Software Faster and Safer.pptx
How DevSecOps Can Help You Deliver Software Faster and Safer.pptxHow DevSecOps Can Help You Deliver Software Faster and Safer.pptx
How DevSecOps Can Help You Deliver Software Faster and Safer.pptxDev Software
 
DevSecOps: Integrating Security into DevOps
DevSecOps: Integrating Security into DevOpsDevSecOps: Integrating Security into DevOps
DevSecOps: Integrating Security into DevOpsDomain News Tech
 
Understanding DevSecOps.pdf
Understanding DevSecOps.pdfUnderstanding DevSecOps.pdf
Understanding DevSecOps.pdfCiente
 
DevOps and Devsecops.pdf
DevOps and Devsecops.pdfDevOps and Devsecops.pdf
DevOps and Devsecops.pdfTechugo
 
DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.Techugo
 
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...basilmph
 
DevSecOps: Integrating Security Into Your SDLC
DevSecOps: Integrating Security Into Your SDLCDevSecOps: Integrating Security Into Your SDLC
DevSecOps: Integrating Security Into Your SDLCDev Software
 
DevSecOps Best Practices-Safeguarding Your Digital Landscape
DevSecOps Best Practices-Safeguarding Your Digital LandscapeDevSecOps Best Practices-Safeguarding Your Digital Landscape
DevSecOps Best Practices-Safeguarding Your Digital Landscapestevecooper930744
 
Dev week cloud world conf2021
Dev week cloud world conf2021Dev week cloud world conf2021
Dev week cloud world conf2021Archana Joshi
 
How to implement DevOps for Enterprise
How to implement DevOps for EnterpriseHow to implement DevOps for Enterprise
How to implement DevOps for EnterpriseSimform
 
Intro to Security in SDLC
Intro to Security in SDLCIntro to Security in SDLC
Intro to Security in SDLCTjylen Veselyj
 
Devops security-An Insight into Secure-SDLC
Devops security-An Insight into Secure-SDLCDevops security-An Insight into Secure-SDLC
Devops security-An Insight into Secure-SDLCSuman Sourav
 
DevSecOps - offpage blog final draft - 03.docx
DevSecOps - offpage blog final draft - 03.docxDevSecOps - offpage blog final draft - 03.docx
DevSecOps - offpage blog final draft - 03.docxSun Technologies
 
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...CREST @ University of Adelaide
 

Similar to Lean_Security.pptx (20)

Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdfResolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
Resolving the Security Bottleneck Why DevSecOps is Better compared to DevOps.pdf
 
Achieving Security and Compliance in DevOps Best Strategies.pdf
Achieving Security and Compliance in DevOps Best Strategies.pdfAchieving Security and Compliance in DevOps Best Strategies.pdf
Achieving Security and Compliance in DevOps Best Strategies.pdf
 
DevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdfDevOps and Devsecops What are the Differences.pdf
DevOps and Devsecops What are the Differences.pdf
 
Shift Left Save Resources DevSecOps and the CICD Pipeline
Shift Left Save Resources DevSecOps and the CICD PipelineShift Left Save Resources DevSecOps and the CICD Pipeline
Shift Left Save Resources DevSecOps and the CICD Pipeline
 
DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.DevOps and Devsecops- What are the Differences.
DevOps and Devsecops- What are the Differences.
 
Introduction to DevSecOps
Introduction to DevSecOpsIntroduction to DevSecOps
Introduction to DevSecOps
 
How DevSecOps Can Help You Deliver Software Faster and Safer.pptx
How DevSecOps Can Help You Deliver Software Faster and Safer.pptxHow DevSecOps Can Help You Deliver Software Faster and Safer.pptx
How DevSecOps Can Help You Deliver Software Faster and Safer.pptx
 
DevSecOps: Integrating Security into DevOps
DevSecOps: Integrating Security into DevOpsDevSecOps: Integrating Security into DevOps
DevSecOps: Integrating Security into DevOps
 
Understanding DevSecOps.pdf
Understanding DevSecOps.pdfUnderstanding DevSecOps.pdf
Understanding DevSecOps.pdf
 
DevOps and Devsecops.pdf
DevOps and Devsecops.pdfDevOps and Devsecops.pdf
DevOps and Devsecops.pdf
 
DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.DevOps and Devsecops- Everything you need to know.
DevOps and Devsecops- Everything you need to know.
 
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...
How to Secure Your Outsourced Operations: The Ultimate Guide to DevOps as a S...
 
DevSecOps: Integrating Security Into Your SDLC
DevSecOps: Integrating Security Into Your SDLCDevSecOps: Integrating Security Into Your SDLC
DevSecOps: Integrating Security Into Your SDLC
 
DevSecOps Best Practices-Safeguarding Your Digital Landscape
DevSecOps Best Practices-Safeguarding Your Digital LandscapeDevSecOps Best Practices-Safeguarding Your Digital Landscape
DevSecOps Best Practices-Safeguarding Your Digital Landscape
 
Dev week cloud world conf2021
Dev week cloud world conf2021Dev week cloud world conf2021
Dev week cloud world conf2021
 
How to implement DevOps for Enterprise
How to implement DevOps for EnterpriseHow to implement DevOps for Enterprise
How to implement DevOps for Enterprise
 
Intro to Security in SDLC
Intro to Security in SDLCIntro to Security in SDLC
Intro to Security in SDLC
 
Devops security-An Insight into Secure-SDLC
Devops security-An Insight into Secure-SDLCDevops security-An Insight into Secure-SDLC
Devops security-An Insight into Secure-SDLC
 
DevSecOps - offpage blog final draft - 03.docx
DevSecOps - offpage blog final draft - 03.docxDevSecOps - offpage blog final draft - 03.docx
DevSecOps - offpage blog final draft - 03.docx
 
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
DevSecOps: Continuous Engineering with Security by Design: Challenges and Sol...
 

Recently uploaded

Olivia Cox. intertextual references.pptx
Olivia Cox. intertextual references.pptxOlivia Cox. intertextual references.pptx
Olivia Cox. intertextual references.pptxLauraFagan6
 
Karachi Escorts | +923070433345 | Escort Service in Karachi
Karachi Escorts | +923070433345 | Escort Service in KarachiKarachi Escorts | +923070433345 | Escort Service in Karachi
Karachi Escorts | +923070433345 | Escort Service in KarachiAyesha Khan
 
Akola Call Girls #9907093804 Contact Number Escorts Service Akola
Akola Call Girls #9907093804 Contact Number Escorts Service AkolaAkola Call Girls #9907093804 Contact Number Escorts Service Akola
Akola Call Girls #9907093804 Contact Number Escorts Service Akolasrsj9000
 
Aiims Call Girls : ☎ 8527673949, Low rate Call Girls
Aiims Call Girls : ☎ 8527673949, Low rate Call GirlsAiims Call Girls : ☎ 8527673949, Low rate Call Girls
Aiims Call Girls : ☎ 8527673949, Low rate Call Girlsashishs7044
 
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp Anytime
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp AnytimeRussian Call Girls Delhi NCR 9999965857 Call or WhatsApp Anytime
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp AnytimeKomal Khan
 
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | DelhiFULL ENJOY - 9953040155 Call Girls in Mahipalpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | DelhiMalviyaNagarCallGirl
 
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | Delhi
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | DelhiFULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | Delhi
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | DelhiMalviyaNagarCallGirl
 
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 60009654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000Sapana Sha
 
Zagor VČ OP 055 - Oluja nad Haitijem.pdf
Zagor VČ OP 055 - Oluja nad Haitijem.pdfZagor VČ OP 055 - Oluja nad Haitijem.pdf
Zagor VČ OP 055 - Oluja nad Haitijem.pdfStripovizijacom
 
Call Girl Service in Karachi +923081633338 Karachi Call Girls
Call Girl Service in Karachi +923081633338 Karachi Call GirlsCall Girl Service in Karachi +923081633338 Karachi Call Girls
Call Girl Service in Karachi +923081633338 Karachi Call GirlsAyesha Khan
 
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts ServiceRussian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Servicedoor45step
 
Govindpuri Call Girls : ☎ 8527673949, Low rate Call Girls
Govindpuri Call Girls : ☎ 8527673949, Low rate Call GirlsGovindpuri Call Girls : ☎ 8527673949, Low rate Call Girls
Govindpuri Call Girls : ☎ 8527673949, Low rate Call Girlsashishs7044
 
Kishangarh Call Girls : ☎ 8527673949, Low rate Call Girls
Kishangarh Call Girls : ☎ 8527673949, Low rate Call GirlsKishangarh Call Girls : ☎ 8527673949, Low rate Call Girls
Kishangarh Call Girls : ☎ 8527673949, Low rate Call Girlsashishs7044
 
FULL ENJOY - 9953040155 Call Girls in Noida | Delhi
FULL ENJOY - 9953040155 Call Girls in Noida | DelhiFULL ENJOY - 9953040155 Call Girls in Noida | Delhi
FULL ENJOY - 9953040155 Call Girls in Noida | DelhiMalviyaNagarCallGirl
 
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857delhimodel235
 
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts ServiceRussian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Servicedoor45step
 
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | Delhi
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | DelhiFULL ENJOY - 9953040155 Call Girls in Karol Bagh | Delhi
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | DelhiMalviyaNagarCallGirl
 
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | Delhi
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | DelhiFULL ENJOY - 9953040155 Call Girls in Uttam Nagar | Delhi
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | DelhiMalviyaNagarCallGirl
 
Roadrunner Lodge, Motel/Residence, Tucumcari NM
Roadrunner Lodge, Motel/Residence, Tucumcari NMRoadrunner Lodge, Motel/Residence, Tucumcari NM
Roadrunner Lodge, Motel/Residence, Tucumcari NMroute66connected
 

Recently uploaded (20)

Olivia Cox. intertextual references.pptx
Olivia Cox. intertextual references.pptxOlivia Cox. intertextual references.pptx
Olivia Cox. intertextual references.pptx
 
Karachi Escorts | +923070433345 | Escort Service in Karachi
Karachi Escorts | +923070433345 | Escort Service in KarachiKarachi Escorts | +923070433345 | Escort Service in Karachi
Karachi Escorts | +923070433345 | Escort Service in Karachi
 
Akola Call Girls #9907093804 Contact Number Escorts Service Akola
Akola Call Girls #9907093804 Contact Number Escorts Service AkolaAkola Call Girls #9907093804 Contact Number Escorts Service Akola
Akola Call Girls #9907093804 Contact Number Escorts Service Akola
 
Aiims Call Girls : ☎ 8527673949, Low rate Call Girls
Aiims Call Girls : ☎ 8527673949, Low rate Call GirlsAiims Call Girls : ☎ 8527673949, Low rate Call Girls
Aiims Call Girls : ☎ 8527673949, Low rate Call Girls
 
Dxb Call Girls # +971529501107 # Call Girls In Dxb Dubai || (UAE)
Dxb Call Girls # +971529501107 # Call Girls In Dxb Dubai || (UAE)Dxb Call Girls # +971529501107 # Call Girls In Dxb Dubai || (UAE)
Dxb Call Girls # +971529501107 # Call Girls In Dxb Dubai || (UAE)
 
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp Anytime
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp AnytimeRussian Call Girls Delhi NCR 9999965857 Call or WhatsApp Anytime
Russian Call Girls Delhi NCR 9999965857 Call or WhatsApp Anytime
 
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | DelhiFULL ENJOY - 9953040155 Call Girls in Mahipalpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Mahipalpur | Delhi
 
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | Delhi
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | DelhiFULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | Delhi
FULL ENJOY - 9953040155 Call Girls in Gandhi Vihar | Delhi
 
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 60009654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000
9654467111 Call Girls In Noida Sector 62 Short 1500 Night 6000
 
Zagor VČ OP 055 - Oluja nad Haitijem.pdf
Zagor VČ OP 055 - Oluja nad Haitijem.pdfZagor VČ OP 055 - Oluja nad Haitijem.pdf
Zagor VČ OP 055 - Oluja nad Haitijem.pdf
 
Call Girl Service in Karachi +923081633338 Karachi Call Girls
Call Girl Service in Karachi +923081633338 Karachi Call GirlsCall Girl Service in Karachi +923081633338 Karachi Call Girls
Call Girl Service in Karachi +923081633338 Karachi Call Girls
 
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts ServiceRussian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 104 Noida✨8375860717⚡Escorts Service
 
Govindpuri Call Girls : ☎ 8527673949, Low rate Call Girls
Govindpuri Call Girls : ☎ 8527673949, Low rate Call GirlsGovindpuri Call Girls : ☎ 8527673949, Low rate Call Girls
Govindpuri Call Girls : ☎ 8527673949, Low rate Call Girls
 
Kishangarh Call Girls : ☎ 8527673949, Low rate Call Girls
Kishangarh Call Girls : ☎ 8527673949, Low rate Call GirlsKishangarh Call Girls : ☎ 8527673949, Low rate Call Girls
Kishangarh Call Girls : ☎ 8527673949, Low rate Call Girls
 
FULL ENJOY - 9953040155 Call Girls in Noida | Delhi
FULL ENJOY - 9953040155 Call Girls in Noida | DelhiFULL ENJOY - 9953040155 Call Girls in Noida | Delhi
FULL ENJOY - 9953040155 Call Girls in Noida | Delhi
 
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857
Low Rate Call Girls in Laxmi Nagar Delhi Call 9990771857
 
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts ServiceRussian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Service
Russian⚡ Call Girls In Sector 39 Noida✨8375860717⚡Escorts Service
 
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | Delhi
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | DelhiFULL ENJOY - 9953040155 Call Girls in Karol Bagh | Delhi
FULL ENJOY - 9953040155 Call Girls in Karol Bagh | Delhi
 
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | Delhi
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | DelhiFULL ENJOY - 9953040155 Call Girls in Uttam Nagar | Delhi
FULL ENJOY - 9953040155 Call Girls in Uttam Nagar | Delhi
 
Roadrunner Lodge, Motel/Residence, Tucumcari NM
Roadrunner Lodge, Motel/Residence, Tucumcari NMRoadrunner Lodge, Motel/Residence, Tucumcari NM
Roadrunner Lodge, Motel/Residence, Tucumcari NM
 

Lean_Security.pptx

  • 1. Lean Security A framework of security activities and design factors for DevSecOps Research performed under the guidance of: Dennis Verslegers Strategic Advisor Application Security Orange CyberDefense
  • 3. Approaches based on iterations over small units of work promoting fast feedback and room for experimentation is the best approach to build complex systems Security is too often treated as an afterthought Which security activities are relevant to DevSecOps and how do we approach them (differently)?
  • 5. Integrate security assurance in DevOps without increasing delay Culture Automation Measurement Sharing Increasing regulatory compliance requirements Potential impact of breaches on market value and reputation Security is seen as an obstacle for DevOps adoption Mohan, Othmane, 2016 Tashi, 2009 Goel, Shawky, 2009 Sinanaj, Muntermann, 2015 Relies on experts Documentation driven Performed on finished product Convential sequential security activities create detering delays between critically short iterations and inflate development budgets Beznosov, Kruchten, 2004 Increased speed of response Auditability Repeatability Automation improves security Forsgren, Smith, Humble, Frazelle, 2019 Doing DevOps well enables you to do security well Forsgren, Smith, Humble, Frazelle, 2019
  • 7. Integrate security assurance in DevOps without increasing delay RQ1a: Definition of DevOps? RQ1b: Definition of DevSecOps? RQ2: Which set of security activities and design factors relevant to DevOps processes can be distinguished from academic literature? RQ3: How do the identified security activities rank in terms of effectiveness and delay from a practitioner point of view? Literature review Literature review Thematic analysis Expert survey Expert survey 2 definitions 33 activities 87 design factors GSS session Prioritised list of activities Effectiveness Delay Financial IQR 1 1 1
  • 9. CODE BUILD TEST DEPLOY OPERATE MONITOR Manage digital supply chain Automated Software Composition Analysis Automated Container Image Scanning Scan artifact and source code repositories Threat modeling Security Requirements Security SLA cloud providers Risk Analysis Automated Security Testing Automated Static Testing Integrate security tests with unit testing Run-Time application security testing Establish Security Mindset Perform Security Training Establish Security Satellites Perform Continuous Assurance Manual Security Testing Manual Penetration Testing Manual Security Verifications Secrets management Security Configuration Automation Automated Remediation Practice Incident Response Continuous Monitoring Security Controls Application behaviour Ci/CD security metrics System metrics Security SLAs Centralised dashboards Self-service capabilities for dev and ops Continuous feedback from prod to dev Secure the Ci/CD pipeline
  • 10. Prioritised list of activities Effectiveness Delay Financial IQR 1 1 1 Effectiveness Delay Financial IQR 1 1 1 Relevance 8 of 10 experts Number of experts who perceive the activity as relevant to DevSecOps Inter-Quartile Range of the expert scores Rounded median score on effectiveness (higher = more effective) Rounded median score on delay (higher = less delay) Rounded median score on financial impact (higher = less impact)
  • 11. Automated Security Testing Leverage SecaaS by using cloud provided self- managed, automated and scalable security services Integrate the security tools in an automated deployment pipeline Automate as many security controls and verifications as possible Ensure the team and management understands and supports the security validations integrated in the automated deployment pipeline Added by expert Fail fast when security validations do not pass Added by expert Integrate the validations in the Definition of Done Added by expert Ensure APIs (of security verifications) align with organisational processes allowing the implementation to remain easy to understand Added by expert Automated testing is geared towards finding implementation bugs but generally not suited to spot design flaws Added by expert
  • 12. Usage and key takeaways
  • 13. Integrate security assurance in DevOps without increasing delay Framework delay effectiveness financial & Tailor Model Assess DevSecOps roadmap Provides a toolbox of what (activities) and how (design factors) for DevSecOps
  • 14. Establish a security engineering mindset
  • 15. Integrate security assurance in DevOps without increasing delay Framework DevSecOps is not so much about doing different things as it is about doing things differently DEV OPS flow Feedback loops Continual experimentation and learning Share security learning experiences and create a security engineering mindset Shift security responsibility to the teams and create supporting mechanisms to get the job done Leverage security automation capabilities wherever possible Establish security measurements to gain insights and create learning opportunities Favor reducing delay over other aspects (cost, licensing, …)
  • 16. SAMM Why + Objectives Lean security What + How
  • 18. Develop a reference implementation leveraging the existing set of OWASP tools Combine the results of this research with research performed on the relationship between DevSecOps and compliance Develop a periodic table of the DevSecOps tooling landscape
  • 19. Executive Master in IT Risk & Cyber Security Management @ Antwerp Management School https://www.lean-security.org
  • 20.
  • 21. Thank you Research performed under the guidance of: Dennis Verslegers Strategic Advisor Application Security Orange CyberDefense