SlideShare a Scribd company logo
1 of 17
Download to read offline
2@aaronrinehart @verica_io #chaosengineering
WASHINGTON, DC, JUNE 25th, 2020 -- This
morning while vacationing in Washington, City,
W. B. Earp, a Marshal from Tombstone, A. T.,
arrested a cowboy named Aaron “Mad Dog”
Rinehart. Rinehart, a former Chief Security
Architect at United Healthcare, and formerly a
renegade at DoD, and NASA is a frequent
speaker and author on Chaos Engineering. As a
pioneer behind Security Chaos Engineering
he’s authored Chaos Engineering, and Security
Chaos Engineering books for O’Reilly. After
being fined twenty five dollars and disarmed in
the Justice’s Court, Rinehart left, swearing
vengeance with his Chaos Slingr.
CHAOS LEADER APPREHENDED BY
VACATIONING MARSHALL
3@djschleen @rally_health #deadpool
GOLDEN, CO, JUNE 25th, 2020 -- While on
his way to Glenwood Springs Bat Masterson
subdued DJ Schleen, while he was panning for
gold in Clear Creek. Schleen, a DevSecOps
pioneer and Application Security Manager at
Rally Health tried to evade capture with crafty
automation tactics. While on the run for the last
10 years, he’s been involved with the “DevOps
Crew” and has been preaching about automated
security at gatherings across the world and in
the books that he has written. After refusing to
pay the $10 fine, Schleen escaped using
automated security tools through engineering
pipelines.
ALLEGEDLY INSANE AUTOMATION
INNOVATOR CAPTURED IN COLORADO
A Grass Roots Beginning
• Teams across Silos & Disciplines w/ No Funding
• 60 Developers, Operations Engineers, and
Security Leaders from across the entire
company.• Began with Six Core DevOps Security Problem Sets
• Security Baseline + Configuration Validation w/
Chef & Inspec• Gauntlt Rugged Attack Framework
• Static Code Analysis (SAST): Automating
Fortify with Jenkins via API
• Application Vulnerability Scans(DAST):
Automating WebInspect with Jenkins via API
• DevOps Self-Governance & Operationalization
Framework: How does this world look from an
operational support perspective?
• Clair Container Image Scanning: Building Image
Scanning into Jenkins
Warm Regards, Aaron
The Journey
It all started when I was part of a startup
recently acquired by a massive healthcare
organization.
We needed to rapidly address problems with
new technologies and built our own
orchestration when no other tools were
available
We started with nothing and needed to steer
the boat towards AppSec as a practice.
Security had become more than GRC,
TPRG, IAM, SOC.
There were pockets of knowledge, no centers
of excellence in software security.
D.J. Schleen, ESQ
Eureka! Gold!
Successfully delivered an open source DAST tool
into CI/CD pipeline to drive instrumentation of
runtime security left in the delivery pipeline
Drove down delivery times of highly regulated
workloads by automating the verification of security
hardening configuration using InSpec
Delivered the ability for teams to initiate their own
DAST/SAST scanning via API
Adopted Commercial IAST solution. Took a very
long time to procure but saved the company millions
of dollars in efficiency per month.
Built empathy within the Security Organization by
adopting a Everyone Must Learn to Code learning
development
Warm Regards, Aaron
The Good Parts
Reduced overall vulnerabilities in our
code base
Educational programs (mentoring,
champions, etc) helped both developers
and security engineers understand the
challenges facing each other
Codifying automation improved
efficiency
Developers could react to vulnerabilities
and zero days faster than they could
without security in the mindset
D.J. Schleen, ESQ
Fools Gold!
Dagnabbit. We started with a
SAST program first - should
have started with OSS
Started with tools but should
have started with
relationships
We foolishly looked at
integration first before
knowing where the highest
risk application code was!
D.J. Schleen, ESQ
Can we have a do-over?
Focus on top down transformation
more. Bottom-Up was more
successful until we hit a point of
needing funding to go further
Spend more time helping to
transform flagship company
products. This sets the proper tone
for the rest of the enterprise.
Spend more time educating
security counterparts on the
business value of what
transforming
•
Warm Regards, Aaron
Image courtesy of Warner Bros.
A need for a Compass
Initially automating our existing
SAST/DAST scanning tools via API
caused the scanning infrastructure to
crash. The servers that supported it could
not withstand the volume.
Initially implementing Secrets
Management was difficult. Security
teams did not understand what software
secrets were. There was confusion
between Secrets and Privileged
Accounts.
Docker Container Image Scanning with
Clair didn’t meet needs
Warm Regards, Aaron
Hold yer Horses
We failed builds based on security
vulnerabilities before we helped
burn down vulnerabilities.
Doing this blocked production
deployments.
Blocked deployments meant
controls were taken out without
security knowledge.
We tried to move too quickly and
didn’t plan as much as we should
have
D.J. Schleen, ESQ
How to ride a Horse
Important Skills are Listening and Mutual Empathy
Show something Built is Better than an Idea
Fail small, fail fast
Its a culture shift, not just about automation
Continuous Learning is more important than
Continuous Fixing
Don't try to reduce complexity, learn to navigate it.
Avoid Analysis Paralysis: DevOps is a culture and
a living organism
DevOps is not a fad, it is the future
Automation is Important but “Don’t be Distracted
by it
Warm Regards, Aaron
Colorado Territory
If people aren’t on board, nobody cares.
You’re dealing with traditional security
organizations being assholes. That
shouldn’t be surprising.
Don’t invite people to your party if you
aren’t ready yet.
Know (or at least have a good idea)
where the highest risks are.
Look before you automate (look before
you cross the road)
Its the human fear of not being in control
that hinders automation.
D.J. Schleen, ESQ
Witchcraft
Tools haven’t caught up yet. We areusing flashlights for high mountedbrake lights and feathers when we
need airbags
Current Security Tooling SUCKS
We’ll see more innovation in thedetection of security issues
Tighter feedback loops for securityissues - fixing security issues withconfidence of break risk
DevSecOps becomes known as
“Engineering”
D.J. Schleen, ESQ
Snake Oil
The Next Generation of Security Professionals
will be Chosen from DevOps Teams
Shared Responsibility becomes more of a
reality.
Security continues the move towards value
stream
Security becomes a recognized skill within
Site Reliability Engineering (SRE)
Chaos Engineering becomes a core discipline
within DevSecOps
Compliance in DevSecOps becomes a
byproduct of good engineering practices
•
•
•
Warm Regards, Aaron
@djschleen @aaronrinehart
cutt.ly/verica-book
Free copy mailed to you complements of Verica

More Related Content

What's hot

Biometrics and Multi-Factor Authentication, The Unleashed Dragon
Biometrics and Multi-Factor Authentication, The Unleashed DragonBiometrics and Multi-Factor Authentication, The Unleashed Dragon
Biometrics and Multi-Factor Authentication, The Unleashed DragonClare Nelson, CISSP, CIPP-E
 
What we learned from three years sciencing the crap out of devops
What we learned from three years sciencing the crap out of devopsWhat we learned from three years sciencing the crap out of devops
What we learned from three years sciencing the crap out of devopsNicole Forsgren
 
A DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and PeopleA DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and PeopleJames Wickett
 
How secure are your IT systems? (Darrell Burkey, CASE)
How secure are your IT systems? (Darrell Burkey, CASE)How secure are your IT systems? (Darrell Burkey, CASE)
How secure are your IT systems? (Darrell Burkey, CASE)makinglinks
 
Continuous Security: 5 Ways DevOps Improves Security
Continuous Security: 5 Ways DevOps Improves SecurityContinuous Security: 5 Ways DevOps Improves Security
Continuous Security: 5 Ways DevOps Improves SecuritySonatype
 
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSec
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSecDevOps Connect: Josh Corman and Gene Kim discuss DevOpsSec
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSecSonatype
 
Acquiforce H4D Stanford 2018 final presentation
Acquiforce H4D Stanford 2018 final presentationAcquiforce H4D Stanford 2018 final presentation
Acquiforce H4D Stanford 2018 final presentationStanford University
 
Biometric Recognition for Authentication, BSides Austin, May 2017
Biometric Recognition for Authentication, BSides Austin, May 2017Biometric Recognition for Authentication, BSides Austin, May 2017
Biometric Recognition for Authentication, BSides Austin, May 2017Clare Nelson, CISSP, CIPP-E
 

What's hot (10)

Biometrics and Multi-Factor Authentication, The Unleashed Dragon
Biometrics and Multi-Factor Authentication, The Unleashed DragonBiometrics and Multi-Factor Authentication, The Unleashed Dragon
Biometrics and Multi-Factor Authentication, The Unleashed Dragon
 
What we learned from three years sciencing the crap out of devops
What we learned from three years sciencing the crap out of devopsWhat we learned from three years sciencing the crap out of devops
What we learned from three years sciencing the crap out of devops
 
A DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and PeopleA DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and People
 
Theia H4D Stanford 2018
Theia H4D Stanford 2018Theia H4D Stanford 2018
Theia H4D Stanford 2018
 
How secure are your IT systems? (Darrell Burkey, CASE)
How secure are your IT systems? (Darrell Burkey, CASE)How secure are your IT systems? (Darrell Burkey, CASE)
How secure are your IT systems? (Darrell Burkey, CASE)
 
Continuous Security: 5 Ways DevOps Improves Security
Continuous Security: 5 Ways DevOps Improves SecurityContinuous Security: 5 Ways DevOps Improves Security
Continuous Security: 5 Ways DevOps Improves Security
 
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSec
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSecDevOps Connect: Josh Corman and Gene Kim discuss DevOpsSec
DevOps Connect: Josh Corman and Gene Kim discuss DevOpsSec
 
Acquiforce H4D Stanford 2018 final presentation
Acquiforce H4D Stanford 2018 final presentationAcquiforce H4D Stanford 2018 final presentation
Acquiforce H4D Stanford 2018 final presentation
 
Biometric Recognition for Authentication, BSides Austin, May 2017
Biometric Recognition for Authentication, BSides Austin, May 2017Biometric Recognition for Authentication, BSides Austin, May 2017
Biometric Recognition for Authentication, BSides Austin, May 2017
 
Panacea H4D Stanford 2019
Panacea H4D Stanford 2019Panacea H4D Stanford 2019
Panacea H4D Stanford 2019
 

Similar to Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)

Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)DJ Schleen
 
Craft 2019 - Security Chaos Engineering - Security Precognition
Craft 2019 - Security Chaos Engineering - Security PrecognitionCraft 2019 - Security Chaos Engineering - Security Precognition
Craft 2019 - Security Chaos Engineering - Security PrecognitionAaron Rinehart
 
ADDO - Navigating the DevSecOps App-ocalypse 2020
ADDO - Navigating the DevSecOps App-ocalypse 2020 ADDO - Navigating the DevSecOps App-ocalypse 2020
ADDO - Navigating the DevSecOps App-ocalypse 2020 Aaron Rinehart
 
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"Aaron Rinehart
 
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019Aaron Rinehart
 
DevSecOps at Agile 2019
DevSecOps at   Agile 2019 DevSecOps at   Agile 2019
DevSecOps at Agile 2019 Elizabeth Ayer
 
The Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CDThe Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CDJames Wickett
 
pbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxpbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxJulie Tsai
 
AllTheTalks Security Chaos Engineering
AllTheTalks Security Chaos Engineering AllTheTalks Security Chaos Engineering
AllTheTalks Security Chaos Engineering Aaron Rinehart
 
Shift Left Security – Guidance on embedding security for a Digital Transforma...
Shift Left Security – Guidance on embedding security for a Digital Transforma...Shift Left Security – Guidance on embedding security for a Digital Transforma...
Shift Left Security – Guidance on embedding security for a Digital Transforma...Yazad Khandhadia
 
DevOps for Defenders in the Enterprise
DevOps for Defenders in the EnterpriseDevOps for Defenders in the Enterprise
DevOps for Defenders in the EnterpriseJames Wickett
 
DevSecOps and the CI/CD Pipeline
 DevSecOps and the CI/CD Pipeline DevSecOps and the CI/CD Pipeline
DevSecOps and the CI/CD PipelineJames Wickett
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineThe DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineJames Wickett
 
Agile Relevance in the age of Continuous Everything ....
Agile Relevance in the age of Continuous Everything ....Agile Relevance in the age of Continuous Everything ....
Agile Relevance in the age of Continuous Everything ....Eturnti Consulting Pvt Ltd
 
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...Emrah Alpa, CISSP CEH CCSK
 
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...Aaron Rinehart
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...Patrick Thomas
 
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-AutomationDevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-AutomationAlex Senkevitch
 
Security precognition chaos engineering in incident response
Security precognition  chaos engineering in incident responseSecurity precognition  chaos engineering in incident response
Security precognition chaos engineering in incident responsePriyanka Aash
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptxSecure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptxlior mazor
 

Similar to Blameless Retrospectives in DevSecOps (at Global Healthcare Giants) (20)

Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)
 
Craft 2019 - Security Chaos Engineering - Security Precognition
Craft 2019 - Security Chaos Engineering - Security PrecognitionCraft 2019 - Security Chaos Engineering - Security Precognition
Craft 2019 - Security Chaos Engineering - Security Precognition
 
ADDO - Navigating the DevSecOps App-ocalypse 2020
ADDO - Navigating the DevSecOps App-ocalypse 2020 ADDO - Navigating the DevSecOps App-ocalypse 2020
ADDO - Navigating the DevSecOps App-ocalypse 2020
 
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"
VMWare Tech Talk: "The Road from Rugged DevOps to Security Chaos Engineering"
 
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019
Velocity 2019 - Security Precognition 2019 Slides - San Jose 2019
 
DevSecOps at Agile 2019
DevSecOps at   Agile 2019 DevSecOps at   Agile 2019
DevSecOps at Agile 2019
 
The Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CDThe Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CD
 
pbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxpbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptx
 
AllTheTalks Security Chaos Engineering
AllTheTalks Security Chaos Engineering AllTheTalks Security Chaos Engineering
AllTheTalks Security Chaos Engineering
 
Shift Left Security – Guidance on embedding security for a Digital Transforma...
Shift Left Security – Guidance on embedding security for a Digital Transforma...Shift Left Security – Guidance on embedding security for a Digital Transforma...
Shift Left Security – Guidance on embedding security for a Digital Transforma...
 
DevOps for Defenders in the Enterprise
DevOps for Defenders in the EnterpriseDevOps for Defenders in the Enterprise
DevOps for Defenders in the Enterprise
 
DevSecOps and the CI/CD Pipeline
 DevSecOps and the CI/CD Pipeline DevSecOps and the CI/CD Pipeline
DevSecOps and the CI/CD Pipeline
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineThe DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD Pipeline
 
Agile Relevance in the age of Continuous Everything ....
Agile Relevance in the age of Continuous Everything ....Agile Relevance in the age of Continuous Everything ....
Agile Relevance in the age of Continuous Everything ....
 
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...
Micro Focus SRG Solution Mapping to the New BDDK Regulations for Turkish Fina...
 
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...
HealthConDX Virtual Summit 2021 - How Security Chaos Engineering is Changing ...
 
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
OWASP AppSec Cali 2018 - Enabling Product Security With Culture and Cloud (As...
 
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-AutomationDevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
DevSecOps: A Secure SDLC in the Age of DevOps and Hyper-Automation
 
Security precognition chaos engineering in incident response
Security precognition  chaos engineering in incident responseSecurity precognition  chaos engineering in incident response
Security precognition chaos engineering in incident response
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptxSecure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
 

Recently uploaded

My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfngoud9212
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfjimielynbastida
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 

Recently uploaded (20)

My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
Bluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdfBluetooth Controlled Car with Arduino.pdf
Bluetooth Controlled Car with Arduino.pdf
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdf
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 

Blameless Retrospectives in DevSecOps (at Global Healthcare Giants)

  • 1.
  • 2. 2@aaronrinehart @verica_io #chaosengineering WASHINGTON, DC, JUNE 25th, 2020 -- This morning while vacationing in Washington, City, W. B. Earp, a Marshal from Tombstone, A. T., arrested a cowboy named Aaron “Mad Dog” Rinehart. Rinehart, a former Chief Security Architect at United Healthcare, and formerly a renegade at DoD, and NASA is a frequent speaker and author on Chaos Engineering. As a pioneer behind Security Chaos Engineering he’s authored Chaos Engineering, and Security Chaos Engineering books for O’Reilly. After being fined twenty five dollars and disarmed in the Justice’s Court, Rinehart left, swearing vengeance with his Chaos Slingr. CHAOS LEADER APPREHENDED BY VACATIONING MARSHALL
  • 3. 3@djschleen @rally_health #deadpool GOLDEN, CO, JUNE 25th, 2020 -- While on his way to Glenwood Springs Bat Masterson subdued DJ Schleen, while he was panning for gold in Clear Creek. Schleen, a DevSecOps pioneer and Application Security Manager at Rally Health tried to evade capture with crafty automation tactics. While on the run for the last 10 years, he’s been involved with the “DevOps Crew” and has been preaching about automated security at gatherings across the world and in the books that he has written. After refusing to pay the $10 fine, Schleen escaped using automated security tools through engineering pipelines. ALLEGEDLY INSANE AUTOMATION INNOVATOR CAPTURED IN COLORADO
  • 4.
  • 5.
  • 6.
  • 7. A Grass Roots Beginning • Teams across Silos & Disciplines w/ No Funding • 60 Developers, Operations Engineers, and Security Leaders from across the entire company.• Began with Six Core DevOps Security Problem Sets • Security Baseline + Configuration Validation w/ Chef & Inspec• Gauntlt Rugged Attack Framework • Static Code Analysis (SAST): Automating Fortify with Jenkins via API • Application Vulnerability Scans(DAST): Automating WebInspect with Jenkins via API • DevOps Self-Governance & Operationalization Framework: How does this world look from an operational support perspective? • Clair Container Image Scanning: Building Image Scanning into Jenkins Warm Regards, Aaron The Journey It all started when I was part of a startup recently acquired by a massive healthcare organization. We needed to rapidly address problems with new technologies and built our own orchestration when no other tools were available We started with nothing and needed to steer the boat towards AppSec as a practice. Security had become more than GRC, TPRG, IAM, SOC. There were pockets of knowledge, no centers of excellence in software security. D.J. Schleen, ESQ
  • 8. Eureka! Gold! Successfully delivered an open source DAST tool into CI/CD pipeline to drive instrumentation of runtime security left in the delivery pipeline Drove down delivery times of highly regulated workloads by automating the verification of security hardening configuration using InSpec Delivered the ability for teams to initiate their own DAST/SAST scanning via API Adopted Commercial IAST solution. Took a very long time to procure but saved the company millions of dollars in efficiency per month. Built empathy within the Security Organization by adopting a Everyone Must Learn to Code learning development Warm Regards, Aaron The Good Parts Reduced overall vulnerabilities in our code base Educational programs (mentoring, champions, etc) helped both developers and security engineers understand the challenges facing each other Codifying automation improved efficiency Developers could react to vulnerabilities and zero days faster than they could without security in the mindset D.J. Schleen, ESQ
  • 9. Fools Gold! Dagnabbit. We started with a SAST program first - should have started with OSS Started with tools but should have started with relationships We foolishly looked at integration first before knowing where the highest risk application code was! D.J. Schleen, ESQ Can we have a do-over? Focus on top down transformation more. Bottom-Up was more successful until we hit a point of needing funding to go further Spend more time helping to transform flagship company products. This sets the proper tone for the rest of the enterprise. Spend more time educating security counterparts on the business value of what transforming • Warm Regards, Aaron
  • 10.
  • 11. Image courtesy of Warner Bros.
  • 12. A need for a Compass Initially automating our existing SAST/DAST scanning tools via API caused the scanning infrastructure to crash. The servers that supported it could not withstand the volume. Initially implementing Secrets Management was difficult. Security teams did not understand what software secrets were. There was confusion between Secrets and Privileged Accounts. Docker Container Image Scanning with Clair didn’t meet needs Warm Regards, Aaron Hold yer Horses We failed builds based on security vulnerabilities before we helped burn down vulnerabilities. Doing this blocked production deployments. Blocked deployments meant controls were taken out without security knowledge. We tried to move too quickly and didn’t plan as much as we should have D.J. Schleen, ESQ
  • 13. How to ride a Horse Important Skills are Listening and Mutual Empathy Show something Built is Better than an Idea Fail small, fail fast Its a culture shift, not just about automation Continuous Learning is more important than Continuous Fixing Don't try to reduce complexity, learn to navigate it. Avoid Analysis Paralysis: DevOps is a culture and a living organism DevOps is not a fad, it is the future Automation is Important but “Don’t be Distracted by it Warm Regards, Aaron Colorado Territory If people aren’t on board, nobody cares. You’re dealing with traditional security organizations being assholes. That shouldn’t be surprising. Don’t invite people to your party if you aren’t ready yet. Know (or at least have a good idea) where the highest risks are. Look before you automate (look before you cross the road) Its the human fear of not being in control that hinders automation. D.J. Schleen, ESQ
  • 14.
  • 15. Witchcraft Tools haven’t caught up yet. We areusing flashlights for high mountedbrake lights and feathers when we need airbags Current Security Tooling SUCKS We’ll see more innovation in thedetection of security issues Tighter feedback loops for securityissues - fixing security issues withconfidence of break risk DevSecOps becomes known as “Engineering” D.J. Schleen, ESQ Snake Oil The Next Generation of Security Professionals will be Chosen from DevOps Teams Shared Responsibility becomes more of a reality. Security continues the move towards value stream Security becomes a recognized skill within Site Reliability Engineering (SRE) Chaos Engineering becomes a core discipline within DevSecOps Compliance in DevSecOps becomes a byproduct of good engineering practices • • • Warm Regards, Aaron
  • 16.
  • 17. @djschleen @aaronrinehart cutt.ly/verica-book Free copy mailed to you complements of Verica