Submit Search
Upload
OpenControl Overview - Joshua McKenty
•
1 like
•
369 views
J
Julie Coonce
Follow
Joshua McKenty Talks OpenControl @ Cloud Native DC Meetup || March 8, 2016
Read less
Read more
Technology
Report
Share
Report
Share
1 of 17
Download now
Download to read offline
Recommended
Cloud Native Future
Cloud Native Future
Julie Coonce
DevOps: Process, Tool or Mindset?
DevOps: Process, Tool or Mindset?
Tathagat Varma
Devops skills you got what it takes ?
Devops skills you got what it takes ?
Initcron Systems Private Limited
A DevOps Mario Developer Game Challenge with GRC
A DevOps Mario Developer Game Challenge with GRC
BMK Lakshminarayanan
DevOps-Redefining your IT Strategy-28thJan15
DevOps-Redefining your IT Strategy-28thJan15
Edureka!
Death to the DevOps team - Agile Cambridge 2014
Death to the DevOps team - Agile Cambridge 2014
Matthew Skelton
Devops
Devops
Fernando Ike
Introduction to devops - update 2017
Introduction to devops - update 2017
gjdevos
Recommended
Cloud Native Future
Cloud Native Future
Julie Coonce
DevOps: Process, Tool or Mindset?
DevOps: Process, Tool or Mindset?
Tathagat Varma
Devops skills you got what it takes ?
Devops skills you got what it takes ?
Initcron Systems Private Limited
A DevOps Mario Developer Game Challenge with GRC
A DevOps Mario Developer Game Challenge with GRC
BMK Lakshminarayanan
DevOps-Redefining your IT Strategy-28thJan15
DevOps-Redefining your IT Strategy-28thJan15
Edureka!
Death to the DevOps team - Agile Cambridge 2014
Death to the DevOps team - Agile Cambridge 2014
Matthew Skelton
Devops
Devops
Fernando Ike
Introduction to devops - update 2017
Introduction to devops - update 2017
gjdevos
DevOps 101 - an Introduction to DevOps
DevOps 101 - an Introduction to DevOps
Red Gate Software
Introduction to DevOps
Introduction to DevOps
Md. Mazharul Anwar
DevOps
DevOps
Hakan Yüksel
Introduction to DevOps
Introduction to DevOps
João Miranda
Dev ops
Dev ops
Eslam El Husseiny
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
Edureka!
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
BMK Lakshminarayanan
DevOps Culture & Methodology Intro
DevOps Culture & Methodology Intro
Najib Radzuan
DevOps - Understanding Core Concepts
DevOps - Understanding Core Concepts
Nitin Bhide
DevOps 2016 summit
DevOps 2016 summit
Chihyang Li
DevOps Introduction
DevOps Introduction
Robert Sell
DevOps by examples - Continuous Lifecycle London 2017
DevOps by examples - Continuous Lifecycle London 2017
Giulio Vian
Introduction to devops 2016
Introduction to devops 2016
gjdevos
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
David Walker
Meetup DevOps - Accelerate
Meetup DevOps - Accelerate
Delta-N
eDevOps in HPSW from buzzword to reality
eDevOps in HPSW from buzzword to reality
AgileSparks
DevOps: A Culture Transformation, More than Technology
DevOps: A Culture Transformation, More than Technology
CA Technologies
DevOps without DevOps Tools
DevOps without DevOps Tools
Jagatveer Singh
Devops
Devops
Kris Buytaert
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
WinOps Conf
Cloud native Microservices using Spring Boot
Cloud native Microservices using Spring Boot
Sufyaan Kazi
Modernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIs
Apigee | Google Cloud
More Related Content
What's hot
DevOps 101 - an Introduction to DevOps
DevOps 101 - an Introduction to DevOps
Red Gate Software
Introduction to DevOps
Introduction to DevOps
Md. Mazharul Anwar
DevOps
DevOps
Hakan Yüksel
Introduction to DevOps
Introduction to DevOps
João Miranda
Dev ops
Dev ops
Eslam El Husseiny
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
Edureka!
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
BMK Lakshminarayanan
DevOps Culture & Methodology Intro
DevOps Culture & Methodology Intro
Najib Radzuan
DevOps - Understanding Core Concepts
DevOps - Understanding Core Concepts
Nitin Bhide
DevOps 2016 summit
DevOps 2016 summit
Chihyang Li
DevOps Introduction
DevOps Introduction
Robert Sell
DevOps by examples - Continuous Lifecycle London 2017
DevOps by examples - Continuous Lifecycle London 2017
Giulio Vian
Introduction to devops 2016
Introduction to devops 2016
gjdevos
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
David Walker
Meetup DevOps - Accelerate
Meetup DevOps - Accelerate
Delta-N
eDevOps in HPSW from buzzword to reality
eDevOps in HPSW from buzzword to reality
AgileSparks
DevOps: A Culture Transformation, More than Technology
DevOps: A Culture Transformation, More than Technology
CA Technologies
DevOps without DevOps Tools
DevOps without DevOps Tools
Jagatveer Singh
Devops
Devops
Kris Buytaert
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
WinOps Conf
What's hot
(20)
DevOps 101 - an Introduction to DevOps
DevOps 101 - an Introduction to DevOps
Introduction to DevOps
Introduction to DevOps
DevOps
DevOps
Introduction to DevOps
Introduction to DevOps
Dev ops
Dev ops
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
What is DevOps | DevOps Introduction | DevOps Training | DevOps Tutorial | Ed...
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
How to Avoid Cloud Confusion, DevOps dilemma, Microservice Madness
DevOps Culture & Methodology Intro
DevOps Culture & Methodology Intro
DevOps - Understanding Core Concepts
DevOps - Understanding Core Concepts
DevOps 2016 summit
DevOps 2016 summit
DevOps Introduction
DevOps Introduction
DevOps by examples - Continuous Lifecycle London 2017
DevOps by examples - Continuous Lifecycle London 2017
Introduction to devops 2016
Introduction to devops 2016
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
Devops & Agility - Build the Culture, Get the Tools, Win the Day - Dundee Tec...
Meetup DevOps - Accelerate
Meetup DevOps - Accelerate
eDevOps in HPSW from buzzword to reality
eDevOps in HPSW from buzzword to reality
DevOps: A Culture Transformation, More than Technology
DevOps: A Culture Transformation, More than Technology
DevOps without DevOps Tools
DevOps without DevOps Tools
Devops
Devops
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
WinOps Conf 2016 - Matteo Emili - Development and QA Dilemmas in DevOps
Similar to OpenControl Overview - Joshua McKenty
Cloud native Microservices using Spring Boot
Cloud native Microservices using Spring Boot
Sufyaan Kazi
Modernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIs
Apigee | Google Cloud
Removing Barriers Between Dev and Ops
Removing Barriers Between Dev and Ops
Marie-Jeanne Dougados
2016 Federal User Group Conference - DevOps Product Strategy
2016 Federal User Group Conference - DevOps Product Strategy
CollabNet
WebSocket in Enterprise Applications 2015
WebSocket in Enterprise Applications 2015
Pavel Bucek
DevOps Deconstructed
DevOps Deconstructed
Jeremy Pullen
Il paradigma DevOps e Continuous Delivery Automation
Il paradigma DevOps e Continuous Delivery Automation
HP Enterprise Italia
Pivotal CF 소개
Pivotal CF 소개
seungdon Choi
Delivering Applications Continuously to Cloud
Delivering Applications Continuously to Cloud
IBM UrbanCode Products
Tweet for Beer - Beertap Powered by Java Goes IoT, Cloud, and JavaFX
Tweet for Beer - Beertap Powered by Java Goes IoT, Cloud, and JavaFX
Bruno Borges
Linux Foundation Japan 2015
Linux Foundation Japan 2015
Jason Jackson
The Power of Java and Oracle WebLogic Server in the Public Cloud (OpenWorld, ...
The Power of Java and Oracle WebLogic Server in the Public Cloud (OpenWorld, ...
jeckels
SOA_BPM_12c_launch_event_BPM_track_proficiency_features_joost_volker_oracle
SOA_BPM_12c_launch_event_BPM_track_proficiency_features_joost_volker_oracle
Getting value from IoT, Integration and Data Analytics
Cloud Roundtable | Pivoltal: Agile platform
Cloud Roundtable | Pivoltal: Agile platform
Codemotion
Łukasz Romaszewski on Internet of Things Raspberry Pi and Java Embedded JavaC...
Łukasz Romaszewski on Internet of Things Raspberry Pi and Java Embedded JavaC...
Tomek Borek
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
OpenStack Korea Community
DOES SFO 2016 - Scott Willson - Top 10 Ways to Fail at DevOps
DOES SFO 2016 - Scott Willson - Top 10 Ways to Fail at DevOps
Gene Kim
Harman deepak v - agile on steriod - dev ops led transformation
Harman deepak v - agile on steriod - dev ops led transformation
Xebia India
Pivotal Cloud Platform Roadshow Keynote
Pivotal Cloud Platform Roadshow Keynote
cornelia davis
Oracle REST Data Services
Oracle REST Data Services
Chris Muir
Similar to OpenControl Overview - Joshua McKenty
(20)
Cloud native Microservices using Spring Boot
Cloud native Microservices using Spring Boot
Modernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIs
Removing Barriers Between Dev and Ops
Removing Barriers Between Dev and Ops
2016 Federal User Group Conference - DevOps Product Strategy
2016 Federal User Group Conference - DevOps Product Strategy
WebSocket in Enterprise Applications 2015
WebSocket in Enterprise Applications 2015
DevOps Deconstructed
DevOps Deconstructed
Il paradigma DevOps e Continuous Delivery Automation
Il paradigma DevOps e Continuous Delivery Automation
Pivotal CF 소개
Pivotal CF 소개
Delivering Applications Continuously to Cloud
Delivering Applications Continuously to Cloud
Tweet for Beer - Beertap Powered by Java Goes IoT, Cloud, and JavaFX
Tweet for Beer - Beertap Powered by Java Goes IoT, Cloud, and JavaFX
Linux Foundation Japan 2015
Linux Foundation Japan 2015
The Power of Java and Oracle WebLogic Server in the Public Cloud (OpenWorld, ...
The Power of Java and Oracle WebLogic Server in the Public Cloud (OpenWorld, ...
SOA_BPM_12c_launch_event_BPM_track_proficiency_features_joost_volker_oracle
SOA_BPM_12c_launch_event_BPM_track_proficiency_features_joost_volker_oracle
Cloud Roundtable | Pivoltal: Agile platform
Cloud Roundtable | Pivoltal: Agile platform
Łukasz Romaszewski on Internet of Things Raspberry Pi and Java Embedded JavaC...
Łukasz Romaszewski on Internet of Things Raspberry Pi and Java Embedded JavaC...
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
[2015-11월 정기 세미나] Cloud Native Platform - Pivotal
DOES SFO 2016 - Scott Willson - Top 10 Ways to Fail at DevOps
DOES SFO 2016 - Scott Willson - Top 10 Ways to Fail at DevOps
Harman deepak v - agile on steriod - dev ops led transformation
Harman deepak v - agile on steriod - dev ops led transformation
Pivotal Cloud Platform Roadshow Keynote
Pivotal Cloud Platform Roadshow Keynote
Oracle REST Data Services
Oracle REST Data Services
Recently uploaded
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
Padma Pradeep
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
Fwdays
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
Commit University
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
Memoori
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
null - The Open Security Community
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April Automation LPDG
MarianaLemus7
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
Dubai Multi Commodity Centre
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
Florian Wilhelm
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
Ridwan Fadjar
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
charlottematthew16
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
Miki Katsuragi
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
hariprasad279825
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
Alex Barbosa Coqueiro
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Wonjun Hwang
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
BookNet Canada
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Safe Software
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Mark Simos
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
Pixlogix Infotech
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
Fwdays
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
2toLead Limited
Recently uploaded
(20)
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April Automation LPDG
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
Vertex AI Gemini Prompt Engineering Tips
Vertex AI Gemini Prompt Engineering Tips
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
OpenControl Overview - Joshua McKenty
1.
1© 2014 Pivotal
Software, Inc. All rights reserved. 1© 2014 Pivotal Software, Inc. All rights reserved. Compliance as Code thru Continuous Authorization for A&A Joshua McKenty, Pivotal
2.
“Bureaucracy is the
art of making the possible impossible.” ~ Javier Pascal Salcedo
3.
3© 2014 Pivotal
Software, Inc. All rights reserved. What: Automated Pipelines of A&A As TDD is to Development, and DevOps is to Operations, so OpenControl is to Compliance.
4.
4© 2014 Pivotal
Software, Inc. All rights reserved. Why? Ÿ Speed is everything – Respond quickly to CVEs – Respond quickly to mission requirements – Deploy frequently to avoid “Big-Bang” risks Ÿ Automation makes Speed possible Ÿ (Bonus: Automation makes security BETTER!)
5.
5© 2014 Pivotal
Software, Inc. All rights reserved. How (Theory) Ÿ Unified or parallel pipelines of code and compliance Ÿ Pipeline requirements: – Dependency injection – Task reuse – Multiple inputs, multiple outputs Ÿ Common schema, common components Ÿ Separation of components from system details
6.
6© 2014 Pivotal
Software, Inc. All rights reserved. How (Practice): http://open-control.org Ÿ Schema (YAML) Ÿ Tools (CLI and web) Ÿ Pipelines (Concourse.ci) Ÿ Common compliance packages (800-53, FedRAMP, etc)
7.
7© 2014 Pivotal
Software, Inc. All rights reserved. 7© 2014 Pivotal Software, Inc. All rights reserved. YAML!!!!!
8.
9.
9© 2014 Pivotal
Software, Inc. All rights reserved. How (Practice) Ÿ Inputs: – Certifications – Standards – Component Controls – System Details Ÿ Outputs: – BoE / SPP (as a .docx) – Inventory reports (in .xsl) – POAM details – OpenSCAP config
10.
10© 2014 Pivotal
Software, Inc. All rights reserved. Community
11.
11© 2014 Pivotal
Software, Inc. All rights reserved.
12.
12© 2014 Pivotal
Software, Inc. All rights reserved. Schemas
13.
13© 2014 Pivotal
Software, Inc. All rights reserved.
14.
15.
15© 2014 Pivotal
Software, Inc. All rights reserved.
16.
16© 2014 Pivotal
Software, Inc. All rights reserved. 16© Copyright 2014 Pivotal. All rights reserved. "Culture does not change because we desire to change it. Culture changes when the organization is transformed; the culture reflects the realities of people working together every day.” - Frances Hesselbein
Download now