SlideShare a Scribd company logo
1 of 25
Preventing
Devoops with
DevSecOps
Kieran Jacobsen
Technical Lead – Infrastructure & Security
Page / Copyright ©2017 by Readify Limited2
2016 was a big year…
Page / Copyright ©2017 by Readify Limited3
2017 is getting of to a bad start…
Page / Copyright ©2017 by Readify Limited4
Before DevOps
Page / Copyright ©2017 by Readify Limited5
DevOps
Page / Copyright ©2017 by Readify Limited6
But Where Is Security?
Page / Copyright ©2017 by Readify Limited7
DevSecOps
› Clear Communication Pathways
› Streamlined Communication
› Security As Code
› Training
› Integrate security into DevOps cycle
Page / Copyright ©2017 by Readify Limited9
Communication Pathways
Development Operations
Security
Page / Copyright ©2017 by Readify Limited10
Streamlined Communication
NO:
› Excel checklists
› Word document reports
› Email Attachments
Page / Copyright ©2017 by Readify Limited11
Streamlined Communication
YES:
› Backlogs/boards
Page / Copyright ©2017 by Readify Limited12
Streamlined Communication
YES:
› Backlogs/boards
› Support ticketing
Page / Copyright ©2017 by Readify Limited13
Streamlined Communication
YES:
› Backlogs/boards
› Support ticketing
› Markup and Git
Page / Copyright ©2017 by Readify Limited14
Security As Code
› Application Source Code
› Azure ARM and AWS Cloud Formation
› Server Configuration – Chef, Puppet, DSC
Page / Copyright ©2017 by Readify Limited15
ARM Templates
Page / Copyright ©2017 by Readify Limited16
PowerShell DSC
Page / Copyright ©2017 by Readify Limited17
Training
› We can’t be experts in Dev, Sec and Ops
› We need cross pollination of skills
› Starts at day 0
› Hands on training for senior developers
Page / Copyright ©2017 by Readify Limited18
Training: Phishing
Employee Breakdown
Technical Non-Technical
Click Break Down
Technical Victims Non-Technical Victims Passed
Page / Copyright ©2017 by Readify Limited19
Integrating Security
Page / Copyright ©2017 by Readify Limited20
Plan
› Integrate security into sprint planning and
reviews
› Consider security user stories early
Page / Copyright ©2017 by Readify Limited21
Code
› Training!
› Test driven development
› Use of the correct tools
› Pull Requests
Page / Copyright ©2017 by Readify Limited22
Build
› Static code analysis
› Dynamic code analysis
Page / Copyright ©2017 by Readify Limited23
Test
› Develop security test cases
› Fuzzing
› Load testing
Page / Copyright ©2017 by Readify Limited24
Release & Deploy
› Automated scanning upon deployment
Page / Copyright ©2017 by Readify Limited25
Operate & Monitor
› Monitor logs
› Rescan for vulnerabilities
› Track dependencies
Thank You

More Related Content

What's hot

A journey from dev ops to devsecops
A journey from dev ops to devsecopsA journey from dev ops to devsecops
A journey from dev ops to devsecopsVeritis Group, Inc
 
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019 Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019 Amazon Web Services
 
Application Security in a DevOps World
Application Security in a DevOps WorldApplication Security in a DevOps World
Application Security in a DevOps WorldCA Technologies
 
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps WhiteSource
 
Security at the Speed of Software - Twistlock
Security at the Speed of Software - TwistlockSecurity at the Speed of Software - Twistlock
Security at the Speed of Software - TwistlockAmazon Web Services
 
New security solutions for next generation of IT
New security solutions for next generation of ITNew security solutions for next generation of IT
New security solutions for next generation of ITDATA SECURITY SOLUTIONS
 
DevSecOps without DevOps is Just Security
DevSecOps without DevOps is Just SecurityDevSecOps without DevOps is Just Security
DevSecOps without DevOps is Just SecurityKevin Fealey
 
Secure your Application with Google cloud armor
Secure your Application with Google cloud armorSecure your Application with Google cloud armor
Secure your Application with Google cloud armorDevOps Indonesia
 
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...Lacework
 
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...SBA Research
 
Securing Container-Based Applications at the Speed of DevOps
Securing Container-Based Applications at the Speed of DevOpsSecuring Container-Based Applications at the Speed of DevOps
Securing Container-Based Applications at the Speed of DevOpsWhiteSource
 
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIERO
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIEROSécurité by design + Cloud = Infrastructure as Code par Sergio LOURIERO
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIEROTelecomValley
 
DevSecOps Everything You Need To Know
DevSecOps Everything You Need To KnowDevSecOps Everything You Need To Know
DevSecOps Everything You Need To KnowCentextech
 
DevSecOps Days SF at RSA Conference 2018
DevSecOps Days SF at RSA Conference 2018DevSecOps Days SF at RSA Conference 2018
DevSecOps Days SF at RSA Conference 2018DevSecOps Days
 
Your Resolution for 2018: Five Principles For Securing DevOps
Your Resolution for 2018: Five Principles For Securing DevOpsYour Resolution for 2018: Five Principles For Securing DevOps
Your Resolution for 2018: Five Principles For Securing DevOpsDevOps.com
 
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...DevSecCon
 
BitSensor Webwinkel Vakdagen
BitSensor Webwinkel VakdagenBitSensor Webwinkel Vakdagen
BitSensor Webwinkel Vakdagenwebwinkelvakdag
 
Bio IT World 2015 - DevOps Security and Transparency
Bio IT World 2015 - DevOps Security and TransparencyBio IT World 2015 - DevOps Security and Transparency
Bio IT World 2015 - DevOps Security and TransparencyKevin Gilpin
 
Lacework Overview: Security Redefined for Cloud Scale
Lacework Overview: Security Redefined for Cloud ScaleLacework Overview: Security Redefined for Cloud Scale
Lacework Overview: Security Redefined for Cloud ScaleLacework
 

What's hot (20)

A journey from dev ops to devsecops
A journey from dev ops to devsecopsA journey from dev ops to devsecops
A journey from dev ops to devsecops
 
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019 Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019
Modernizing Traditional Security - DEM13 - AWS re:Inforce 2019
 
Application Security in a DevOps World
Application Security in a DevOps WorldApplication Security in a DevOps World
Application Security in a DevOps World
 
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
From Zero to DevSecOps: How to Implement Security at the Speed of DevOps
 
Security at the Speed of Software - Twistlock
Security at the Speed of Software - TwistlockSecurity at the Speed of Software - Twistlock
Security at the Speed of Software - Twistlock
 
New security solutions for next generation of IT
New security solutions for next generation of ITNew security solutions for next generation of IT
New security solutions for next generation of IT
 
DevSecOps without DevOps is Just Security
DevSecOps without DevOps is Just SecurityDevSecOps without DevOps is Just Security
DevSecOps without DevOps is Just Security
 
Secure your Application with Google cloud armor
Secure your Application with Google cloud armorSecure your Application with Google cloud armor
Secure your Application with Google cloud armor
 
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...
AWS Security Week | Getting to Continuous Security and Compliance Monitoring ...
 
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
 
Securing Container-Based Applications at the Speed of DevOps
Securing Container-Based Applications at the Speed of DevOpsSecuring Container-Based Applications at the Speed of DevOps
Securing Container-Based Applications at the Speed of DevOps
 
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIERO
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIEROSécurité by design + Cloud = Infrastructure as Code par Sergio LOURIERO
Sécurité by design + Cloud = Infrastructure as Code par Sergio LOURIERO
 
DevSecOps outline
DevSecOps outlineDevSecOps outline
DevSecOps outline
 
DevSecOps Everything You Need To Know
DevSecOps Everything You Need To KnowDevSecOps Everything You Need To Know
DevSecOps Everything You Need To Know
 
DevSecOps Days SF at RSA Conference 2018
DevSecOps Days SF at RSA Conference 2018DevSecOps Days SF at RSA Conference 2018
DevSecOps Days SF at RSA Conference 2018
 
Your Resolution for 2018: Five Principles For Securing DevOps
Your Resolution for 2018: Five Principles For Securing DevOpsYour Resolution for 2018: Five Principles For Securing DevOps
Your Resolution for 2018: Five Principles For Securing DevOps
 
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...
DevSecCon Asia 2017 Joel Divekar: Using Open Source Automation tools for DevS...
 
BitSensor Webwinkel Vakdagen
BitSensor Webwinkel VakdagenBitSensor Webwinkel Vakdagen
BitSensor Webwinkel Vakdagen
 
Bio IT World 2015 - DevOps Security and Transparency
Bio IT World 2015 - DevOps Security and TransparencyBio IT World 2015 - DevOps Security and Transparency
Bio IT World 2015 - DevOps Security and Transparency
 
Lacework Overview: Security Redefined for Cloud Scale
Lacework Overview: Security Redefined for Cloud ScaleLacework Overview: Security Redefined for Cloud Scale
Lacework Overview: Security Redefined for Cloud Scale
 

Viewers also liked

Lineamientos estratégicos para la comunicación global efectiva de mi marca
Lineamientos estratégicos para la comunicación global efectiva de mi marcaLineamientos estratégicos para la comunicación global efectiva de mi marca
Lineamientos estratégicos para la comunicación global efectiva de mi marcaAlbelidys
 
Resolución rectoral nº 001 2017
Resolución rectoral nº 001 2017Resolución rectoral nº 001 2017
Resolución rectoral nº 001 2017deiberrector
 
Tokyo mou deficiency codes (june 2014)
Tokyo mou deficiency codes (june 2014)Tokyo mou deficiency codes (june 2014)
Tokyo mou deficiency codes (june 2014)GOLDENDRAGON511
 
3Com 10000563
3Com 100005633Com 10000563
3Com 10000563savomir
 
Problema gestion del capital humano y evaluacion del desempeño laboral
Problema gestion del capital humano y evaluacion del desempeño laboralProblema gestion del capital humano y evaluacion del desempeño laboral
Problema gestion del capital humano y evaluacion del desempeño laboralalixindriago2013
 
Evaluación del estado de nutrición
Evaluación del estado de nutriciónEvaluación del estado de nutrición
Evaluación del estado de nutriciónFatimaBriseidaCG
 
Evolving your automation with hybrid workers
Evolving your automation with hybrid workersEvolving your automation with hybrid workers
Evolving your automation with hybrid workerskieranjacobsen
 
Fun with the Hak5 Rubber Ducky
Fun with the Hak5 Rubber DuckyFun with the Hak5 Rubber Ducky
Fun with the Hak5 Rubber Duckykieranjacobsen
 
Exploiting MS15-034 In PowerShell
Exploiting MS15-034 In PowerShellExploiting MS15-034 In PowerShell
Exploiting MS15-034 In PowerShellkieranjacobsen
 
Enabling Enterprise Mobility
Enabling Enterprise MobilityEnabling Enterprise Mobility
Enabling Enterprise Mobilitykieranjacobsen
 
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data Centre
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data CentreGlobal Azure Bootcamp 2016 - Azure Automation Invades Your Data Centre
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data Centrekieranjacobsen
 
Sentuhan suami untuk mengurangi rasa nyeri persalinan
Sentuhan suami untuk mengurangi rasa nyeri persalinanSentuhan suami untuk mengurangi rasa nyeri persalinan
Sentuhan suami untuk mengurangi rasa nyeri persalinanAsih Astuti
 
DirectAccess, do’s and don’ts
DirectAccess, do’s and don’tsDirectAccess, do’s and don’ts
DirectAccess, do’s and don’tskieranjacobsen
 
Infrastructure Saturday 2011 - Understanding PKI and Certificate Services
Infrastructure Saturday 2011 - Understanding PKI and Certificate ServicesInfrastructure Saturday 2011 - Understanding PKI and Certificate Services
Infrastructure Saturday 2011 - Understanding PKI and Certificate Serviceskieranjacobsen
 
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบก
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบกLoadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบก
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบกnawaporn khamseanwong
 
Azure automation invades your data centre
Azure automation invades your data centreAzure automation invades your data centre
Azure automation invades your data centrekieranjacobsen
 

Viewers also liked (19)

Lineamientos estratégicos para la comunicación global efectiva de mi marca
Lineamientos estratégicos para la comunicación global efectiva de mi marcaLineamientos estratégicos para la comunicación global efectiva de mi marca
Lineamientos estratégicos para la comunicación global efectiva de mi marca
 
Resolución rectoral nº 001 2017
Resolución rectoral nº 001 2017Resolución rectoral nº 001 2017
Resolución rectoral nº 001 2017
 
7 filtros
7 filtros7 filtros
7 filtros
 
Tokyo mou deficiency codes (june 2014)
Tokyo mou deficiency codes (june 2014)Tokyo mou deficiency codes (june 2014)
Tokyo mou deficiency codes (june 2014)
 
Full+toefl grammar
Full+toefl grammarFull+toefl grammar
Full+toefl grammar
 
Problemas 3 fff
Problemas 3 fffProblemas 3 fff
Problemas 3 fff
 
3Com 10000563
3Com 100005633Com 10000563
3Com 10000563
 
Problema gestion del capital humano y evaluacion del desempeño laboral
Problema gestion del capital humano y evaluacion del desempeño laboralProblema gestion del capital humano y evaluacion del desempeño laboral
Problema gestion del capital humano y evaluacion del desempeño laboral
 
Evaluación del estado de nutrición
Evaluación del estado de nutriciónEvaluación del estado de nutrición
Evaluación del estado de nutrición
 
Evolving your automation with hybrid workers
Evolving your automation with hybrid workersEvolving your automation with hybrid workers
Evolving your automation with hybrid workers
 
Fun with the Hak5 Rubber Ducky
Fun with the Hak5 Rubber DuckyFun with the Hak5 Rubber Ducky
Fun with the Hak5 Rubber Ducky
 
Exploiting MS15-034 In PowerShell
Exploiting MS15-034 In PowerShellExploiting MS15-034 In PowerShell
Exploiting MS15-034 In PowerShell
 
Enabling Enterprise Mobility
Enabling Enterprise MobilityEnabling Enterprise Mobility
Enabling Enterprise Mobility
 
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data Centre
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data CentreGlobal Azure Bootcamp 2016 - Azure Automation Invades Your Data Centre
Global Azure Bootcamp 2016 - Azure Automation Invades Your Data Centre
 
Sentuhan suami untuk mengurangi rasa nyeri persalinan
Sentuhan suami untuk mengurangi rasa nyeri persalinanSentuhan suami untuk mengurangi rasa nyeri persalinan
Sentuhan suami untuk mengurangi rasa nyeri persalinan
 
DirectAccess, do’s and don’ts
DirectAccess, do’s and don’tsDirectAccess, do’s and don’ts
DirectAccess, do’s and don’ts
 
Infrastructure Saturday 2011 - Understanding PKI and Certificate Services
Infrastructure Saturday 2011 - Understanding PKI and Certificate ServicesInfrastructure Saturday 2011 - Understanding PKI and Certificate Services
Infrastructure Saturday 2011 - Understanding PKI and Certificate Services
 
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบก
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบกLoadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบก
Loadแนวข้อสอบ ลูกมือช่าง กรมสรรพาวุธทหารบก
 
Azure automation invades your data centre
Azure automation invades your data centreAzure automation invades your data centre
Azure automation invades your data centre
 

Similar to Prevent Devoops with DevSecOps Approach

Tales from an Enterprise DevOps transformation
Tales from an Enterprise DevOps transformationTales from an Enterprise DevOps transformation
Tales from an Enterprise DevOps transformationLee Eason
 
Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps ProgramTake Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps ProgramDeborah Schalm
 
Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps Program Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps Program DevOps.com
 
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...Dárcio Takara
 
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...Synopsys Software Integrity Group
 
DevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDiego Gabriel Cardoso
 
DevSecOps - Colocando segurança na esteira
DevSecOps - Colocando segurança na esteiraDevSecOps - Colocando segurança na esteira
DevSecOps - Colocando segurança na esteiraDiego Gabriel Cardoso
 
22by7 campus presentation v1.05
22by7 campus presentation v1.0522by7 campus presentation v1.05
22by7 campus presentation v1.05Sashikris
 
How to get the best out of DevSecOps - an operations perspective
How to get the best out of DevSecOps - an operations perspectiveHow to get the best out of DevSecOps - an operations perspective
How to get the best out of DevSecOps - an operations perspectiveColin Domoney
 
Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!Jason Jolley
 
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...Eric Vanderburg
 
How to (Permanently) Fix the Most Common DevOps Security Blunders
How to (Permanently) Fix the Most Common DevOps Security BlundersHow to (Permanently) Fix the Most Common DevOps Security Blunders
How to (Permanently) Fix the Most Common DevOps Security BlundersDevOps.com
 
DevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDiego Gabriel Cardoso
 
Red7 SSDLC Introduction: Building Secure Web and Mobile Applications
Red7 SSDLC Introduction: Building Secure Web and Mobile ApplicationsRed7 SSDLC Introduction: Building Secure Web and Mobile Applications
Red7 SSDLC Introduction: Building Secure Web and Mobile ApplicationsRobert Grupe, CSSLP CISSP PE PMP
 
Welcome to the Metrics
Welcome to the MetricsWelcome to the Metrics
Welcome to the MetricsVMware Tanzu
 
Synopsys_site.pptx
Synopsys_site.pptxSynopsys_site.pptx
Synopsys_site.pptxArthur528009
 

Similar to Prevent Devoops with DevSecOps Approach (20)

Tales from an Enterprise DevOps transformation
Tales from an Enterprise DevOps transformationTales from an Enterprise DevOps transformation
Tales from an Enterprise DevOps transformation
 
Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps ProgramTake Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps Program
 
Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps Program Take Control: Design a Complete DevSecOps Program
Take Control: Design a Complete DevSecOps Program
 
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
SecDevOps: afaste-se dos ciberataques sem complicar o dia a dia dos desenvolv...
 
Speed and security for your PHP application
Speed and security for your PHP applicationSpeed and security for your PHP application
Speed and security for your PHP application
 
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...
Synopsys Security Event Israel Presentation: Keynote: Securing Your Software,...
 
DevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteira
 
Webinar–Best Practices for DevSecOps at Scale
Webinar–Best Practices for DevSecOps at ScaleWebinar–Best Practices for DevSecOps at Scale
Webinar–Best Practices for DevSecOps at Scale
 
DevSecOps - Colocando segurança na esteira
DevSecOps - Colocando segurança na esteiraDevSecOps - Colocando segurança na esteira
DevSecOps - Colocando segurança na esteira
 
Securing Your Cloud With Check Point's vSEC
Securing Your Cloud With Check Point's vSECSecuring Your Cloud With Check Point's vSEC
Securing Your Cloud With Check Point's vSEC
 
22by7 campus presentation v1.05
22by7 campus presentation v1.0522by7 campus presentation v1.05
22by7 campus presentation v1.05
 
How to get the best out of DevSecOps - an operations perspective
How to get the best out of DevSecOps - an operations perspectiveHow to get the best out of DevSecOps - an operations perspective
How to get the best out of DevSecOps - an operations perspective
 
Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!Alfresco Virtual DevCon 2020 - Security First!
Alfresco Virtual DevCon 2020 - Security First!
 
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...
Cybersecurity Incident Response Strategies and Tactics - RIMS 2017 - Eric Van...
 
How to (Permanently) Fix the Most Common DevOps Security Blunders
How to (Permanently) Fix the Most Common DevOps Security BlundersHow to (Permanently) Fix the Most Common DevOps Security Blunders
How to (Permanently) Fix the Most Common DevOps Security Blunders
 
DevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteiraDevSecOps: Colocando segurança na esteira
DevSecOps: Colocando segurança na esteira
 
Red7 SSDLC Introduction: Building Secure Web and Mobile Applications
Red7 SSDLC Introduction: Building Secure Web and Mobile ApplicationsRed7 SSDLC Introduction: Building Secure Web and Mobile Applications
Red7 SSDLC Introduction: Building Secure Web and Mobile Applications
 
Welcome to the Metrics
Welcome to the MetricsWelcome to the Metrics
Welcome to the Metrics
 
Webinar–That is Not How This Works
Webinar–That is Not How This WorksWebinar–That is Not How This Works
Webinar–That is Not How This Works
 
Synopsys_site.pptx
Synopsys_site.pptxSynopsys_site.pptx
Synopsys_site.pptx
 

More from kieranjacobsen

The Boring Security Talk - Azure Global Bootcamp Melbourne 2019
The Boring Security Talk - Azure Global Bootcamp Melbourne 2019The Boring Security Talk - Azure Global Bootcamp Melbourne 2019
The Boring Security Talk - Azure Global Bootcamp Melbourne 2019kieranjacobsen
 
CrikeyCon VI - The Boring Security Talk
CrikeyCon VI - The Boring Security TalkCrikeyCon VI - The Boring Security Talk
CrikeyCon VI - The Boring Security Talkkieranjacobsen
 
The Boring Security Talk
The Boring Security TalkThe Boring Security Talk
The Boring Security Talkkieranjacobsen
 
The Boring Security Talk
The Boring Security TalkThe Boring Security Talk
The Boring Security Talkkieranjacobsen
 
Secure Azure Deployment Patterns
Secure Azure Deployment PatternsSecure Azure Deployment Patterns
Secure Azure Deployment Patternskieranjacobsen
 
Ransomware 0, Admins 1
Ransomware 0, Admins 1Ransomware 0, Admins 1
Ransomware 0, Admins 1kieranjacobsen
 
DecSecOps in 10 minutes
DecSecOps in 10 minutesDecSecOps in 10 minutes
DecSecOps in 10 minuteskieranjacobsen
 
Lateral Movement with PowerShell
Lateral Movement with PowerShellLateral Movement with PowerShell
Lateral Movement with PowerShellkieranjacobsen
 
Lateral Movement with PowerShell
Lateral Movement with PowerShellLateral Movement with PowerShell
Lateral Movement with PowerShellkieranjacobsen
 
Advanced PowerShell Automation
Advanced PowerShell AutomationAdvanced PowerShell Automation
Advanced PowerShell Automationkieranjacobsen
 

More from kieranjacobsen (11)

The Boring Security Talk - Azure Global Bootcamp Melbourne 2019
The Boring Security Talk - Azure Global Bootcamp Melbourne 2019The Boring Security Talk - Azure Global Bootcamp Melbourne 2019
The Boring Security Talk - Azure Global Bootcamp Melbourne 2019
 
CrikeyCon VI - The Boring Security Talk
CrikeyCon VI - The Boring Security TalkCrikeyCon VI - The Boring Security Talk
CrikeyCon VI - The Boring Security Talk
 
The Boring Security Talk
The Boring Security TalkThe Boring Security Talk
The Boring Security Talk
 
The Boring Security Talk
The Boring Security TalkThe Boring Security Talk
The Boring Security Talk
 
Secure Azure Deployment Patterns
Secure Azure Deployment PatternsSecure Azure Deployment Patterns
Secure Azure Deployment Patterns
 
Ransomware 0, Admins 1
Ransomware 0, Admins 1Ransomware 0, Admins 1
Ransomware 0, Admins 1
 
Ransomware 0 admins 1
Ransomware 0 admins 1Ransomware 0 admins 1
Ransomware 0 admins 1
 
DecSecOps in 10 minutes
DecSecOps in 10 minutesDecSecOps in 10 minutes
DecSecOps in 10 minutes
 
Lateral Movement with PowerShell
Lateral Movement with PowerShellLateral Movement with PowerShell
Lateral Movement with PowerShell
 
Lateral Movement with PowerShell
Lateral Movement with PowerShellLateral Movement with PowerShell
Lateral Movement with PowerShell
 
Advanced PowerShell Automation
Advanced PowerShell AutomationAdvanced PowerShell Automation
Advanced PowerShell Automation
 

Recently uploaded

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsHyundai Motor Group
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?XfilesPro
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAndikSusilo4
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetEnjoy Anytime
 

Recently uploaded (20)

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter RoadsSnow Chain-Integrated Tire for a Safe Drive on Winter Roads
Snow Chain-Integrated Tire for a Safe Drive on Winter Roads
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
Azure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & ApplicationAzure Monitor & Application Insight to monitor Infrastructure & Application
Azure Monitor & Application Insight to monitor Infrastructure & Application
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
 

Prevent Devoops with DevSecOps Approach

  • 2. Page / Copyright ©2017 by Readify Limited2 2016 was a big year…
  • 3. Page / Copyright ©2017 by Readify Limited3 2017 is getting of to a bad start…
  • 4. Page / Copyright ©2017 by Readify Limited4 Before DevOps
  • 5. Page / Copyright ©2017 by Readify Limited5 DevOps
  • 6. Page / Copyright ©2017 by Readify Limited6 But Where Is Security?
  • 7. Page / Copyright ©2017 by Readify Limited7 DevSecOps › Clear Communication Pathways › Streamlined Communication › Security As Code › Training › Integrate security into DevOps cycle
  • 8. Page / Copyright ©2017 by Readify Limited9 Communication Pathways Development Operations Security
  • 9. Page / Copyright ©2017 by Readify Limited10 Streamlined Communication NO: › Excel checklists › Word document reports › Email Attachments
  • 10. Page / Copyright ©2017 by Readify Limited11 Streamlined Communication YES: › Backlogs/boards
  • 11. Page / Copyright ©2017 by Readify Limited12 Streamlined Communication YES: › Backlogs/boards › Support ticketing
  • 12. Page / Copyright ©2017 by Readify Limited13 Streamlined Communication YES: › Backlogs/boards › Support ticketing › Markup and Git
  • 13. Page / Copyright ©2017 by Readify Limited14 Security As Code › Application Source Code › Azure ARM and AWS Cloud Formation › Server Configuration – Chef, Puppet, DSC
  • 14. Page / Copyright ©2017 by Readify Limited15 ARM Templates
  • 15. Page / Copyright ©2017 by Readify Limited16 PowerShell DSC
  • 16. Page / Copyright ©2017 by Readify Limited17 Training › We can’t be experts in Dev, Sec and Ops › We need cross pollination of skills › Starts at day 0 › Hands on training for senior developers
  • 17. Page / Copyright ©2017 by Readify Limited18 Training: Phishing Employee Breakdown Technical Non-Technical Click Break Down Technical Victims Non-Technical Victims Passed
  • 18. Page / Copyright ©2017 by Readify Limited19 Integrating Security
  • 19. Page / Copyright ©2017 by Readify Limited20 Plan › Integrate security into sprint planning and reviews › Consider security user stories early
  • 20. Page / Copyright ©2017 by Readify Limited21 Code › Training! › Test driven development › Use of the correct tools › Pull Requests
  • 21. Page / Copyright ©2017 by Readify Limited22 Build › Static code analysis › Dynamic code analysis
  • 22. Page / Copyright ©2017 by Readify Limited23 Test › Develop security test cases › Fuzzing › Load testing
  • 23. Page / Copyright ©2017 by Readify Limited24 Release & Deploy › Automated scanning upon deployment
  • 24. Page / Copyright ©2017 by Readify Limited25 Operate & Monitor › Monitor logs › Rescan for vulnerabilities › Track dependencies

Editor's Notes

  1. Good morning everyone, and welcome to the Readify Dev Breakfast. My name is Kieran Jacobsen, I am the Technical Lead for Infrastructure and Security within Readify’s Managed Services team. My responsibility is to manage and maintain Readify’s internal systems and infrastructure. I spent a lot of time working with developers, and customer operational and security teams to achieve positive outcomes. I have a fairly unique understanding of the pressures and unique challenges for each group. I have seen strategies that have worked, and quite a few that have failed.
  2. By all accounts, 2016 was a massive year for information security. We saw a significant number of breach disclosures, breaking records in terms of the number and size of the breaches. We saw a number of older breaches appear for the first time, like those impacting LinkedIn, Myspace and Yahoo. We saw the mirai IOT bot net appear, hit Brian Krebs with a record breaking denial of service attack, then target DynDNS and knocking off Spotify, twitter, GitHub PayPal and more. We also saw a number of breaches where database backups made public, including one impacting the Australian Red Cross.
  3. Yet 2017, politics aside, seems to be gearing up to be even worse. Attackers have laid waste to poorly secured Hadoop, MongoDB, ElasticSearch and CouchDB instances; deleting data and leaving ransom notes. We also saw a suspected DDOS take down Lloyds bank for 2 days. Recently, a 13 year old worm made a reappearance, That’s right, SQL Slammer is back!
  4. Here we see a representation of development and operations before the introduction of DevOps. Development would catapult new builds at operations, and they would return with a volley of bugs and issues. Our applications were unstable, deployments were a complex mess and overall our organisations suffered.
  5. Along came DevOps, with a promise that we would get two waring factions to act as one. DevOps has largely been a success, applications have become more stable, we now have a faster release cycle, with fixes deployed to production often at an hourly basis. Development and Operations is now moving at a speed to which the rest of the business was wanting. Gartner predicted that 2016 was the year DevOps goes mainstream, with 25% of the businesses using DevOps by 2017. HP Enterprise, my old employer went so firmly as to say that within 5 years DevOps will be the norm when it comes to software development.
  6. With everything, we somehow left our security. Organisations rushed to embrace DevOps, often at times forgetting to bring their security teams along. This has lead to a variety of issues, including those we saw earlier. In someway, It feels like we are back in the late 90s or early 2000s. If 2016 is the year that DevOps goes mainstream, then 2017 will surely be the year that attacks against DevOps becomes the norm.
  7. So how do we move to DevSecOps? Well, we start by creating clear communication pathways between the groups, and using streamlined communication techniques. We need to consider security as code, training and obviously, integrate security controls into our DevOps cycle.
  8. This quote, from Queensland Microsoft MVP, Jess Dodson, succinctly sums up some of the issues in the relationship between the three groups. It is such a great quote. We are all in customer service, our users are our customers; I want to extend upon this and say that within the IT industry, we are each others customers. We need to understand them and their needs to do our job well; and this goes for the relationships between Dev, Sec and Ops as well. We both the customer and the service providers within our organisation.
  9. So here are the three groups. <click> With DevOps we recognise that dev and ops are customers of each other. Dev cannot create without the assistance of Ops, and conversely ops needs stable high quality code from the dev teams to ensure that everything runs smoothly. What about Security? <click> Well obviously, Security is a client of dev and ops. Security needs both groups to fix identified security issues, if it security has any chance of ensuring that the organisation is safe. <click> The often forgotten relationship. Dev and Ops are customers of security. These two groups are not security experts, they need guidance, assistance and support from security specialist to ensure that they are developing secure applications and deploying secure infrastructure. For these relationships to succeed, we need to ensure that there is clear communication. How do we support these relationships?
  10. Now I hope that by now, everyone is aware of the risks of using excel and word documents containing macros, and you should have them blocked within your organisation. Unfortunately many security activities still occur via excel checklists and word documents sent via email. Excel is clunky, it is slow and difficult to process, I recently completed a review process, all 12 thousand questions in macro enabled excel files, it was slow, and it wasn’t productive. Word documents have their challenges as well, it can be hard to difference them. If I knew I was compliant to version 1.15 of the security policy, and now there is 1.16, how do I know what changed in this word document? And don’t start me on change history entries at the start of documents, do they ever work? Email attachments are great for sharing, but bad for collaboration. You should also be aware of the risks of communicating sensitive security matters using email and email attachments. Now everyone’s security is up to your level. So what should we do?
  11. Backlogs and boards have worked wonders for agile and devops. These tools promote a collaborative effort to complete tasks and fosters ownership. Teams work together to determine the priorities for tasks. Operation and security tasks can exist within backlogs just as development tasks can, I know, because this is how I work.
  12. Don’t forget ticket, support or helpdesk tools, like ZenDesk here. These tools foster team collaboration and encourage communication with customers. These tools allow for incidents and tasks to be passed cleanly between different parts of your organisation, with history maintained as required. You can write automated responses, saving time and allowing issues to be closed faster and with less fuss. Here is a great example, a user calls your helpdesk, they have noticed an issue with an application, it doesn’t seem to be handling the correct input. Helpdesk takes a look, validates the issue and sends it across to the system admin team. The sysadmin team looks, does some more troubleshooting, it now looks like a security issue in the app, so they send the ticket across to security, who review it, confirm the issue and pass it, with additional information on what the cause of the issue is, across to the development team to fix the issue. Once a fix has been developed, it goes back to operations to ensure its deployed smoothly. This is a smooth progression between teams, its clear who has responsibility for the issue, and its clear to the user what is happening.
  13. The last one, is something I myself has only just in the past 6 months come to realise. Documentation needs to be in a format where editing is easy, and for that reason we often fall back to word, excel and onenote, but its then hard to version and track changes. Writing documentation using markup, and using git workflows, helps this. The workflow can be simple, operations teams make changes to say, some security processes. Once they have finished making their changes, they commit them to a branch and create a pull request. Security reviews the changes, approves them and the changes are pushed to the rest of the organisation.
  14. So the next big takeaway is security as code. Or as I like to put it, here is all of the code that could impact your organisations security. So obviously we have application source code, but what about the other parts of your environment? If your developers are using Azure or AWS, they are probably using templates to deploy infrastructure. Care needs to be taken that these templates are created in a way that the infrastructure they deploy is secure. Does operations review these? What about security? Server configuration tools like Chef, Puppet and PowerShell DSC are all the rage, but I often see two major issues. Firstly, have you secured these tools correctly? Secondly, is the configuration these tools are deploying secure?
  15. What we see here, is an except from a template that deploys a virtual machine. This except covers the configuration of a Network Security Group, these are basically a ACL. I took this one from the Azure QuickStart Templates repository. In this example, we can see they locked down traffic to RDP only, but the allowed sources is the Internet. Guess this box will start seeing brute force traffic. Surprisingly, this isn’t the worst that I have seen, its actually pretty good. The majority of templates do not make use of NSGs, this results in an ANY:ANY rule being applied, resulting in all services, from RDP, to SSH,, to SMB to SQL left exposed to all in sundry. Why Microsoft when this way, I cannot explain. What I do know, is that your developers are probably using these templates or basing their own templates from these.
  16. So let’s take a quick look at another example, this type its PowerShell DSC. This example is snipped of a much larger DSC configuration that all of our servers at Readify comply to. This will disable insecure ciphers being used for HTTPS connections. Imagine the effectiveness if you pushed this out to all of your web servers, or better yet, every server in your fleet? You would be close to having a A+ rating for all of your web properties.
  17. Training is so important, and there is a massive return on investment to be gained from training your developers, operations teams and security teams. We cannot be experts at development and security and operations, but I can have an awareness and some working knowledge of the other areas. For instance, the developer who understands application vulnerability testing, the operations team member that knows some IOS development, or the security engineer that knows how to deploy cloud infrastructure. For developers, security awareness begins at day zero. When a new developer starts, they need more than the simple password and shoulder surfing but they need specialist training as well. You need to ensure that developers know what the quality expectations for code they write is, the basics of secure coding and the most common exploit vendors. Do not assume they come with this knowledge. Senior developers should go on training courses that cover secure code practices and common mistakes. This training needs to be hands on. Training like this encourages ownership of security by senior developers, and this is critically important. Senior developers are mentors for junior developers, they sent the tone of the team and the projects, and importantly they lead code review processes. Training isn’t a once off thing, it’s a multiple times per year thing. Training is not just a PowerPoint slide, nor is it the same video each year. Training needs to be reviewed regularly to ensure it covers the latest technology and the changes in the security landscape.
  18. At Readify, we identified that phishing was a critical risk to an organisation. Technology can only solve so much, there isn’t a silver bullet. So we opted to organise some training. We selected an external vendor that had a three step process. The first is a baseline, every use gets an email, the same email, throughout a month long period. After baseline comes training, and then once training is complete, there is a period of continual training. During this final phase, staff get one phishing email each month to test them and to help hone their skills. Before we look at the results, lets look at the break down of staff at Readify. <click> As you can see, the majority, around 80%, of our employees are technical, be it developers, database people, business intelligence, SharePoint, or infrastructure people like me. My expectation was that the majority of those who fell for the baseline email, would be non-technical, I know, I am biased. <click> As you can see, the results are a tad more interesting. Overall, we had 26% of our staff click on the baseline email, surprisingly, only a small fraction of those, 2 people, were non-technical. Since the training, our click rate is down to about 2% each month. Moral of the story, don’t always expect your non-technical staff to be the source of your security issues.
  19. So back to the infinity of DevOps. Where do we integrate security? The answer simply is, at every step. We need to consider security at every point, and security gates should exist between each step. They say security is as strong as the weakest link in the chain, well, this is your new chain, make it as you wish.
  20. Security planning is critical, we need to involve security personnel and teams in sprint planning and reviews. Consider security stories early in projects, they can be complex and should not be rushed.
  21. Training is what impacts our coding phase the post, but don’t forget to consider methodologies like test driven development. Creating unit tests that verify security aspects is highly affective at finding bugs early. Think about tooling, most new IDEs contain tools and plugins that can assist developers and alert them for particular code quality issues. Invest in the right tooling. Finally, establish code views via pull requests. People should never approve their own requests, no matter the urgency. Those performing reviews need the adequate training, they need to know and understand attack vectors in code and common security issues. Any piece of code, that contains issues, be they security, stability or quality issues, shouldn’t be approved.
  22. During the build processes, static and dynamic code analysis tools can assist in finding security issues before the reach production. We can use static analysis before build, or dynamic after build. Now I am not going to enter the which one is better argument, its been going on for a while in the security industry. When it comes to these tools, you need to ensure that you have tuned them correctly. Issues raised need to be feed back into the development teams and prioritised based upon their risks and any mitigating factors. Just because a tool says an issue is of a high priority, doesn’t take into account any mitigation that may be in place within your application or infrastructure. Now I am going to point out, if these tools detect issues, or a specific number of issues, or issues of specific urgency or criteria, then the build fails, and the code doesn’t proceed any further.
  23. We test to ensure that our code is of the right quality, and that it does what we need it do. Testing comes in all forms. A quick example might be automated interface testing that puts SQLi into user input on a web application and tests for an adequate response. Automated Fuzzing is become quite popular in large enterprises. A number of vendors, including Microsoft are offering cloud based fuzzing platforms. Now I can’t believe in 2017 I still need to talk about this, but people still don’t do load testing. Load testing comes in two forms, the first, validating that an application and its infrastructure can handle the expected load, and the other is to push an them to their breaking point. Both are crucial to security. Just look at the Australian Census, it couldn’t handle the legitimate traffic, let alone attack traffic. If an app fails here, it doesn’t proceed.
  24. There are some unique opportunities in terms of finding potential security vulnerabilities. Typically after an app passes build, and testing, we install it to some sort of pre-production environments. It is here that we have the first clear vision of the application on the full stack, servers, databases, and load balancers. What I recommend, is that here, before proceeding to production, scan using integrated vulnerability tools. You will get a better picture of any infrastructure vulnerabilities here, so make use of the opportunity. You can automatically trigger off this scanning upon successful deployment. Depending upon what is found, you may proceed to production or block and wait for a fix.
  25. Now the final stages operate and monitor are where some of our typical ops team activities come in. Obviously we need to monitor our applications to ensure they are available to users, we need to monitor logs for application exceptions as well. But we can also monitor the logs for security issues, look for malicious activities and suspicious patterns and trends. We should rescan using our vulnerability assessment tools on a regular basis, this is more critical where builds happen less frequently, as we need to ensure that no new vulnerabilities have since been discovered. Tracking dependencies in your infrastructure and your code is also critical, there are a number of platforms that can do this, and alert you to vulnerabilities. Do you know if all of your NPM packages are free of bugs? Track issues and remediate.
  26. I want to thank you all for coming this morning, it has been a pleasure to speak to you. We have time for some questions before breaking up for networking afterwards. Does anyone have any questions?