Let's build with DevSecOps
Culture
By : Vishwas Narayan
DevSecOps
Institution
What will DevSecOps Look like
If DevOps Existed
If DevOps did not Existed
Program manager to
Developer
General DevSecOps Architecture - 3 lines Model
Guide pratique _
Audit interne et 2ème
ligne de maîtrise.pdf
(theiia.org)
General DevSecOps Architecture - 3 lines Model
DoD Enterprise
DevSecOps Reference
Design v1.0_Public
Release.pdf
(defense.gov)
DEV OPS
Change
Stabilit
y
Conway’s Law
“Any organization that designs a system (defined more
broadly here than just information systems) will
inevitably produce a design whose structure is a copy of
the organization's communication structure”
Minimal Viable Security
● How do you prove that we are safe?
● How do we demonstrate that we are secure?
● How are we Rollbacking for Chaos?Is it a right or a wrong Strategy
Security Transition is Crazy
Change the Right way don't mess it up - make it the ultimate objective and rule the
Ops and let the Dev’s also make some decision.
Take Risk by
● Change Management
● Continuous Verification
● Make a major mechanical shift
Guidance on Cloud Security Assessment and Authorization (ITSP.50.105) - Canadian Centre for Cyber Security
Have some Defensive Strategy
Detect and Respond
Build a Architecture for the Trust
● Perimeter Based Trust for the Architecture
● Zero Trust Architecture
● Distributed Trust for the System Design
Make a Impact now just be novel for this Era
● Data Mesh for the less Critical Data
● DevOps Automated Governance
● Distributed Trust model,Identity and Secrets
● Make Sure You have high Trust Audits
DevOps Automated Architecture
Dependency
Management
Artifactory
Repository
So now we have the Modern Solution for the World
● NIST 800-207
● SPIFEE
● SigStore
● CNSF
● ISO
● CFA
● And so on
Zero Trust Architecture (nist.gov)
Reason I and you Exist today is Because old folks also
Did
DevSecOps

Lets build with DevSecOps Culture.pdf