SecOps
Bringing agility into security
ANDREW WURSTER | SECINT TEAM LEAD | @YOURCISCOKID
Meet Atlassian’s Security Team
BUILD TRUST WITH
EVERY TEAM.
Security Intelligence
Incident detection, response
Who is the Atlassian Security Team?
Policies and Trust
Trust @ Atlassian
Security Engineering
Secure by design
How we work
Prepare Detect,
Analyze
Contain,
Eradicate,
Recover
Post-Incident
Review
Primer: Incident Handling Process
Phase 0: Prepare
Phase 1: Detect and Analyze
THE BACKSTORY
Apache Struts
Framework
Remote Code
Execution
Multiple
Products,
Services
Alerts
Logs / Alerts JIRA / Service DeskEmail Ingestion User ReportsIndustry Groups
Investigations
Incidents
INCIDENT TIMELINE
Apache
contacts us
06 Mar
Reported to
Apache
02 Mar ??
Vuln.
Published
0 Day
Investigations
kick off
Incident Raised
Incident —>
07 Mar
Investigation —>
09 Mar09 Mar
Incidents
Phase 2:

Contain, Eradicate, Recover
CROSSING THE STREAMS
Investigating the
exploit
Building and
deploying the fix
Forming and
sending comms
INCIDENT TIMELINE
Incident ActivitiesHipChat Fix
Customer Comms
Incident —>
Investigate Access
13 Mar09 Mar
Review —>
Crowd Fix
Bamboo Fix
Push fix to Bamboo Cloud
Validate Fix Revalidate Fix
Check Access
10 Mar
Vulnerability Annouce
CommsComms Draft
Recovery
Phase 3: Review
INCIDENT TIMELINE
Conduct Incident
Review Carry out PIR
actions
Incident —>
05 April
Review —>
10 Mar 30 Mar13 Mar
Open PIR for
comment
Close PIR
Helping you
Thank you!
ANDREW WURSTER | SECINT TEAM LEAD | @YOURCISCOKID

SecOps - Bringing Agility into Security