SlideShare uma empresa Scribd logo
1 de 29
Baixar para ler offline
1
DevOps:
Lead, Follow, Or Get Out of the Way
A CISO Perspective
Presented by:
Tim Virtue
CISO, Texas.gov
The Lawyers Made Me Do It
 Any references to specific organizations, people,
products, or services, are purely examples or learning
opportunities and neither criticisms nor
endorsements
 The views presented are strictly my own and may or
may not represent any organizations or affiliations I
have (mostly because they have not seen the light
yet )
 It’s OK to agree to disagree, but anyone who gets
that worked up over slides needs a vacation
ABC Soup & Street Cred
 CISSP, CCSK, CISA, CIPP/G, CFE, ITIL V3, CVE, QGVM,
blah blah blah…
 Over 15 years experience in Security, Risk
Management and IT
 Executive Master of Science in Information Systems
from a top business school
 Cyber Security Instructor, Author & Speaker
 Not bragging – just showing perspective & credibility
– if DevOps can sell me, you can sell it to the greater
security community and your organization
 Something to be
ignored
 Something Security
should try and stop
 Something done in
isolation
 A system or tool
implementation
What DevOps Is Not
What is DevOps?
 Many things to many people
 A trendy buzzword, but with a powerful ideology
 Not just for “The Unicorn Companies”
 For today, lets focus on key concepts such as Agile,
Culture, Quality, Automation & Tools
 For a great in depth discussion read “What Is
DevOps?” by the Agile admin:
http://theagileadmin.com/what-is-devops/
DevOps: My Initial Thoughts
3 Ring Circus
Like I didn’t
have enough
problems when
they
(Development &
Operations)
worked
independently –
now they want
us to work
together –
Seriously???
Puppets, Chefs,
& Vagrants –
These are now
in the
environment – I
don’t know
what this
means, but your
telling me not
to worry –
Really???
We struggle with a few
security basics already
– and now you want to
do everything faster –
Fantastic!
 Once I began to
understand the DevOps
shift and that it means
more than a suite of new
tools, I began to feel a little
better
 Communication,
Collaboration and
Integration – these sound
like good things that we
can use more of
 Everyone is doing it –
How bad could it be?
A Light At The End of The Tunnel – But I Still Think It
Could Be A Train
 CIA – Confidentiality,
Integrity, Availability
 Slower is better
 Separation of Duties
 Documentation
 Security Says No!
Traditional Security 101
How Security Sees Itself
How Security Sees Development & Operations
How Development & Operations See Security
Security Says…
NO!!!
How We All Should Be Seen
Dev OpsSec
Faster releases means faster
security fixes
More automation = Less manual
processes (read less human error
& reduced insider threats)
More visibility and involvement
with stakeholders
Time For A Change
 Security not only embraces but leads a Security
driven DevOps Culture
 We control our own destiny rather than fight an
inevitable and uphill battle
 We manage by risk based approach – but still
achieve our compliance requirements
SecDevOps
DevOps Security
 Happens a lot faster, if not “real time”
 Automation
 Less Documentation
 “Blurred” segregation of duties
 Security needs to say yes with secure, flexible,
solutions that address CIA and not loose focus on
what we are really trying to protect
 Collaboration
• Work together so the output is
more like SecDevOps
 Communication
• Share what you are doing and
why
• Learn to speak the DevOps
language but share Security
perspectives too
 Innovation
• Work with to find solutions to
support traditional Security 101
goals while supporting new
methodologies
How Do We
Get There?
 It is happening one way
or the other – better to
control our own destiny
rather than fight an
uphill battle
 Let us all work
collaboratively to get
our needs met
 Let us show you how it
can benefit you
How Do We Sell This?
 Faster releases means
faster security fixes and
less vulnerabilities
 More automation = Less
manual processes (read
less human error &
insider threats)
 More visibility and
involvement with
stakeholders
CISO Benefits – If DevOps Security Is Done Right
Some Other Things To Consider
 Security leaders will need to invest time in the
transition so you can help meet existing security
requirements while supporting the mission
 Start small and prove this works
 Get the CISO onboard, he can be your biggest
advocate
 This is a huge shift – it will take time – practice
traditional organizational change management
techniques
 Lead by example
 More & Improved Collaboration
and Communication
 More open minds and increased
knowledge
 Flexible solutions that address the
intent of CIA while not getting
hung up on “Old School” and we
have always done it that way
methodologies
 Become change agents in the
security community (including risk
managers, auditors, compliance
professionals)
What Needs
To Change -
Security
 More & Improved Collaboration
and Communication
 Innovative ways to support
traditional security objectives
while embracing DevOps
 Put the “No” in Technology and
start speaking the language of
risk management
 Build in security through out the
entire DevOps Lifecycle
What Needs
To Change -
DevOps
Where To Start
 Focusing on technology and
ignoring organizational culture
 Lack of creativity
 Lack of executive support
 Only select teams/individuals
adopting new methodologies
 Loosing sight business goals and
desired outcomes
Cause of
Failure
 Proper training
 Starting small
 Alignment with business
 Creating a culture of agility
 Incremental improvement
 Focus on the intent of security
requirements
 Risk based approach
Cause of
Success
 Start today
• You invested the time in this session
– take the next step
 Avoid overthinking
• You don’t need to rollout the perfect
solution
 Iterative approach
• Crawl, Walk, Run
 Be constructively dissatisfied
• Deliver continuous improvement
 Lead by example & and build
controls into the process
Call to Action
Thank You!
 Help me spread the message to others
 Build security into your organizational DevOps
culture so that it looks more like SecDevOps
Please check me out on LinkedIn
http://www.linkedin.com/in/timvirtue
Or follow me on Twitter
https://twitter.com/timvirtue
 Tim Virtue
• Chief Information Security Officer
• Tim.Virtue@egov.comContact Me
DevOps:  Lead, Follow or Get Out of the Way - A CISO Perspective

Mais conteúdo relacionado

Mais procurados

Mistake proofing presentation
Mistake proofing presentation Mistake proofing presentation
Mistake proofing presentation
leanadvisors
 
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detectionAgile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
Michael Palotas
 
Quality Without Heroics
Quality Without HeroicsQuality Without Heroics
Quality Without Heroics
Thoughtworks
 
10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts
Internet World
 

Mais procurados (16)

Mistake proofing presentation
Mistake proofing presentation Mistake proofing presentation
Mistake proofing presentation
 
DevOps not a Toolbox
DevOps not a ToolboxDevOps not a Toolbox
DevOps not a Toolbox
 
Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...
 
Agile is all about learning
Agile is all about learningAgile is all about learning
Agile is all about learning
 
Innovation Decentralized
Innovation DecentralizedInnovation Decentralized
Innovation Decentralized
 
Cloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security PractitionerCloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security Practitioner
 
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detectionAgile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
 
Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)
 
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPackCONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
 
Colin Domoney -
Colin Domoney -  Colin Domoney -
Colin Domoney -
 
How to Build a Healthy On-Call Culture
How to Build a Healthy On-Call CultureHow to Build a Healthy On-Call Culture
How to Build a Healthy On-Call Culture
 
Quality Without Heroics
Quality Without HeroicsQuality Without Heroics
Quality Without Heroics
 
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
 
Lean
LeanLean
Lean
 
Brians Presn
Brians PresnBrians Presn
Brians Presn
 
10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts
 

Semelhante a DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

Effective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptxEffective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptx
Rezi Purnama
 
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
FiSTB
 

Semelhante a DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective (20)

Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019
 
Effective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptxEffective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptx
 
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
 
Applying Lean Security To The Business
Applying Lean Security To The BusinessApplying Lean Security To The Business
Applying Lean Security To The Business
 
DevOps for Managers
DevOps for ManagersDevOps for Managers
DevOps for Managers
 
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
 
Modeling and Measuring DevOps Culture
Modeling and Measuring DevOps CultureModeling and Measuring DevOps Culture
Modeling and Measuring DevOps Culture
 
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps SolutionsLet’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
 
Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?
 
A Culture Transformed: Instilling DevOps Ways of Working
A Culture Transformed:  Instilling DevOps Ways of Working A Culture Transformed:  Instilling DevOps Ways of Working
A Culture Transformed: Instilling DevOps Ways of Working
 
What is DevOps?
What is DevOps?What is DevOps?
What is DevOps?
 
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
 
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's PerspectiveDevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
 
DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015
 
DevSecCon Keynote
DevSecCon KeynoteDevSecCon Keynote
DevSecCon Keynote
 
Practically applying agile
Practically applying agilePractically applying agile
Practically applying agile
 
Top 10 devops values
Top 10 devops valuesTop 10 devops values
Top 10 devops values
 
Introduction to DevOps
Introduction to DevOpsIntroduction to DevOps
Introduction to DevOps
 
DevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile ManagementDevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile Management
 
The Journey to DevSecOps
The Journey to DevSecOpsThe Journey to DevSecOps
The Journey to DevSecOps
 

Mais de Texas.gov

Mais de Texas.gov (9)

Beyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile CapabilitiesBeyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile Capabilities
 
Mobile Trends
Mobile TrendsMobile Trends
Mobile Trends
 
Texas.gov Presents: Battle of Programming Languages
Texas.gov Presents:  Battle of Programming LanguagesTexas.gov Presents:  Battle of Programming Languages
Texas.gov Presents: Battle of Programming Languages
 
Fee Pay Lite Screenshots
Fee Pay Lite ScreenshotsFee Pay Lite Screenshots
Fee Pay Lite Screenshots
 
Commissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo SlidesCommissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo Slides
 
Hackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve ResultsHackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve Results
 
Texas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common GoalTexas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common Goal
 
NACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you ComputeNACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you Compute
 
THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Último (20)

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 

DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

  • 1. 1 DevOps: Lead, Follow, Or Get Out of the Way A CISO Perspective Presented by: Tim Virtue CISO, Texas.gov
  • 2. The Lawyers Made Me Do It  Any references to specific organizations, people, products, or services, are purely examples or learning opportunities and neither criticisms nor endorsements  The views presented are strictly my own and may or may not represent any organizations or affiliations I have (mostly because they have not seen the light yet )  It’s OK to agree to disagree, but anyone who gets that worked up over slides needs a vacation
  • 3. ABC Soup & Street Cred  CISSP, CCSK, CISA, CIPP/G, CFE, ITIL V3, CVE, QGVM, blah blah blah…  Over 15 years experience in Security, Risk Management and IT  Executive Master of Science in Information Systems from a top business school  Cyber Security Instructor, Author & Speaker  Not bragging – just showing perspective & credibility – if DevOps can sell me, you can sell it to the greater security community and your organization
  • 4.  Something to be ignored  Something Security should try and stop  Something done in isolation  A system or tool implementation What DevOps Is Not
  • 5. What is DevOps?  Many things to many people  A trendy buzzword, but with a powerful ideology  Not just for “The Unicorn Companies”  For today, lets focus on key concepts such as Agile, Culture, Quality, Automation & Tools  For a great in depth discussion read “What Is DevOps?” by the Agile admin: http://theagileadmin.com/what-is-devops/
  • 6. DevOps: My Initial Thoughts 3 Ring Circus Like I didn’t have enough problems when they (Development & Operations) worked independently – now they want us to work together – Seriously??? Puppets, Chefs, & Vagrants – These are now in the environment – I don’t know what this means, but your telling me not to worry – Really??? We struggle with a few security basics already – and now you want to do everything faster – Fantastic!
  • 7.  Once I began to understand the DevOps shift and that it means more than a suite of new tools, I began to feel a little better  Communication, Collaboration and Integration – these sound like good things that we can use more of  Everyone is doing it – How bad could it be? A Light At The End of The Tunnel – But I Still Think It Could Be A Train
  • 8.  CIA – Confidentiality, Integrity, Availability  Slower is better  Separation of Duties  Documentation  Security Says No! Traditional Security 101
  • 10. How Security Sees Development & Operations
  • 11. How Development & Operations See Security Security Says… NO!!!
  • 12. How We All Should Be Seen Dev OpsSec
  • 13. Faster releases means faster security fixes More automation = Less manual processes (read less human error & reduced insider threats) More visibility and involvement with stakeholders
  • 14. Time For A Change
  • 15.  Security not only embraces but leads a Security driven DevOps Culture  We control our own destiny rather than fight an inevitable and uphill battle  We manage by risk based approach – but still achieve our compliance requirements SecDevOps
  • 16. DevOps Security  Happens a lot faster, if not “real time”  Automation  Less Documentation  “Blurred” segregation of duties  Security needs to say yes with secure, flexible, solutions that address CIA and not loose focus on what we are really trying to protect
  • 17.  Collaboration • Work together so the output is more like SecDevOps  Communication • Share what you are doing and why • Learn to speak the DevOps language but share Security perspectives too  Innovation • Work with to find solutions to support traditional Security 101 goals while supporting new methodologies How Do We Get There?
  • 18.  It is happening one way or the other – better to control our own destiny rather than fight an uphill battle  Let us all work collaboratively to get our needs met  Let us show you how it can benefit you How Do We Sell This?
  • 19.  Faster releases means faster security fixes and less vulnerabilities  More automation = Less manual processes (read less human error & insider threats)  More visibility and involvement with stakeholders CISO Benefits – If DevOps Security Is Done Right
  • 20. Some Other Things To Consider  Security leaders will need to invest time in the transition so you can help meet existing security requirements while supporting the mission  Start small and prove this works  Get the CISO onboard, he can be your biggest advocate  This is a huge shift – it will take time – practice traditional organizational change management techniques  Lead by example
  • 21.  More & Improved Collaboration and Communication  More open minds and increased knowledge  Flexible solutions that address the intent of CIA while not getting hung up on “Old School” and we have always done it that way methodologies  Become change agents in the security community (including risk managers, auditors, compliance professionals) What Needs To Change - Security
  • 22.  More & Improved Collaboration and Communication  Innovative ways to support traditional security objectives while embracing DevOps  Put the “No” in Technology and start speaking the language of risk management  Build in security through out the entire DevOps Lifecycle What Needs To Change - DevOps
  • 24.  Focusing on technology and ignoring organizational culture  Lack of creativity  Lack of executive support  Only select teams/individuals adopting new methodologies  Loosing sight business goals and desired outcomes Cause of Failure
  • 25.  Proper training  Starting small  Alignment with business  Creating a culture of agility  Incremental improvement  Focus on the intent of security requirements  Risk based approach Cause of Success
  • 26.  Start today • You invested the time in this session – take the next step  Avoid overthinking • You don’t need to rollout the perfect solution  Iterative approach • Crawl, Walk, Run  Be constructively dissatisfied • Deliver continuous improvement  Lead by example & and build controls into the process Call to Action
  • 27. Thank You!  Help me spread the message to others  Build security into your organizational DevOps culture so that it looks more like SecDevOps Please check me out on LinkedIn http://www.linkedin.com/in/timvirtue Or follow me on Twitter https://twitter.com/timvirtue
  • 28.  Tim Virtue • Chief Information Security Officer • Tim.Virtue@egov.comContact Me