SlideShare uma empresa Scribd logo
1 de 33
1
DevSecOps - Building Continuous
Security Into IT & App Infrastructures
John Pescatore, SANS
Chris Carlson, Qualys
2
Protecting Your Company From the Company It Keeps
 Business is increasingly
interconnected and interdependent
via software
 The bad guys have figured that out.
So have the regulators
 The “app cloud” exacerbates that
trend, additional levels of “parties”
 Software security/quality is a key
factor in business success
3
What a Long Strange Trip It Has Been…
Sometimes the light's all shinin' on me,
Other times I can barely see.
4
The Basics of Cyber Risks
Risk = Threat x Vulnerability +/- Action
•Vulnerabilities are at the center
•Threat actors will act
•Threat delivery continually evolves
•Effectiveness and timeliness of business security action
separates high loss/low loss
•Fewer Vulnerabilities
•Faster mitigation action
5
First there was DevOps
• Amazon: “DevOps is the combination of cultural philosophies, practices,
and tools that increases an organization’s ability to deliver applications
and services at high velocity: evolving and improving products at a faster
pace than organizations using traditional software development and
infrastructure management processes. ”
• Not really much new, but key concepts: combine and faster
6
So, What is SecOps?
• SecOps: “Integrating security processes with IT acquisition,
development, administration and operations practices to
reduce vulnerabilities and more quickly mitigate exposures.”
• Overcoming people/organizational barriers
• Integrating processes, then tools and data flow
Source: devops.tumblr.com
7
SecOps – Continuous Processes
Shield
Eliminate Root
Cause
Monitor/
Report
Policy
Assess
Risk
Baseline
Vuln Assessment/Pen Test
Security Configuration
Mitigate
• FW/IPS
• Anti-malware
• NAC
• Patch Management
• Config Management
• Change Management
• Software Vuln Test
• Training
• Network Arch
• Privilege Mgmt
Discovery/Inventory
• SIEM
• Security Analytics
• Incident Response
Threats
Regulations
Requirements
OTT Dictates
8
Delivering Security Efficiency and Effectiveness
• Decrease the cost of dealing
with known threats
• Decrease the impact of
residual risks
• Decrease the cost of
demonstrating compliance
• Reduce business damage due
to security failures
• Maintaining level of
protection with less EBITDA
impact
• Increase the speed of dealing
with a new threat or
technology
• Decrease the time required
to secure a new business
application, partner, supplier
• Reducing incident cost
○ Less down time
○ Fewer customer defections
• Security as a competitive
business factor
Efficiency Effectiveness
9
Digital Transformation
is driving
Business + IT + Security
10
#1 Engage Customers
#2 Empower Employees
#3 Optimize Operations
#4 Transform Products & Enable New Business
Models
Source: https://news.microsoft.com/apac/2017/02/20/80-of-business-
leaders-believe-they-need-to-be-a-digital-business-to-succeed-microsoft-
study/microsoft-digital-transformation-infographic-asia
Digital Transformation – Priorities
11
#1 Cyber Threats & Security Concerns
#1 Lack of Digitally-Skilled Workforce
#2 Lack of Supporting Government Policies and ICT Infrastructure
#3 Uncertain Economic Environment
#3 Lack of Leadership to Ideate, Plan, and Lead Digital
Transformation Strategy
Digital Transformation – Barriers
12
Not a Challenge – An Opportunity!
Business Transformation IT Transformation
IT Transformation Security Transformation
13
DevSecOps =/ DevOps + Security
14
If DevOps is about
Speed
Agility
Automation
15
False Approach ~ False Start ~ Failure
16
Security + DevOps = Revolt or Left Out?
Source: https://theclumpany.wordpress.com/2015/08/09/pitchforks-and-
flaming-torches/
17
Food Safety is a Security Problem in
Manufacturing Pipeline
Source:
http://www.foodengineeringmag.com/articles/889
90-tech-update-metal-detection-xray-inspection-
18
Shift
Time
Shift
Technique
Shift
Tools
Shift Approaches
19
Shift Time
It’s not about doing the same things earlier …
... but an opportunity to do different and
better things earlier
20
Case Study: Financial Services Mobile Wallet
21
Security
Born in the Cloud: New
builds in AWS every 60 days
Automated Regression &
Test-Driven Development
Docker containers abstracts
applications from OS
DevOps
Qualys Case Study: Financial Services Mobile Wallet
Commercial/Open Source
vulnerabilities are detected & fixed
on same release cadence
Automated regression
finds patch issues faster
OS vulnerabilities are patched
separate from Applications
1
2
3
22
Qualys Case Study: Financial Services Mobile Wallet
23
Shift Techniques
Instead of thinking like a security person –
perimeter, gates, limiting access, closed…
... Think like a developer:
Automation API
Integration Continuous
Visibility Measure + Refine
24
Qualys Case Study: One of Largest Ecommerce Companies
25
Prevent Software Check-Ins
that use Vulnerable Libraries
Apply Technique
Tag Vulnerable Libraries in
Source Control
1
Shift Technique
Automatically open tickets for
Developers on security issues
Apply Technique
Vulnerabilities in Production
are Treated as Defects
Shift Technique
2
Excessive Remediation Times
are escalated to CEO
Apply Technique
Open Vulnerabilities Reported
to Business Unit VPs
Shift Technique
3
Qualys Case Study: One of Largest Ecommerce Companies
26
Shift Tools
Find/Implement the right tools for the DevOps
Processes…
... But:
You may not need to procure new tools
APIs, Integrations, Self-Service UIs
Collaborate with current vendors on your DevOps plans
27
Qualys Case Study: Financial Investment Services
28
Qualys Case Study: Financial Investment Services
SolutionChallenge
400+ Web Apps in production
Web Security Assessment found
they had a lot of “easily”
mitigated app vulnerabilities
Integrated the production Web
Security Assessment tool into DevOps
processes via API
Automatically create Jira bugs for
App Development to fix XSS and
SQL Injection issues
Continuously assess Web
Apps in the dev process so
issues are not re-introduced
Hard for developers to fix
security issues in production
1
2
3
29
Integrate Production Security Tool into DevOps
Image Source: https://www.smashingmagazine.com/2015/01/basic-test-automation-for-apps-
games-and-mobile-web/
Selenium
Qualys WAS
Jira Issues
Selenium
Qualys WAS
Jira Issues
30
How can you get
started?
31
Next Week
• Take an accounting of
current security tools –
are they DevOps
friendly with APIs,
automation, or self-
service UIs?
• Identify development
teams using DevOps –
engage and discuss
DevSecOps
• Visible vs. Safe project
• Cloud vs. On-premise
Next Quarter
• Integrate security tools
into one development
lifecycle
• Security process(es) to
overcome tool integration
• Measure outcomes – #
vulns identified/fixed
before release
• Host a vendor Summit –
present your project
roadmap and Evangelize
DevSecOps
Next 6 Months
• Consolidate / select new
security tool sets ($$
savings)
• Implement self-service
and API-based
DevSecOps programs
• Expand to more projects
– foundational
• Present at conferences
and user groups on
DevSecOps
32
Resources
• SANS : https://www.sans.org/webcasts/archive/2017
• SAFECode: https://www.safecode.org/
• SANS Difference Makers - https://www.sans.org/cyber-innovation-awards
• Qualys: https://www.qualys.com
• Questions: q@sans.org
• @John_Pescatore
• @Qualys
33
Acknowledgements
Thanks to our sponsor:
And also to our speakers and to our attendees:
Thank you for joining us today
© 2017 The SANS™ Institute – www.sans.org

Mais conteúdo relacionado

Último

Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 

Último (20)

Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Destaque

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Destaque (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

DevSecOps - Building Continuous Security Into IT & App Infrastructures

  • 1. 1 DevSecOps - Building Continuous Security Into IT & App Infrastructures John Pescatore, SANS Chris Carlson, Qualys
  • 2. 2 Protecting Your Company From the Company It Keeps  Business is increasingly interconnected and interdependent via software  The bad guys have figured that out. So have the regulators  The “app cloud” exacerbates that trend, additional levels of “parties”  Software security/quality is a key factor in business success
  • 3. 3 What a Long Strange Trip It Has Been… Sometimes the light's all shinin' on me, Other times I can barely see.
  • 4. 4 The Basics of Cyber Risks Risk = Threat x Vulnerability +/- Action •Vulnerabilities are at the center •Threat actors will act •Threat delivery continually evolves •Effectiveness and timeliness of business security action separates high loss/low loss •Fewer Vulnerabilities •Faster mitigation action
  • 5. 5 First there was DevOps • Amazon: “DevOps is the combination of cultural philosophies, practices, and tools that increases an organization’s ability to deliver applications and services at high velocity: evolving and improving products at a faster pace than organizations using traditional software development and infrastructure management processes. ” • Not really much new, but key concepts: combine and faster
  • 6. 6 So, What is SecOps? • SecOps: “Integrating security processes with IT acquisition, development, administration and operations practices to reduce vulnerabilities and more quickly mitigate exposures.” • Overcoming people/organizational barriers • Integrating processes, then tools and data flow Source: devops.tumblr.com
  • 7. 7 SecOps – Continuous Processes Shield Eliminate Root Cause Monitor/ Report Policy Assess Risk Baseline Vuln Assessment/Pen Test Security Configuration Mitigate • FW/IPS • Anti-malware • NAC • Patch Management • Config Management • Change Management • Software Vuln Test • Training • Network Arch • Privilege Mgmt Discovery/Inventory • SIEM • Security Analytics • Incident Response Threats Regulations Requirements OTT Dictates
  • 8. 8 Delivering Security Efficiency and Effectiveness • Decrease the cost of dealing with known threats • Decrease the impact of residual risks • Decrease the cost of demonstrating compliance • Reduce business damage due to security failures • Maintaining level of protection with less EBITDA impact • Increase the speed of dealing with a new threat or technology • Decrease the time required to secure a new business application, partner, supplier • Reducing incident cost ○ Less down time ○ Fewer customer defections • Security as a competitive business factor Efficiency Effectiveness
  • 10. 10 #1 Engage Customers #2 Empower Employees #3 Optimize Operations #4 Transform Products & Enable New Business Models Source: https://news.microsoft.com/apac/2017/02/20/80-of-business- leaders-believe-they-need-to-be-a-digital-business-to-succeed-microsoft- study/microsoft-digital-transformation-infographic-asia Digital Transformation – Priorities
  • 11. 11 #1 Cyber Threats & Security Concerns #1 Lack of Digitally-Skilled Workforce #2 Lack of Supporting Government Policies and ICT Infrastructure #3 Uncertain Economic Environment #3 Lack of Leadership to Ideate, Plan, and Lead Digital Transformation Strategy Digital Transformation – Barriers
  • 12. 12 Not a Challenge – An Opportunity! Business Transformation IT Transformation IT Transformation Security Transformation
  • 14. 14 If DevOps is about Speed Agility Automation
  • 15. 15 False Approach ~ False Start ~ Failure
  • 16. 16 Security + DevOps = Revolt or Left Out? Source: https://theclumpany.wordpress.com/2015/08/09/pitchforks-and- flaming-torches/
  • 17. 17 Food Safety is a Security Problem in Manufacturing Pipeline Source: http://www.foodengineeringmag.com/articles/889 90-tech-update-metal-detection-xray-inspection-
  • 19. 19 Shift Time It’s not about doing the same things earlier … ... but an opportunity to do different and better things earlier
  • 20. 20 Case Study: Financial Services Mobile Wallet
  • 21. 21 Security Born in the Cloud: New builds in AWS every 60 days Automated Regression & Test-Driven Development Docker containers abstracts applications from OS DevOps Qualys Case Study: Financial Services Mobile Wallet Commercial/Open Source vulnerabilities are detected & fixed on same release cadence Automated regression finds patch issues faster OS vulnerabilities are patched separate from Applications 1 2 3
  • 22. 22 Qualys Case Study: Financial Services Mobile Wallet
  • 23. 23 Shift Techniques Instead of thinking like a security person – perimeter, gates, limiting access, closed… ... Think like a developer: Automation API Integration Continuous Visibility Measure + Refine
  • 24. 24 Qualys Case Study: One of Largest Ecommerce Companies
  • 25. 25 Prevent Software Check-Ins that use Vulnerable Libraries Apply Technique Tag Vulnerable Libraries in Source Control 1 Shift Technique Automatically open tickets for Developers on security issues Apply Technique Vulnerabilities in Production are Treated as Defects Shift Technique 2 Excessive Remediation Times are escalated to CEO Apply Technique Open Vulnerabilities Reported to Business Unit VPs Shift Technique 3 Qualys Case Study: One of Largest Ecommerce Companies
  • 26. 26 Shift Tools Find/Implement the right tools for the DevOps Processes… ... But: You may not need to procure new tools APIs, Integrations, Self-Service UIs Collaborate with current vendors on your DevOps plans
  • 27. 27 Qualys Case Study: Financial Investment Services
  • 28. 28 Qualys Case Study: Financial Investment Services SolutionChallenge 400+ Web Apps in production Web Security Assessment found they had a lot of “easily” mitigated app vulnerabilities Integrated the production Web Security Assessment tool into DevOps processes via API Automatically create Jira bugs for App Development to fix XSS and SQL Injection issues Continuously assess Web Apps in the dev process so issues are not re-introduced Hard for developers to fix security issues in production 1 2 3
  • 29. 29 Integrate Production Security Tool into DevOps Image Source: https://www.smashingmagazine.com/2015/01/basic-test-automation-for-apps- games-and-mobile-web/ Selenium Qualys WAS Jira Issues Selenium Qualys WAS Jira Issues
  • 30. 30 How can you get started?
  • 31. 31 Next Week • Take an accounting of current security tools – are they DevOps friendly with APIs, automation, or self- service UIs? • Identify development teams using DevOps – engage and discuss DevSecOps • Visible vs. Safe project • Cloud vs. On-premise Next Quarter • Integrate security tools into one development lifecycle • Security process(es) to overcome tool integration • Measure outcomes – # vulns identified/fixed before release • Host a vendor Summit – present your project roadmap and Evangelize DevSecOps Next 6 Months • Consolidate / select new security tool sets ($$ savings) • Implement self-service and API-based DevSecOps programs • Expand to more projects – foundational • Present at conferences and user groups on DevSecOps
  • 32. 32 Resources • SANS : https://www.sans.org/webcasts/archive/2017 • SAFECode: https://www.safecode.org/ • SANS Difference Makers - https://www.sans.org/cyber-innovation-awards • Qualys: https://www.qualys.com • Questions: q@sans.org • @John_Pescatore • @Qualys
  • 33. 33 Acknowledgements Thanks to our sponsor: And also to our speakers and to our attendees: Thank you for joining us today © 2017 The SANS™ Institute – www.sans.org