Início
Conheça mais
Enviar pesquisa
Carregar
Entrar
Cadastre-se
Anúncio
Check these out next
Dos and Don'ts of DevSecOps
Priyanka Aash
10 things to get right for successful dev secops
Mohammed Ahmed
Automating Security Compliance on AWS with DevSecOps
Tushar Gupta
PIACERE - DevSecOps Automated
PIACERE
Dev secops security and compliance at the speed of continuous delivery - owasp
Dag Rowe
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
Mohamed Nizzad
Scale DevSecOps with your Continuous Integration Pipeline
DevOps.com
Practical DevSecOps Course - Part 1
Mohammed A. Imran
1
de
23
Top clipped slide
Microsoft DevOps Forum 2021 – DevOps & Security
7 de Jul de 2021
•
0 gostou
0 gostaram
×
Seja o primeiro a gostar disto
mostrar mais
•
241 visualizações
visualizações
×
Vistos totais
0
No Slideshare
0
De incorporações
0
Número de incorporações
0
Baixar agora
Baixar para ler offline
Denunciar
Tecnologia
DevOps practices for small teams and organizations, with a focus on security
Nico Meisenzahl
Seguir
Cloud Solution Architect | Head of DevOps Consulting & Operations em white duck
Anúncio
Anúncio
Anúncio
Recomendados
DevOps & DevSecOps in Swiss Banking
Aarno Aukia
159 visualizações
•
41 slides
DevSecOps reference architectures 2018
Sonatype
9.8K visualizações
•
27 slides
Painless DevSecOps: Building Security Into Your DevOps Pipeline
Tasktop
646 visualizações
•
12 slides
Dev secops. Real experience.
Vitaly Balashov
226 visualizações
•
18 slides
DevSecOps for the DoD
JamesHarmison
82 visualizações
•
42 slides
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
754 visualizações
•
44 slides
Mais conteúdo relacionado
Apresentações para você
(20)
Dos and Don'ts of DevSecOps
Priyanka Aash
•
448 visualizações
10 things to get right for successful dev secops
Mohammed Ahmed
•
186 visualizações
Automating Security Compliance on AWS with DevSecOps
Tushar Gupta
•
61 visualizações
PIACERE - DevSecOps Automated
PIACERE
•
116 visualizações
Dev secops security and compliance at the speed of continuous delivery - owasp
Dag Rowe
•
217 visualizações
DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and c...
Mohamed Nizzad
•
156 visualizações
Scale DevSecOps with your Continuous Integration Pipeline
DevOps.com
•
373 visualizações
Practical DevSecOps Course - Part 1
Mohammed A. Imran
•
3.3K visualizações
Barriers to Container Security and How to Overcome Them
WhiteSource
•
124 visualizações
NYIT DSC/ Spring 2021 - Introduction to DevOps (CI/CD)
Hui (Henry) Chen
•
40 visualizações
Zero to Ninety in Securing DevOps
DevSecOps Days
•
2.5K visualizações
#ATAGTR2019 Presentation "DevSecOps with GitLab" By Avishkar Nikale
Agile Testing Alliance
•
324 visualizações
DevSecOps Days SF at RSA Conference 2018
DevSecOps Days
•
192 visualizações
Introduction to DevSecOps
Setu Parimi
•
1.8K visualizações
DevSecOps Training Bootcamp - A Practical DevSecOps Course
Tonex
•
606 visualizações
Professional Cloud DevOps Engineer - Study Group - Week 1
Ervin Weber
•
58 visualizações
DevSecOps 101
Narudom Roongsiriwong, CISSP
•
7K visualizações
DevSecOps : an Introduction
Prashanth B. P.
•
235 visualizações
Secure Your Code Implement DevSecOps in Azure
kloia
•
197 visualizações
How to automate your DevSecOps successfully
Manuel Pistner
•
767 visualizações
Similar a Microsoft DevOps Forum 2021 – DevOps & Security
(20)
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
•
124 visualizações
KCD Munich 2022: How to Prevent Your Kubernetes Cluster From Being Hacked
Nico Meisenzahl
•
48 visualizações
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
•
69 visualizações
Container Days: Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
•
14 visualizações
How to Prevent Your Kubernetes Cluster From Being Hacked
Nico Meisenzahl
•
46 visualizações
ContainerConf 2022: Hijack Kubernetes
Nico Meisenzahl
•
52 visualizações
GitLab Remote Meetup: Enhance Your Kubernetes CI/CD Pipelines with GitLab & O...
Cloud Native Rosenheim Meetup
•
52 visualizações
GitLab Remote Meetup: Enhance Your Kubernetes CI/CD Pipelines with GitLab & ...
Nico Meisenzahl
•
155 visualizações
KCD Munich 2022: Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
•
12 visualizações
Cloud Love Conference: Kubernetes is awesome, but...
Nico Meisenzahl
•
11 visualizações
Azure Rosenheim Meetup: Azure Service Operator
Nico Meisenzahl
•
61 visualizações
GitHub Actions 101
Nico Meisenzahl
•
104 visualizações
ContainerConf 2022: Kubernetes is awesome - but...
Nico Meisenzahl
•
184 visualizações
Shift Left for More Secure Apps with F5 NGINX
NGINX, Inc.
•
98 visualizações
Hijack a Kubernetes Cluster - a Walkthrough
Nico Meisenzahl
•
100 visualizações
azdevcom - Hijack a Kubernetes Cluster
Nico Meisenzahl
•
137 visualizações
Mitigate potential compliance risks
Jürgen Brüder
•
117 visualizações
Container Day Security: How to Prevent Your Kubernetes Cluster From Being Hacked
Nico Meisenzahl
•
24 visualizações
DevOpsCon Berlin: Helm vs Operators – Do I Need to Decide?
Nico Meisenzahl
•
107 visualizações
Cncf checkov and bridgecrew
LibbySchulze
•
1.3K visualizações
Anúncio
Mais de Nico Meisenzahl
(15)
Festive Tech Calendar: Festive time with AKS networking
Nico Meisenzahl
•
16 visualizações
Azure Zürich User Group: Azure Kubernetes Service – more than just a managed ...
Nico Meisenzahl
•
90 visualizações
Continuous Lifecycle: Enhance Your Compliance and Governance With Policy-Base...
Nico Meisenzahl
•
163 visualizações
Continuous Lifecycle: Hijack Kubernetes
Nico Meisenzahl
•
52 visualizações
GitLab Commit: Enhance your Compliance with Policy-Based CI/CD
Nico Meisenzahl
•
531 visualizações
Azure Meetup Hamburg: Production-Ready Terraform Deployments on Azure
Nico Meisenzahl
•
287 visualizações
GitLab Commit DevOps: How GitLab Can Save your Kubernetes environment from Be...
Nico Meisenzahl
•
86 visualizações
Azure Saturday Hamburg: Containerize Your .NET Microservice - the Right Way!
Nico Meisenzahl
•
249 visualizações
Cloud Native Day: Cloud-native Anwendungsentwicklung im Jahr 2021
Nico Meisenzahl
•
145 visualizações
Die Evolution von Container Image Builds
Nico Meisenzahl
•
223 visualizações
Azure Service Operator - Provision Your Resources in a Cloud-Native Way
Nico Meisenzahl
•
223 visualizações
Effiziente CI/CD-Pipelines – mit den richtigen Tools klappt das
Nico Meisenzahl
•
46 visualizações
DevOpsCon London: How containerized Pipelines can boost your CI/CD
Nico Meisenzahl
•
219 visualizações
GitLab Commit: Your Attackers Won't Be Happy! How GitLab Can Help You Secure ...
Nico Meisenzahl
•
103 visualizações
Virtual GitLab Meetup: How Containerized Pipelines and Kubernetes Can Boost Y...
Nico Meisenzahl
•
205 visualizações
Último
(20)
Perform Mensuration and Calculation PPT.pptx
PauloAngeles4
•
2 visualizações
Migrating to the Cloud - From Preparation to Operation copy.pdf
Symptai Consulting Limited
•
2 visualizações
WordPress Coding Standards
Jonathan Bossenger
•
0 visão
State of PrintCSS - MarkupUK 2023.pdf
Andreas Jung
•
0 visão
ISO 27001 How to accelerate the implementation.pdf
Andrey Prozorov, CISM, CIPP/E, CDPSE. LA 27001
•
0 visão
CDP_Presentation.pptx
Abbas335883
•
2 visualizações
kamil.pdf
AzeemAslam11
•
2 visualizações
Multi Standard Mixed Mode.pdf
MbBot
•
3 visualizações
Theben DALI-2 Room Solution
Ivory Egg
•
13 visualizações
Partnerships And Affiliations | Chetu
Chetu
•
0 visão
DNN Community Newsletter: An In-Person Review of Recent Open-Source Activity
Will Strohl
•
0 visão
Fab library construction protocol.pdf
AliceChang70
•
0 visão
Office 365 DLP-1.pptx
AnanyaShukla45
•
0 visão
State Of GPT
ssuser6f266e
•
0 visão
Operating System.pptx
NoumanHameed16
•
0 visão
Chapter 1
Aman564573
•
0 visão
Home care agencies!
AlexHill876665
•
0 visão
PTManu.pdf
abrhsh abadi
•
0 visão
MINOR PROJECT.pptx
YashikaSengar2
•
0 visão
Ga4 Recommended ecommerce events.pdf
Codilar Technologies
•
0 visão
Anúncio
Microsoft DevOps Forum 2021 – DevOps & Security
DevOps practices for
small teams and organizations, with a focus on security Microsoft DevOps Forum 2021 – DevOps & Security
Nico Meisenzahl • Senior
Cloud & DevOps Consultant at white duck • Microsoft MVP, Docker Community Leader & GitLab Hero • Container, Kubernetes, Cloud-Native & DevOps © white duck GmbH 2021 Phone: +49 8031 230159 0 Email: nico.meisenzahl@whiteduck.de Twitter: @nmeisenzahl LinkedIn: https://www.linkedin.com/in/nicomeisenzahl Blog: https://meisenzahl.org
Agenda • Current state
of DevSecOps in small teams & orgs • Demo: Implementing quick wins • Get started with DevSecOps • Implement quick wins © white duck GmbH 2021
Current state of
DevSecOps DevOps is now widely known and increasingly implemented in small teams & organizations. DevSecOps practices, on the other hand, are not well- known and typically not yet adopted. © white duck GmbH 2021
Current state of
DevSecOps in small teams & orgs • overall low Cloud / Cloud-Native security knowledge • same “problems” with security as with QA • no big invests • no real focus until there is breach or issue • no shift-left and fail-fast cultures • no security baseline • like governance, policies and landing zones © white duck GmbH 2021
What we see
at clients • traditional IT departments trying to secure cloud-native projects by relying on on-premises and outdated patterns • slowing down of projects & inovation, but no real increased security • an MVP (Minimum Viable Product) is leveraged as a long- term solution • skipped topics (in terms of time-to-market) are not considered anymore © white duck GmbH 2021
What we see
at clients • self-managed resources are sometimes preferred over PaaS and SaaS • then, not maintained with the necessary staff to operate them safely • self-implemented Identity management (AuthN, AuthZ) • without utilizing common best practices, managed services, and libraries/frameworks © white duck GmbH 2021
SANS 2021 Cloud
Security Survey © white duck GmbH 2021
Demo – Implementing
quick wins • “Ping me app”, based on Golang, deployed to ACI and exposed via App Gateway © white duck GmbH 2021
Demo recap • we
found a security vulnerability and injected commands • we consulted the docs for security recommendations • we implemented a Web Application Firewall (WAF) to secure our app • we enabled Code Scanning in our GitHub Repo to fix the issue as well as to find future security issues in earlier stages © white duck GmbH 2021
Get started with
DevSecOps • start small and grow • introduce security into all DevOps stages • try to shift security to the left • implement zero-trust Tip: Security should be easy to use, integrated and automated © white duck GmbH 2021
Educate yourself • consult
documentation • general docs • Cloud Adoption Framework • https://docs.microsoft.com/azure/cloud-adoption-framework • Azure & GitHub at Microsoft Learn • https://docs.microsoft.com/learn • join a local Meetup group • https://www.meetup.com/pro/azuretechgroups Tip: Get certified © white duck GmbH 2021
Stay up-to-date • Azure
Updates • https://azure.microsoft.com/updates • GitHub Updates • https://github.blog/changelog • https://github.blog/category/product • Azure Friday • https://azure.microsoft.com/resources/videos/azure-friday © white duck GmbH 2021
Security quick wins
through the DevOps cycle © white duck GmbH 2021
Enable your team •
integrate security staff in your development lifecycle (Sprint) • educate developers to raise their security awareness • implement pair programming • enforce PR reviews © white duck GmbH 2021
Ensure secure code •
automate and enforce code checks • check your code for secret • schedule dependency scanning • Dependabot • enforce Static Application Security Testing (SAST) in PRs • scans your code to identify potential security vulnerabilities © white duck GmbH 2021
SAST Tooling • GitHub
CodeQL • https://codeql.github.com • .Net & .Net Core • https://security-code-scan.github.io • Golang • https://securego.io • Kubernetes manifests • https://kubesec.io • Terraform • https://github.com/tfsec/tfsec © white duck GmbH 2021
Ensure secure code
(next stage) • implement automated Dynamic Application Security Testing (DAST) • black-box scanning against a running web application • scheduled scan your artifacts and containers • sign your artifacts and containers © white duck GmbH 2021
App Vulnerability Management
Tooling • Zed Attack Proxy • https://www.zaproxy.org • DefectDojo • https://www.defectdojo.org © white duck GmbH 2021
Ensure a secure
runtime • implement zero-trust • automate everything (App and infrastructure deployments) • prefer PaaS and SaaS over unmanaged services • review Azure Advisor recommendations • opt-in for Azure Security Center to get even more insights • design & implement a Cloud Governance strategy • IAM, Polices, Landing Zone, … © white duck GmbH 2021
Monitor, review and
iterate • implementing security is not a one-time job • you need to stay up-to-date • think big, but start small and iterate • as we do in application development © white duck GmbH 2021
Implement best practices •
https://docs.microsoft.com/de-de/azure/security/ • https://docs.microsoft.com/en-us/security/cybersecurity- reference-architecture/mcra • https://docs.microsoft.com/de- de/azure/architecture/solution-ideas/articles/devsecops-in- github © white duck GmbH 2021
Questions? Nico Meisenzahl (Senior
Cloud & DevOps Consultant) Phone: +49 8031 230159 0 Email: nico.meisenzahl@whiteduck.de Twitter: @nmeisenzahl LinkedIn: https://www.linkedin.com/in/nicomeisenzahl Blog: https://meisenzahl.org © white duck GmbH 2021
Anúncio