©2014 Nebula, Inc. All rights reserved.State of OpenStack SecurityBryan D. PayneDirector of Security ResearchMay 1, 2014
View Slide
©2014 Nebula, Inc. All rights reserved.My Background• Focused on security my entire career• Spent a few years in school
©2014 Nebula, Inc. All rights reserved.Nebula OneDevOPs/TestApps & WorkloadsMediaApps & WorkloadsOther …Apps & WorkloadsSocialCollaboration Apps& WorkloadsBig Data+ AnalyticsApps & WorkloadsMobileApps & WorkloadsCompute Storage NetworkIdentity/SecurityManagement/Orchestration/API InterfaceTurnkey Infrastructure as a Service(IaaS)Block Object1000+ companies contributing to OpenStackIndustry Standard Servers
©2014 Nebula, Inc. All rights reserved.OSSG HISTORY
©2014 Nebula, Inc. All rights reserved.LOOKING FORWARD
©2014 Nebula, Inc. All rights reserved.Key OSSG Projects• OpenStack Security Guide (aka “the book”)• OpenStack Security Notes (OSSN)• Threat Modeling & Analysis
©2014 Nebula, Inc. All rights reserved.Mid-Term Goals• Quality work in three key projects• More formal acceptance in community• Increase collaboration with core devs
©2014 Nebula, Inc. All rights reserved.OpenStack Projects “The Glue”Improve available securityDocument best practicesSimplify security complianceWork with builders, ops, users
©2014 Nebula, Inc. All rights reserved.QUESTIONSEmail: [email protected]Twitter: @bdpsecurity