Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DevOps Security and Continuous Failure: Lessons...

DevOps Security and Continuous Failure: Lessons From Heartbleed, Shellshock, and Countless Other Security Flaws

We pursue increasingly rapid delivery cycles while achieving previously unimaginable degrees of scalability, reliability, and raw performance. But there is obviously a growing and serious mismatch between our development and operations performance in securing our applications compared to our performance in other areas. I work at a company extensively involved in Drupal and other open source projects that concentrate on both DevOps and security, but continue to be plagued by serious security vulnerabilities. Organizations and individuals negatively affected by Heartbleed and other security flaws probably would have readily traded some delay in accessing new features or temporary access problems for better security. So, how can we better focus DevOps culture and practices on the concept of Continuous Security to deliver this? Perhaps we need to look at ongoing advances in automated security testing, more rigorous and frequent manual code review, and paired/team programming practices, and work better on more fully integrating these all into DevOps.

DevOpsDays DC

June 12, 2015
Tweet

More Decks by DevOpsDays DC

Other Decks in Technology

Transcript

  1. Mike Nescot • Web Ops Mgr. JBS International • Web dev, ops

    person since ~ ’94 • Web sec: FISMA, FedRAMP/GovCloud
  2. DevOps/Open Source Security Challenges • Big name bugs • FUD, hype, lies

    • Open source security? • Regulatory burden
  3. DevOps Pipeline vs. Lifecycle •  Continuous feedback •  Event aggregation,

    normalization, correlation • Trickle testing, deployment
  4. Technology to the Rescue: People are People • Developers are developers

    • Better languages • Safeguards (e.g., MFA)
  5. Security Metrics & Marketing • App security • Config management • Financial • Incident

    management • Patch management • Vulnerability management • Balanced Sec Scorecard