Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DevSecOps: Delivering secure software at speed ...
Search
Evandro Mohr
June 08, 2019
Technology
340
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
DevSecOps: Delivering secure software at speed and scale of DevOps
Evandro Mohr
June 08, 2019
More Decks by Evandro Mohr
See All by Evandro Mohr
DevSecOps: Criando uma Cultura shift left
evandromohr
0
180
Trabalhando com Escopo Aberto
evandromohr
1
180
Event-driven architecture
evandromohr
0
230
Hacking your PHP application
evandromohr
0
180
Event-Driven Architecture
evandromohr
1
170
Other Decks in Technology
See All in Technology
Goでデータパイプラインを作ろう
sansantech
PRO
1
450
20260807_第6回_関東kaggler会LT_claw系bot xangiと始める、"寂しくない" kaggle
sugupoko
0
280
オートロックマンションなのに、各部屋は施錠なし!? 攻撃者が組織内ネットワークで大暴れする理由 / The Front Door Is Locked, but the Rooms Are Wide Open: Why Attackers Move Freely Inside Enterprise Networks
nttcom
1
5.7k
グローバル基準のSREは、運用現場でどう機能したか:成熟度アセスメントの実践 / SRE NEXT 2026
sorawatanabe
0
230
Genie Codeハンズオン基礎編
taka_aki
1
120
Bill One 開発エンジニア 紹介資料
sansan33
PRO
7
19k
第3回しろおびセキュリティスポンサーセッション
log0417
0
200
社内の7割が使うデータ基盤を、 データチーム2人で回すためにやったこと
koh_yoshi
4
1.4k
Sansan Engineering Unit 紹介資料
sansan33
PRO
1
4.9k
Flutterをカメラで動かしたかった話
sony
1
140
2026-08-05 IBM Z開発最前線!IBM Bob Premium Package for Zって何がすごいの?
yutanonaka
0
120
サイバー捜査員研修(前半)
nomizone
1
2k
Featured
See All Featured
Accessibility Awareness
sabderemane
1
180
How Software Deployment tools have changed in the past 20 years
geshan
1
34k
Pawsitive SEO: Lessons from My Dog (and Many Mistakes) on Thriving as a Consultant in the Age of AI
davidcarrasco
0
210
The Straight Up "How To Draw Better" Workshop
denniskardys
239
140k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
3
1.1k
Bootstrapping a Software Product
garrettdimon
PRO
307
120k
Darren the Foodie - Storyboard
khoart
PRO
3
3.6k
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
200
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
610
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
56
3.4k
First, design no harm
axbom
PRO
2
1.2k
世界の人気アプリ100個を分析して見えたペイウォール設計の心得
akihiro_kokubo
PRO
73
41k
Transcript
DevSecOps Delivering secure software at speed and scale of DevOps.
Evandro Mohr 2 Developer Pilot Professor Photographer
“ “DevOps is not a goal, but a never-ending process
of continual improvement” – Jez Humble 3
4 It’s all about bottlenecks
Chaotic Model 5 Fix Build First steps is SDLC
Waterfall Model 6
Waterfall Model ▪ Long release cycles. ▪ Functional silos ▪
Rigid ▪ Lot of WIP 7
The dawn of Agile 8 ▪ Shorter release cycles ▪
Cross functional teams ▪ Smaller batch sizes
DEV X OPS 9
DEV X OPS 10
DevOps 11
12 DevOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
DevOps Pipeline
How to keep up with security? 14
DevSecOps Integrating security into Agile and DevOps 15
“ “DevSecOps enable organisations to deliver inherently secure software at
DevOps scale and speed.” 16
Security Practice Checklist ✓ Verify for security Early and Often
✓ Parameterize Queries ✓ Encode data ✓ Validate All Inputs ✓ Implement Identity and Authentication Controls ✓ Implement Appropriate Access Controls ✓ Protect Data ✓ Implement Logging and Intrusion Detection ✓ Use security frameworks and libraries ✓ Error and Exception Handling
OWASP Top 10
Security Practice Checklist
DevSecOps
“ 21 DevOps security hooks
DevSecOps Trigger Points ✓ Static scanning during development ✓ Pull-requests:
Static scans of data-flow, semantic and configurational ✓ Integration branch: Dynamic scanning ✓ QA Release Candidate Integration: Dynamic scanning ✓ Production Acceptance: Production-safe dynamic scanning ✓ Post-Production: RASP (Runtime Application Self-Protection), WAF (Web Application Firewalls) both need rules updated.
23 DevSecOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
Culture ▪ Communication and transparency ▪ Blameless postmortem ▪ Continuous
improvement ▪ Everyone is responsible for security ▪ Automate as much as possible ▪ Everything as code
Processes Secure SDLC ▪ Training ▪ Requirements ▪ Architecture &
Design ▪ Coding ▪ Testing ▪ Deployment ▪ Post deployment
Processes Security Pipeline ▪ Assessment of critical resource ▪ Reduce
friction ▪ Increase visibility ▪ Each step repeatable ▪ Drive up dependency
Processes Security Pipeline
Technologies ▪ Requirements ▪ Code: IDE plugins, SAST ▪ Test:
Gauntlt, DAST ▪ Configure: Sec as code ▪ Maintenance: Patch management ▪ Monitor: Auditing, Attack visibility
Questions? 29
Thank you very much for your time 30 You can
find me at: ▪ br.linkedin.com/in/evandromohr ▪ t.me/phpcomrapadura