Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DevSecOps: Delivering secure software at speed ...
Search
Evandro Mohr
June 08, 2019
Technology
340
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
DevSecOps: Delivering secure software at speed and scale of DevOps
Evandro Mohr
June 08, 2019
More Decks by Evandro Mohr
See All by Evandro Mohr
DevSecOps: Criando uma Cultura shift left
evandromohr
0
180
Trabalhando com Escopo Aberto
evandromohr
1
180
Event-driven architecture
evandromohr
0
240
Hacking your PHP application
evandromohr
0
190
Event-Driven Architecture
evandromohr
1
170
Other Decks in Technology
See All in Technology
Nav2、Nav3 ... はたまた自作?〜 作って理解する Nav3 の設計意図 〜 / Nav2, Nav3 ... or Build Your Own? — Understanding Nav3's design intent by building it from scratch
yanzm
0
230
生成AI時代の クレデンシャルとパーミッション設計
nrinetcom
PRO
3
1.5k
推論の観測、できていますか? 〜 Google Cloud Gemini Enterprise Agent Platformで 3つの Gemini モデルを実測して踏んだ、評価の罠 〜
shukob
PRO
0
150
AI時代におけるプロダクト横断勉強会の設計
zozotech
PRO
0
150
[RSJ26] Building a VLA Model Based on Self-Distilled Classification
keio_smilab
PRO
0
190
【視聴者参加型!】AWSセキュリティアンチパターンクイズ
syoshie
0
400
書籍『生成AIの安全性入門』の入門
wataoka
0
210
KAEN Company Deck
kaen
PRO
0
320
Bet AI Day 2026丨バクラク Autopilot、業務システムの再設計
layerx
PRO
2
1.2k
Sony-DroidKaigi2026
sony
1
320
Bet AI Day 2026丨Agentは、「金融」という巨大産業の何を変えられるのか
layerx
PRO
0
770
生成AIのテナント制御とシャドーMCP対策 | AIを"止めずに"、情報を守る
yukun
0
110
Featured
See All Featured
End of SEO as We Know It (SMX Advanced Version)
ipullrank
3
4.4k
Keith and Marios Guide to Fast Websites
keithpitt
413
23k
What’s in a name? Adding method to the madness
productmarketing
PRO
24
4.2k
DBのスキルで生き残る技術 - AI時代におけるテーブル設計の勘所
soudai
PRO
68
57k
For a Future-Friendly Web
brad_frost
183
10k
HU Berlin: Industrial-Strength Natural Language Processing with spaCy and Prodigy
inesmontani
PRO
0
690
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
128
56k
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
590
Leadership Guide Workshop - DevTernity 2021
reverentgeek
1
360
Bash Introduction
62gerente
615
220k
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
3.7k
How People are Using Generative and Agentic AI to Supercharge Their Products, Projects, Services and Value Streams Today
helenjbeal
1
300
Transcript
DevSecOps Delivering secure software at speed and scale of DevOps.
Evandro Mohr 2 Developer Pilot Professor Photographer
“ “DevOps is not a goal, but a never-ending process
of continual improvement” – Jez Humble 3
4 It’s all about bottlenecks
Chaotic Model 5 Fix Build First steps is SDLC
Waterfall Model 6
Waterfall Model ▪ Long release cycles. ▪ Functional silos ▪
Rigid ▪ Lot of WIP 7
The dawn of Agile 8 ▪ Shorter release cycles ▪
Cross functional teams ▪ Smaller batch sizes
DEV X OPS 9
DEV X OPS 10
DevOps 11
12 DevOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
DevOps Pipeline
How to keep up with security? 14
DevSecOps Integrating security into Agile and DevOps 15
“ “DevSecOps enable organisations to deliver inherently secure software at
DevOps scale and speed.” 16
Security Practice Checklist ✓ Verify for security Early and Often
✓ Parameterize Queries ✓ Encode data ✓ Validate All Inputs ✓ Implement Identity and Authentication Controls ✓ Implement Appropriate Access Controls ✓ Protect Data ✓ Implement Logging and Intrusion Detection ✓ Use security frameworks and libraries ✓ Error and Exception Handling
OWASP Top 10
Security Practice Checklist
DevSecOps
“ 21 DevOps security hooks
DevSecOps Trigger Points ✓ Static scanning during development ✓ Pull-requests:
Static scans of data-flow, semantic and configurational ✓ Integration branch: Dynamic scanning ✓ QA Release Candidate Integration: Dynamic scanning ✓ Production Acceptance: Production-safe dynamic scanning ✓ Post-Production: RASP (Runtime Application Self-Protection), WAF (Web Application Firewalls) both need rules updated.
23 DevSecOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
Culture ▪ Communication and transparency ▪ Blameless postmortem ▪ Continuous
improvement ▪ Everyone is responsible for security ▪ Automate as much as possible ▪ Everything as code
Processes Secure SDLC ▪ Training ▪ Requirements ▪ Architecture &
Design ▪ Coding ▪ Testing ▪ Deployment ▪ Post deployment
Processes Security Pipeline ▪ Assessment of critical resource ▪ Reduce
friction ▪ Increase visibility ▪ Each step repeatable ▪ Drive up dependency
Processes Security Pipeline
Technologies ▪ Requirements ▪ Code: IDE plugins, SAST ▪ Test:
Gauntlt, DAST ▪ Configure: Sec as code ▪ Maintenance: Patch management ▪ Monitor: Auditing, Attack visibility
Questions? 29
Thank you very much for your time 30 You can
find me at: ▪ br.linkedin.com/in/evandromohr ▪ t.me/phpcomrapadura