Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DevSecOps: Delivering secure software at speed ...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
Evandro Mohr
June 08, 2019
Technology
340
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
DevSecOps: Delivering secure software at speed and scale of DevOps
Evandro Mohr
June 08, 2019
More Decks by Evandro Mohr
See All by Evandro Mohr
DevSecOps: Criando uma Cultura shift left
evandromohr
0
180
Trabalhando com Escopo Aberto
evandromohr
1
180
Event-driven architecture
evandromohr
0
240
Hacking your PHP application
evandromohr
0
190
Event-Driven Architecture
evandromohr
1
170
Other Decks in Technology
See All in Technology
Guerilla InnerSource in enterprises, during the AI hype
onenashev
PRO
0
130
bet_ai_day_2026_session02
agenticsec
1
690
Introduction to Sansan for Engineers / エンジニア向け会社紹介
sansan33
PRO
6
77k
Genie Code ワークショップ 応用編 / Genie-Code-Workshop-advanced
databricksjapan
PRO
0
250
現場の暗黙知を継承するAIエージェント — 対話から生まれる長期記憶と Skills
atsukish
0
220
[RSJ26] Building a VLA Model Based on Self-Distilled Classification
keio_smilab
PRO
0
170
Level Up Your CDK DX: 5 Tools I’ve Been Building
gotok365
2
180
いま好きなこと 最初はそんなに好きじゃなかった #tamagawadev
nishiuma
1
200
書籍『生成AIの安全性入門』の入門
wataoka
0
150
PM領域でのAI Agentの活用
lycorptech_jp
PRO
0
220
少人数データチームのDevin活用実践事例
runandy16
2
300
Introduction to Sansan Meishi Maker Development Engineer
sansan33
PRO
0
470
Featured
See All Featured
Google's AI Overviews - The New Search
badams
0
1.6k
Leading Effective Engineering Teams in the AI Era
addyosmani
9
2.5k
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
830
Between Models and Reality
mayunak
4
430
Stewardship and Sustainability of Urban and Community Forests
pwiseman
0
500
Deep Space Network (abreviated)
tonyrice
0
280
WCS-LA-2024
lcolladotor
0
820
The #1 spot is gone: here's how to win anyway
tamaranovitovic
3
1.1k
[SF Ruby Conf 2025] Rails X
palkan
2
1.3k
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
Leveraging LLMs for student feedback in introductory data science courses - posit::conf(2025)
minecr
1
370
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
510
Transcript
DevSecOps Delivering secure software at speed and scale of DevOps.
Evandro Mohr 2 Developer Pilot Professor Photographer
“ “DevOps is not a goal, but a never-ending process
of continual improvement” – Jez Humble 3
4 It’s all about bottlenecks
Chaotic Model 5 Fix Build First steps is SDLC
Waterfall Model 6
Waterfall Model ▪ Long release cycles. ▪ Functional silos ▪
Rigid ▪ Lot of WIP 7
The dawn of Agile 8 ▪ Shorter release cycles ▪
Cross functional teams ▪ Smaller batch sizes
DEV X OPS 9
DEV X OPS 10
DevOps 11
12 DevOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
DevOps Pipeline
How to keep up with security? 14
DevSecOps Integrating security into Agile and DevOps 15
“ “DevSecOps enable organisations to deliver inherently secure software at
DevOps scale and speed.” 16
Security Practice Checklist ✓ Verify for security Early and Often
✓ Parameterize Queries ✓ Encode data ✓ Validate All Inputs ✓ Implement Identity and Authentication Controls ✓ Implement Appropriate Access Controls ✓ Protect Data ✓ Implement Logging and Intrusion Detection ✓ Use security frameworks and libraries ✓ Error and Exception Handling
OWASP Top 10
Security Practice Checklist
DevSecOps
“ 21 DevOps security hooks
DevSecOps Trigger Points ✓ Static scanning during development ✓ Pull-requests:
Static scans of data-flow, semantic and configurational ✓ Integration branch: Dynamic scanning ✓ QA Release Candidate Integration: Dynamic scanning ✓ Production Acceptance: Production-safe dynamic scanning ✓ Post-Production: RASP (Runtime Application Self-Protection), WAF (Web Application Firewalls) both need rules updated.
23 DevSecOps Culture Principles and Practices Processes Automated deployment pipeline
Technologies Supporting tool chain
Culture ▪ Communication and transparency ▪ Blameless postmortem ▪ Continuous
improvement ▪ Everyone is responsible for security ▪ Automate as much as possible ▪ Everything as code
Processes Secure SDLC ▪ Training ▪ Requirements ▪ Architecture &
Design ▪ Coding ▪ Testing ▪ Deployment ▪ Post deployment
Processes Security Pipeline ▪ Assessment of critical resource ▪ Reduce
friction ▪ Increase visibility ▪ Each step repeatable ▪ Drive up dependency
Processes Security Pipeline
Technologies ▪ Requirements ▪ Code: IDE plugins, SAST ▪ Test:
Gauntlt, DAST ▪ Configure: Sec as code ▪ Maintenance: Patch management ▪ Monitor: Auditing, Attack visibility
Questions? 29
Thank you very much for your time 30 You can
find me at: ▪ br.linkedin.com/in/evandromohr ▪ t.me/phpcomrapadura