Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Fortify Your DevOps Castle: Security Considerat...
Search
Faith Kovi
November 05, 2023
Technology
0
67
Fortify Your DevOps Castle: Security Considerations and Best Practices for Open-Source Infrastructure
Faith Kovi
November 05, 2023
Tweet
Share
More Decks by Faith Kovi
See All by Faith Kovi
Introduction to Cloud Engineering
faithkovi
0
14
Other Decks in Technology
See All in Technology
Mackerelにおけるインシデント対応とポストモーテム - 現場での工夫と学び
taxin
0
100
[re:Inent2025事前勉強会(有志で開催)] re:Inventで見つけた人生をちょっと変えるコツ
sh_fk2
1
1.2k
Raycast AI APIを使ってちょっと便利なAI拡張機能を作ってみた
kawamataryo
0
230
GTC 2025 : 가속되고 있는 미래
inureyes
PRO
0
150
プロダクト開発と社内データ活用での、BI×AIの現在地 / Data_Findy
sansan_randd
1
760
Boxを“使われる場”にする統制と自動化の仕組み
demaecan
0
100
データとAIで明らかになる、私たちの課題 ~Snowflake MCP,Salesforce MCPに触れて~ / Data and AI Insights
kaonavi
0
230
DSPy入門
tomehirata
6
850
AIでデータ活用を加速させる取り組み / Leveraging AI to accelerate data utilization
okiyuki99
6
1.6k
新米エンジニアをTech Leadに任命する ー 成長を支える挑戦的な人と組織のマネジメント
naopr
1
340
251029 JAWS-UG AI/ML 退屈なことはQDevにやらせよう
otakensh
0
150
20251029_Cursor Meetup Tokyo #02_MK_「あなたのAI、私のシェル」 - プロンプトインジェクションによるエージェントのハイジャック
mk0721
PRO
6
2.3k
Featured
See All Featured
Bootstrapping a Software Product
garrettdimon
PRO
307
110k
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
46
7.7k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.5k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
359
30k
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
37
2.6k
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
16
1.7k
VelocityConf: Rendering Performance Case Studies
addyosmani
333
24k
Rails Girls Zürich Keynote
gr2m
95
14k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
253
22k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
55
3k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
140
34k
Testing 201, or: Great Expectations
jmmastey
46
7.7k
Transcript
FORTIFY YOUR DEVOPS CASTLE: SECURITY CONSIDERATIONS AND BEST PRACTICES FOR
OPEN-SOURCE INFRASTRUCTURE Faith Kovi
Abo Hey there! I'm a DevOps enthusiast with a
passion for making technology work seamlessly. You could call me a bit of a tech writer too; I enjoy simplifying the complex.
QU VEW Conclusion Introduction The Threat landscape Organization Responsibility Importance
of Continuous monitoring and logging Integrating security practices in the DevOps lifecycle
Welcome, Now imagine your DevOps Infrastructure as a Castle. Integrating
security into this castle is of utmost importance. Inodon
Ransomware and extortion Human Error and Insider Threats Regulatory changes
The r anc Zero Day Exploits Open source vulnerabilities Supply chain attacks Advanced Persistent Threats(APT) IoT and Edge Device Vulnerabilities
Imot of Cnu mori n gig Significance of logs Detection
Compliance Forensic
Imot of Cnu mori n gig Best practices for setting
up an effective monitoring and logging system • Security Information and event management(SIEM) tools • Centralized Log collection • Real-time Alerts • Log retention policy • Log encryption • Regular Log reviews
Imot of Cnu mori n gig Examples of Continuous Monitoring
and logging in action Data breach Investigation Malware detection Insider Threat Detection
Inerg er pat in DvO liy Why integrate security
into the DevOps lifecycle? • Early detection of vulnerabilities • Enhanced product quality • Compliance with regulations • Reduced risks and costs
Inerg er pat in DvO liy How to integrate
security into the DevOps lifecycle? Security requirements Security training Security testing Secure coding standards Code reviews
Inerg er pat in DvO liy Benefits of Integrating
security best practices Proactive security Enhanced trust Faster time-to-market Improved collaboration
Orazi Rsosit • Awareness and accountability • Governance and Policies
• Risk assessment and mitigation • Security training and education • Compliance and regulation • Incident response training
Conso 🛡 Congratulations, Guardians of DevOps! 🏰 🔐 Security is
your armor 🤝 Collaboration is your strength 🔄 Adaptation is your Shield
TAK ! @Vera__Kaka Faith Kovi @FaithKovi
[email protected]