Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Fortify Your DevOps Castle: Security Considerat...
Search
Faith Kovi
November 05, 2023
Technology
73
0
Share
Fortify Your DevOps Castle: Security Considerations and Best Practices for Open-Source Infrastructure
Faith Kovi
November 05, 2023
More Decks by Faith Kovi
See All by Faith Kovi
Introduction to Cloud Engineering
faithkovi
0
17
Other Decks in Technology
See All in Technology
自分をひらくと次のチャレンジの敷居が下がる
sudoakiy
5
1.6k
OCI技術資料 : 証明書サービス概要
ocise
1
7.2k
Datadog で実現するセキュリティ対策 ~オブザーバビリティとセキュリティを 一緒にやると何がいいのか~
a2ush
0
180
制約を設計する - 非決定性との境界線 / Designing constraints
soudai
PRO
4
740
Embeddings : Symfony AI en pratique
lyrixx
0
440
サイボウズ 開発本部採用ピッチ / Cybozu Engineer Recruit
cybozuinsideout
PRO
10
77k
CloudFrontのHost Header転送設定でパケットの中身はどう変わるのか?
nagisa53
1
240
遊びで始めたNew Relic MCP、気づいたらChatOpsなオブザーバビリティボットができてました/From New Relic MCP to a ChatOps Observability Bot
aeonpeople
1
150
Bill One 開発エンジニア 紹介資料
sansan33
PRO
5
18k
How to install a gem
indirect
0
2.1k
【Oracle Cloud ウェビナー】データ主権はクラウドで守れるのか?NTTデータ様のOracle Alloyで実現するソブリン対応クラウドの最適解
oracle4engineer
PRO
3
130
FlutterでPiP再生を実装した話
s9a17
0
240
Featured
See All Featured
Are puppies a ranking factor?
jonoalderson
1
3.2k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.9k
Prompt Engineering for Job Search
mfonobong
0
240
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
250
Data-driven link building: lessons from a $708K investment (BrightonSEO talk)
szymonslowik
1
990
Information Architects: The Missing Link in Design Systems
soysaucechin
0
860
For a Future-Friendly Web
brad_frost
183
10k
Docker and Python
trallard
47
3.8k
Game over? The fight for quality and originality in the time of robots
wayneb77
1
150
Ruling the World: When Life Gets Gamed
codingconduct
0
190
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
254
22k
Why Our Code Smells
bkeepers
PRO
340
58k
Transcript
FORTIFY YOUR DEVOPS CASTLE: SECURITY CONSIDERATIONS AND BEST PRACTICES FOR
OPEN-SOURCE INFRASTRUCTURE Faith Kovi
Abo Hey there! I'm a DevOps enthusiast with a
passion for making technology work seamlessly. You could call me a bit of a tech writer too; I enjoy simplifying the complex.
QU VEW Conclusion Introduction The Threat landscape Organization Responsibility Importance
of Continuous monitoring and logging Integrating security practices in the DevOps lifecycle
Welcome, Now imagine your DevOps Infrastructure as a Castle. Integrating
security into this castle is of utmost importance. Inodon
Ransomware and extortion Human Error and Insider Threats Regulatory changes
The r anc Zero Day Exploits Open source vulnerabilities Supply chain attacks Advanced Persistent Threats(APT) IoT and Edge Device Vulnerabilities
Imot of Cnu mori n gig Significance of logs Detection
Compliance Forensic
Imot of Cnu mori n gig Best practices for setting
up an effective monitoring and logging system • Security Information and event management(SIEM) tools • Centralized Log collection • Real-time Alerts • Log retention policy • Log encryption • Regular Log reviews
Imot of Cnu mori n gig Examples of Continuous Monitoring
and logging in action Data breach Investigation Malware detection Insider Threat Detection
Inerg er pat in DvO liy Why integrate security
into the DevOps lifecycle? • Early detection of vulnerabilities • Enhanced product quality • Compliance with regulations • Reduced risks and costs
Inerg er pat in DvO liy How to integrate
security into the DevOps lifecycle? Security requirements Security training Security testing Secure coding standards Code reviews
Inerg er pat in DvO liy Benefits of Integrating
security best practices Proactive security Enhanced trust Faster time-to-market Improved collaboration
Orazi Rsosit • Awareness and accountability • Governance and Policies
• Risk assessment and mitigation • Security training and education • Compliance and regulation • Incident response training
Conso 🛡 Congratulations, Guardians of DevOps! 🏰 🔐 Security is
your armor 🤝 Collaboration is your strength 🔄 Adaptation is your Shield
TAK ! @Vera__Kaka Faith Kovi @FaithKovi
[email protected]