Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Fortify Your DevOps Castle: Security Considerat...
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Faith Kovi
November 05, 2023
Technology
0
72
Fortify Your DevOps Castle: Security Considerations and Best Practices for Open-Source Infrastructure
Faith Kovi
November 05, 2023
Tweet
Share
More Decks by Faith Kovi
See All by Faith Kovi
Introduction to Cloud Engineering
faithkovi
0
16
Other Decks in Technology
See All in Technology
What happened to RubyGems and what can we learn?
mikemcquaid
0
310
超初心者からでも大丈夫!オープンソース半導体の楽しみ方〜今こそ!オレオレチップをつくろう〜
keropiyo
0
120
AWS Network Firewall Proxyを触ってみた
nagisa53
1
240
コンテナセキュリティの最新事情 ~ 2026年版 ~
kyohmizu
2
700
[CV勉強会@関東 World Model 読み会] Orbis: Overcoming Challenges of Long-Horizon Prediction in Driving World Models (Mousakhan+, NeurIPS 2025)
abemii
0
150
Claude_CodeでSEOを最適化する_AI_Ops_Community_Vol.2__マーケティングx_AIはここまで進化した.pdf
riku_423
2
610
SchooでVue.js/Nuxtを技術選定している理由
yamanoku
3
160
外部キー制約の知っておいて欲しいこと - RDBMSを正しく使うために必要なこと / FOREIGN KEY Night
soudai
PRO
12
5.6k
Ruby版 JSXのRuxが気になる
sansantech
PRO
0
160
Context Engineeringが企業で不可欠になる理由
hirosatogamo
PRO
3
630
SREじゃなかった僕らがenablingを通じて「SRE実践者」になるまでのリアル / SRE Kaigi 2026
aeonpeople
6
2.5k
【Ubie】AIを活用した広告アセット「爆速」生成事例 | AI_Ops_Community_Vol.2
yoshiki_0316
1
110
Featured
See All Featured
State of Search Keynote: SEO is Dead Long Live SEO
ryanjones
0
120
More Than Pixels: Becoming A User Experience Designer
marktimemedia
3
320
The Spectacular Lies of Maps
axbom
PRO
1
520
SEO Brein meetup: CTRL+C is not how to scale international SEO
lindahogenes
0
2.3k
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
1
130
How to train your dragon (web standard)
notwaldorf
97
6.5k
XXLCSS - How to scale CSS and keep your sanity
sugarenia
249
1.3M
Breaking role norms: Why Content Design is so much more than writing copy - Taylor Woolridge
uxyall
0
170
Chrome DevTools: State of the Union 2024 - Debugging React & Beyond
addyosmani
10
1.1k
Designing for Timeless Needs
cassininazir
0
130
Utilizing Notion as your number one productivity tool
mfonobong
3
220
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
380
Transcript
FORTIFY YOUR DEVOPS CASTLE: SECURITY CONSIDERATIONS AND BEST PRACTICES FOR
OPEN-SOURCE INFRASTRUCTURE Faith Kovi
Abo Hey there! I'm a DevOps enthusiast with a
passion for making technology work seamlessly. You could call me a bit of a tech writer too; I enjoy simplifying the complex.
QU VEW Conclusion Introduction The Threat landscape Organization Responsibility Importance
of Continuous monitoring and logging Integrating security practices in the DevOps lifecycle
Welcome, Now imagine your DevOps Infrastructure as a Castle. Integrating
security into this castle is of utmost importance. Inodon
Ransomware and extortion Human Error and Insider Threats Regulatory changes
The r anc Zero Day Exploits Open source vulnerabilities Supply chain attacks Advanced Persistent Threats(APT) IoT and Edge Device Vulnerabilities
Imot of Cnu mori n gig Significance of logs Detection
Compliance Forensic
Imot of Cnu mori n gig Best practices for setting
up an effective monitoring and logging system • Security Information and event management(SIEM) tools • Centralized Log collection • Real-time Alerts • Log retention policy • Log encryption • Regular Log reviews
Imot of Cnu mori n gig Examples of Continuous Monitoring
and logging in action Data breach Investigation Malware detection Insider Threat Detection
Inerg er pat in DvO liy Why integrate security
into the DevOps lifecycle? • Early detection of vulnerabilities • Enhanced product quality • Compliance with regulations • Reduced risks and costs
Inerg er pat in DvO liy How to integrate
security into the DevOps lifecycle? Security requirements Security training Security testing Secure coding standards Code reviews
Inerg er pat in DvO liy Benefits of Integrating
security best practices Proactive security Enhanced trust Faster time-to-market Improved collaboration
Orazi Rsosit • Awareness and accountability • Governance and Policies
• Risk assessment and mitigation • Security training and education • Compliance and regulation • Incident response training
Conso 🛡 Congratulations, Guardians of DevOps! 🏰 🔐 Security is
your armor 🤝 Collaboration is your strength 🔄 Adaptation is your Shield
TAK ! @Vera__Kaka Faith Kovi @FaithKovi
[email protected]