Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Fortify Your DevOps Castle: Security Considerat...
Search
Faith Kovi
November 05, 2023
Technology
0
72
Fortify Your DevOps Castle: Security Considerations and Best Practices for Open-Source Infrastructure
Faith Kovi
November 05, 2023
Tweet
Share
More Decks by Faith Kovi
See All by Faith Kovi
Introduction to Cloud Engineering
faithkovi
0
16
Other Decks in Technology
See All in Technology
セキュリティについて学ぶ会 / 2026 01 25 Takamatsu WordPress Meetup
rocketmartue
1
310
データの整合性を保ちたいだけなんだ
shoheimitani
8
3.2k
日本の85%が使う公共SaaSは、どう育ったのか
taketakekaho
1
230
ランサムウェア対策としてのpnpm導入のススメ
ishikawa_satoru
0
210
レガシー共有バッチ基盤への挑戦 - SREドリブンなリアーキテクチャリングの取り組み
tatsukoni
0
220
AzureでのIaC - Bicep? Terraform? それ早く言ってよ会議
torumakabe
1
590
Frontier Agents (Kiro autonomous agent / AWS Security Agent / AWS DevOps Agent) の紹介
msysh
3
180
配列に見る bash と zsh の違い
kazzpapa3
3
160
AIと新時代を切り拓く。これからのSREとメルカリIBISの挑戦
0gm
2
3k
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
10k
学生・新卒・ジュニアから目指すSRE
hiroyaonoe
2
700
プロダクト成長を支える開発基盤とスケールに伴う課題
yuu26
4
1.4k
Featured
See All Featured
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
22k
The SEO Collaboration Effect
kristinabergwall1
0
350
Taking LLMs out of the black box: A practical guide to human-in-the-loop distillation
inesmontani
PRO
3
2k
Leo the Paperboy
mayatellez
4
1.4k
What’s in a name? Adding method to the madness
productmarketing
PRO
24
3.9k
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
231
22k
Believing is Seeing
oripsolob
1
57
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.6k
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
430
Redefining SEO in the New Era of Traffic Generation
szymonslowik
1
220
Bridging the Design Gap: How Collaborative Modelling removes blockers to flow between stakeholders and teams @FastFlow conf
baasie
0
450
Everyday Curiosity
cassininazir
0
130
Transcript
FORTIFY YOUR DEVOPS CASTLE: SECURITY CONSIDERATIONS AND BEST PRACTICES FOR
OPEN-SOURCE INFRASTRUCTURE Faith Kovi
Abo Hey there! I'm a DevOps enthusiast with a
passion for making technology work seamlessly. You could call me a bit of a tech writer too; I enjoy simplifying the complex.
QU VEW Conclusion Introduction The Threat landscape Organization Responsibility Importance
of Continuous monitoring and logging Integrating security practices in the DevOps lifecycle
Welcome, Now imagine your DevOps Infrastructure as a Castle. Integrating
security into this castle is of utmost importance. Inodon
Ransomware and extortion Human Error and Insider Threats Regulatory changes
The r anc Zero Day Exploits Open source vulnerabilities Supply chain attacks Advanced Persistent Threats(APT) IoT and Edge Device Vulnerabilities
Imot of Cnu mori n gig Significance of logs Detection
Compliance Forensic
Imot of Cnu mori n gig Best practices for setting
up an effective monitoring and logging system • Security Information and event management(SIEM) tools • Centralized Log collection • Real-time Alerts • Log retention policy • Log encryption • Regular Log reviews
Imot of Cnu mori n gig Examples of Continuous Monitoring
and logging in action Data breach Investigation Malware detection Insider Threat Detection
Inerg er pat in DvO liy Why integrate security
into the DevOps lifecycle? • Early detection of vulnerabilities • Enhanced product quality • Compliance with regulations • Reduced risks and costs
Inerg er pat in DvO liy How to integrate
security into the DevOps lifecycle? Security requirements Security training Security testing Secure coding standards Code reviews
Inerg er pat in DvO liy Benefits of Integrating
security best practices Proactive security Enhanced trust Faster time-to-market Improved collaboration
Orazi Rsosit • Awareness and accountability • Governance and Policies
• Risk assessment and mitigation • Security training and education • Compliance and regulation • Incident response training
Conso 🛡 Congratulations, Guardians of DevOps! 🏰 🔐 Security is
your armor 🤝 Collaboration is your strength 🔄 Adaptation is your Shield
TAK ! @Vera__Kaka Faith Kovi @FaithKovi
[email protected]