DevSecOps: Build It, Secure It, Run It

Where Does Security Belong in DevOps?

Modern architectures and design patterns challenge developers, security, and operations in a whole new way. Instead of developers building and handing to security for testing, today’s developers are a key part of the security team - and vice versa.

In this Modern Security Series episode, we look at how security:

Shifts left - earlier into the development cycle
Shifts right - integrating with operations
Adapts to enable app and service owners to respond faster to threats


May 01, 2018

  The DevSecOps View: Build It, Secure It, Run It

  Industry Movement That DevOps thing you keep hearing about

  Two Shifts + Adaptation

  Security Shifts Left! ... earlier into the development cycle

  Security Shifts Right! ... integrating with operations

  Security Adapts! ... to enable app and service owners to respond faster to threats

  DevOps An approach to our work where we continuously look

    for methods to evaluate and improve the technology, process, and people as they relate to building, deploying, operating, securing, and supporting the value our organization provides.
  "Many security teams work with a worldview where their goal

  19. Companies are spending a great deal on security, but we

  Clearly something is wrong. The root of the problem is

    twofold: we're protecting the wrong things, and we're hurting productivity in the process. — Steven M. Bellovin
  The Past Embrace Secrecy Build a Wall Test when Done Certainty Testing

  The best way to predict the future is to invent it

  The Future Embrace Feedback Loops Zero Trust Networks Shift Left Adversity Testing

    Adversity Tes=ng @jasonhand | @wicke0
  New Challenges

  What is Security's new place in the delivery pipeline?

  GDPR General Data Protection Regulation Enforcement Begins: May 25th, 2018

    @jasonhand | @wicke0
  Shifts left ... earlier into the development cycle

  3 Shifts left Design Inheritance Testing

  41. Design for the Bad Guys Use Evil User Stories and

    have security tests being wri7en with other unit tests or whatever tes8ng pa7erns you use: TDD, BDD, ATDD, … @jasonhand | @wicke0
  New School Security Design Mozilla Rapid Risk Assessment link OWASP App Threat Modeling Cheat Sheet link

    App Threat Modeling Cheat Sheet link @jasonhand | @wicke0
  We Inherit our Problems Heartbleed, shellshock, ... We forget our real LOC

    real LOC @jasonhand | @wicke0
  Toolchain for Inheritance testing OWASP Dependency Checker Retire.js link Publish a BOM Git-secrets from awslabs link

    a BOM Git-secrets from awslabs link @jasonhand | @wicke0
  45. Security Tes,ng for Developers Code Standards and security tooling runs

    on developer laptops and systems, but also verified by CI system. @jasonhand | @wicke0
  46. The goal should be to come up with a set

    of automated tests that probe and check security configura9ons and run9me system behavior for security features that will execute every 9me the system is built and every 9me it is deployed. @jasonhand | @wicke0
  48. Gauntlt Framework with Security tes2ng wri5en in a natural language

    that developers, security and opera2ons can understand. @jasonhand | @wicke0
  50. Gauntlt Gauntlt wraps security tes0ng tools to be part of

    the CI/CD pipeline Open source, MIT License, gauntlt.org @jasonhand | @wicke0
  51. We have saved millions of dollars using Gauntlt for the

    largest healthcare industry project. — Aaron Rinehart, UnitedHealthCare @jasonhand | @wicke0
  Lynda.com Security Testing Course link

  Shifts right ... integrating with operations

  62. Detect What Ma*ers Account takeover a-empts Areas of the site

    under a-ack Most likely vectors of a-ack Business logic flows Abuse and Misuse @jasonhand | @wicke0
  IT Performance Metrics Deployment Frequency Lead Time For Changes MTTR Change Failure Rate Cycle Time

  Takeaways Shifts & Adaptations Proactive Observability Collaborative

  Takeaways Learning Performance Metrics Governance Continuous

  jhand.co/SREBook jhand.co/PIRBook jhand.co/ChatOpsBook

  info.signalsciences.com/appsec-defense-needs-top-five

  Lynda.com https://www.lynda.com/Software-Development-tutorials/Security-Testing/667367-2.html