Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DevSecOps - Vom Unikum zur gut geölten Maschine
Search
Nicolas Byl
December 08, 2021
Technology
0
79
DevSecOps - Vom Unikum zur gut geölten Maschine
Nicolas Byl
December 08, 2021
Tweet
Share
More Decks by Nicolas Byl
See All by Nicolas Byl
Die Flucht aus der Prototypen-Hölle
nbyl
0
27
Lean Prototyping for Industrial-IoT Projects
nbyl
0
19
Securing your software supply chain
nbyl
0
290
Keeping-Up-WithUpstream.pdf
nbyl
0
100
Dr. Kube und der Helm - Anatomie einer CD-Pipeline
nbyl
0
89
Securing the "other" supply chain
nbyl
0
210
Kubernetes - Auf die Cluster, Fertig, Los!
nbyl
0
130
Helm - Kubernetes Deployments richtig gemacht
nbyl
0
100
It's the developers, stupid!
nbyl
0
130
Other Decks in Technology
See All in Technology
手軽に始める? おうちサーバーのすゝめ
nyagasan
0
190
FastConnect の冗長性
ocise
0
7.2k
AI活用したくてもできなかった不動産SaaSの今とこれから
nealle
0
220
Mocking in Rust Applications
taiki45
1
350
Segment Anything Model 2
tenten0727
2
490
PDF Viewer作成の今までとこれから
hunachi
0
250
LandingZoneAccelerator と学ぶ 「スケーラブルで安全なマルチアカウントAWS環境」と 私たちにもできるベストプラクティス
maimyyym
1
120
タイミーのBraze活用 ~PUSH通知を活用したレコメンド~
ozeshun
2
150
Towards Effortless Transaction Management in Microservices @KubeDay Japan 2024
scalar
1
100
「家族アルバム みてね」における運用管理・ オブザーバビリティの全貌 / Overview of Operation Management and Observability in FamilyAlbum
isaoshimizu
4
140
Envoy External AuthZとgRPC Extensionを利用した「頑張らない」Microservices認証認可基盤
andoshin11
0
210
効果的なオンコール対応と障害対応
ryuichi1208
5
2.4k
Featured
See All Featured
Designing with Data
zakiwarfel
98
5k
Optimizing for Happiness
mojombo
375
69k
BBQ
matthewcrist
83
9.1k
Adopting Sorbet at Scale
ufuk
73
8.9k
Atom: Resistance is Futile
akmur
261
25k
Documentation Writing (for coders)
carmenintech
65
4.3k
WebSockets: Embracing the real-time Web
robhawkes
59
7.3k
Statistics for Hackers
jakevdp
793
220k
jQuery: Nuts, Bolts and Bling
dougneiner
61
7.4k
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
230
17k
Code Review Best Practice
trishagee
62
16k
Building a Modern Day E-commerce SEO Strategy
aleyda
35
6.8k
Transcript
1 NICOLAS BYL DEVSECOPS VOM UNIKUM ZUR GUT GEÖLTEN MASCHINE
2 INTRODUCTION
3 THE DEVSECOPS CYCLE
4 THE CASTLE ILLUSION
5 THE DEVSECOPS CYCLE
6 THE DEVSECOPS CYCLE
7 SECURE ARCHITECTURE
8 THREAT MODELLING
9 COMPLIANCE
10 PENTESTS
11 THE DEVSECOPS CYCLE
12 DESIGN PATTERNS
13 PRE-COMMIT HOOKS
14 CODE REVIEWS
15 COMMIT SIGNING
16 THE DEVSECOPS CYCLE
17 THE DEPENDENCY ICEBERG
18 AUTOMATION IS KING SOURCE CODE ANALYSIS • FindBugs •
SonarQube • SAST • DAST SOURCE CODE ANALYSIS DEPENDENCY ANALYSIS • Maven, npm, ... • Container Images • Operating System Packages UPDATE AUTOMATION • npm audit • Dependabot • Renovate
19 THE DEVSECOPS CYCLE
20 POLICY OVER CHECKLISTS
21 THE KEY TO THE KINGDOM
22 ZERO-TRUST DEPLOYMENT
23 ROLLER COASTER PASSWORDS
24 INVENTORY SCANS
25 FIRE DRILLS & CHAOS ENGINEERING
26 HOW TO GET IN TOUCH
[email protected]
@ClusterBauer https://www.nexineer.io/career/ WE
ARE ALWAYS LOOKING FOR GREAT COLLEAGUES…
27 PATCHING Sicheres Artefakt Artefakt mit bekannter Schwachstelle Scanning Patching