Upgrade to Pro — share decks privately, control downloads, hide ads and more …

DevSecOps - Vom Unikum zur gut geölten Maschine

Nicolas Byl
December 08, 2021

DevSecOps - Vom Unikum zur gut geölten Maschine

Nicolas Byl

December 08, 2021
Tweet

More Decks by Nicolas Byl

Other Decks in Technology

Transcript

  1. 1
    NICOLAS BYL
    DEVSECOPS
    VOM UNIKUM ZUR GUT GEÖLTEN
    MASCHINE

    View Slide

  2. 2
    INTRODUCTION

    View Slide

  3. 3
    THE DEVSECOPS CYCLE

    View Slide

  4. 4
    THE CASTLE ILLUSION

    View Slide

  5. 5
    THE DEVSECOPS CYCLE

    View Slide

  6. 6
    THE DEVSECOPS CYCLE

    View Slide

  7. 7
    SECURE ARCHITECTURE

    View Slide

  8. 8
    THREAT MODELLING

    View Slide

  9. 9
    COMPLIANCE

    View Slide

  10. 10
    PENTESTS

    View Slide

  11. 11
    THE DEVSECOPS CYCLE

    View Slide

  12. 12
    DESIGN PATTERNS

    View Slide

  13. 13
    PRE-COMMIT HOOKS

    View Slide

  14. 14
    CODE REVIEWS

    View Slide

  15. 15
    COMMIT SIGNING

    View Slide

  16. 16
    THE DEVSECOPS CYCLE

    View Slide

  17. 17
    THE DEPENDENCY ICEBERG

    View Slide

  18. 18
    AUTOMATION IS KING
    SOURCE CODE ANALYSIS
    • FindBugs
    • SonarQube
    • SAST
    • DAST
    SOURCE CODE ANALYSIS
    DEPENDENCY ANALYSIS
    • Maven, npm, ...
    • Container Images
    • Operating System
    Packages
    UPDATE AUTOMATION
    • npm audit
    • Dependabot
    • Renovate

    View Slide

  19. 19
    THE DEVSECOPS CYCLE

    View Slide

  20. 20
    POLICY OVER CHECKLISTS

    View Slide

  21. 21
    THE KEY TO THE KINGDOM

    View Slide

  22. 22
    ZERO-TRUST DEPLOYMENT

    View Slide

  23. 23
    ROLLER COASTER
    PASSWORDS

    View Slide

  24. 24
    INVENTORY SCANS

    View Slide

  25. 25
    FIRE DRILLS & CHAOS
    ENGINEERING

    View Slide

  26. 26
    HOW TO GET IN TOUCH
    [email protected]
    @ClusterBauer
    https://www.nexineer.io/career/
    WE ARE ALWAYS LOOKING FOR GREAT COLLEAGUES…

    View Slide

  27. 27
    PATCHING
    Sicheres Artefakt
    Artefakt
    mit bekannter
    Schwachstelle
    Scanning
    Patching

    View Slide