Slide 1

Slide 1 text

Fast-tracking DevSecOps Maturity With Security Chaos Engineering

Slide 2

Slide 2 text

Source: Datadog DevSecOps Maturity Model - DevSecOps Maturity Model White Paper | Datadog (datadoghq.com) Three Important Questions About DevSecOps Maturity 1 . What is your level of DevSecOps Maturity ? 2. Where is your desired level of DevSecOps maturity ? 3. How do you get there ?

Slide 3

Slide 3 text

Technical leaders need a Maturity Model to answer those three questions.

Slide 4

Slide 4 text

“A maturity model is a tool that helps people assess the current effectiveness of a person or group and supports figuring out what capabilities they need to acquire next in order to improve their performance.” - Martin Fowler MaturityModel (martinfowler.com)

Slide 5

Slide 5 text

A Quick Look At Two Relevant Security Maturity Models

Slide 6

Slide 6 text

Maturity Model 01 : Datadog DevSecOps Maturity Model Datadog DevSecOps Maturity Model - DevSecOps Maturity Model White Paper | Datadog (datadoghq.com) Identifies four stages of maturity across six major competency areas

Slide 7

Slide 7 text

Security Chaos Testing is a Requisite For the Operate Competency Across Intermediate, Advanced & Expert Maturity Stages Datadog DevSecOps Maturity Model - DevSecOps Maturity Model White Paper | Datadog (datadoghq.com)

Slide 8

Slide 8 text

The AWS Security Maturity Model is Organized in Phases. AWS Security Maturity Model - Home :: AWS Security Maturity Model Maturity Model 02: The AWS Security Maturity Model

Slide 9

Slide 9 text

Security Chaos Engineering Is Recommended Under Phase 4. This is critical for enabling cyber resilience AWS Security Maturity Model - Home :: AWS Security Maturity Model

Slide 10

Slide 10 text

What is the Value Props of Security Chaos Engineering for DevSecOps? Spoiler Alert : The value proposition is generally applicable to other cyber security domains. Security Chaos Engineering 101: The Mind Map & Feedback Loop (mitigant.io)

Slide 11

Slide 11 text

DORA Metrics • Deployment Frequency • Lead time for changes • Time to restore service • Change failure rate State of the DevOps Report DORA 2022 Accelerate State of DevOps Report now out | Google Cloud Blog These metrics are indicative low, medium and high performing teams.

Slide 12

Slide 12 text

Security Chaos Engineering Leads to Cyber Resilience Leveraging Security Chaos Engineering for Cloud Cyber Resilience - Part I (mitigant.io) High performing security engineering teams are cyber resilient.

Slide 13

Slide 13 text

Seamlessly Fast-track Your DevSecOps Maturity With The Mitigant Security Chaos Engineering Platform Cloud Immunity | Mitigant https://mitigant.io We are here to support you. Be Secure. Be Resilient.