Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Savinder_Puri_-_DevSecOps_-_sec_adds_the_glitte...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
Savinder Puri
June 03, 2021
Technology
0
25
Savinder_Puri_-_DevSecOps_-_sec_adds_the_glitter_in_DevSecOps.pdf
Savinder Puri
June 03, 2021
Tweet
Share
More Decks by Savinder Puri
See All by Savinder Puri
DevOps World, 2020
savinderpuri
0
24
DevOpsCon 2020
savinderpuri
0
17
Build__Scale_and_Grow_a_career_in_DevOps.pdf
savinderpuri
0
57
Other Decks in Technology
See All in Technology
AIエージェントを開発しよう!-AgentCore活用の勘所-
yukiogawa
0
170
Kiro IDEのドキュメントを全部読んだので地味だけどちょっと嬉しい機能を紹介する
khmoryz
0
200
M&A 後の統合をどう進めるか ─ ナレッジワーク × Poetics が実践した組織とシステムの融合
kworkdev
PRO
1
480
OWASP Top 10:2025 リリースと 少しの日本語化にまつわる裏話
okdt
PRO
3
820
AI駆動開発を事業のコアに置く
tasukuonizawa
1
280
30万人の同時アクセスに耐えたい!新サービスの盤石なリリースを支える負荷試験 / SRE Kaigi 2026
genda
4
1.3k
SREチームをどう作り、どう育てるか ― Findy横断SREのマネジメント
rvirus0817
0
320
インフラエンジニア必見!Kubernetesを用いたクラウドネイティブ設計ポイント大全
daitak
1
370
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
440
SREのプラクティスを用いた3領域同時 マネジメントへの挑戦 〜SRE・情シス・セキュリティを統合した チーム運営術〜
coconala_engineer
2
670
Claude_CodeでSEOを最適化する_AI_Ops_Community_Vol.2__マーケティングx_AIはここまで進化した.pdf
riku_423
2
600
会社紹介資料 / Sansan Company Profile
sansan33
PRO
15
400k
Featured
See All Featured
CoffeeScript is Beautiful & I Never Want to Write Plain JavaScript Again
sstephenson
162
16k
Accessibility Awareness
sabderemane
0
53
Building Applications with DynamoDB
mza
96
6.9k
The Cost Of JavaScript in 2023
addyosmani
55
9.5k
The Organizational Zoo: Understanding Human Behavior Agility Through Metaphoric Constructive Conversations (based on the works of Arthur Shelley, Ph.D)
kimpetersen
PRO
0
240
Bash Introduction
62gerente
615
210k
The Power of CSS Pseudo Elements
geoffreycrofte
80
6.2k
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
54
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
290
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
Fireside Chat
paigeccino
41
3.8k
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
130
Transcript
Savinder Puri DevOps Evangelist, Zensar Technologies, UK @savinderpuri
[email protected]
Savinder Puri DevOps Evangelist, Zensar Technologies, UK Engineering (Computers), Class
of 2000 Ambassador at DevOps Institute & CDF Published author (Available on Amazon worldwide) Reiki Grandmaster & Angelic Healer YOUR LOGO HERE
None
https://amzn.to/3gu5tu0
None
DevOps LOVES ‘Sec’. It adds the glitter to DevSecOps! Everyone
knows that Security isn’t a real tool/process, it’s a mindset
None
Everywhere that you go, add a bit of ‘sec’! That’s
how you make the security mindset actionable
None
Glitter the entire SDLC!!! PO, UX, Dev, Testers, Ops, Network...
everyone has a part to play!
https://digital.ai/periodic-table-of-devops-tools
https://www.sonatype.com/referencearchitecturetestdrive
None
Why can’t we get our actors together? “loss of control”
DevSecOps will give you the “Andon Cord”!
CI/CD Pipelines + Alerts (thresholds) + Discipline ------------------------------- = Andon
Cord ------------------------------- https://medium.com/@jjruescas/to-improve-pull-the-cord-ec309fa9d701
https://medium.com/@jjruescas/to-improve-pull-the-cord-ec309fa9d701 Jenkins CI/CD pipeline
None
Beware of the “SonarQube Circle!”
None
Follow the iterative approach here... Nothing succeeds like success!
None
With “Compliance-as-code (CaC)”, ‘ sec’ will go everywhere! That’s how
you make the security mindset actionable
https://www.jenkins.io/doc/pipeline/steps/sonar/ Jenkins Pipeline for SonarQube Quality Gate
https://bit.ly/34Ohadd Illustrative example with Qualys (love the representation!); there are
several other toolset options out there
None
Once you get ‘sec’ into the DNA, it just organically
spreads everywhere!
None
THANK YOU! Meet me in the Network Chat Lounge for
questions