Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Savinder_Puri_-_DevSecOps_-_sec_adds_the_glitte...
Search
Savinder Puri
June 03, 2021
Technology
0
15
Savinder_Puri_-_DevSecOps_-_sec_adds_the_glitter_in_DevSecOps.pdf
Savinder Puri
June 03, 2021
Tweet
Share
More Decks by Savinder Puri
See All by Savinder Puri
DevOps World, 2020
savinderpuri
0
20
DevOpsCon 2020
savinderpuri
0
14
Build__Scale_and_Grow_a_career_in_DevOps.pdf
savinderpuri
0
45
Other Decks in Technology
See All in Technology
IBC 2024 動画技術関連レポート / IBC 2024 Report
cyberagentdevelopers
PRO
1
120
オープンソースAIとは何か? --「オープンソースAIの定義 v1.0」詳細解説
shujisado
10
1.4k
【Pycon mini 東海 2024】Google Colaboratoryで試すVLM
kazuhitotakahashi
2
570
静的解析で実現した効率的なi18n対応の仕組みづくり
minako__ph
1
160
初心者向けAWS Securityの勉強会mini Security-JAWSを9ヶ月ぐらい実施してきての近況
cmusudakeisuke
0
140
OCI Vault 概要
oracle4engineer
PRO
0
9.7k
Making your applications cross-environment - OSCG 2024 NA
salaboy
0
200
安心してください、日本語使えますよ―Ubuntu日本語Remix提供休止に寄せて― 2024-11-17
nobutomurata
1
1k
SDN の Hype Cycle を一通り経験してみて思うこと / Going through the Hype Cycle of SDN
mshindo
1
180
Amazon CloudWatch Network Monitor のススメ
yuki_ink
1
210
rootlessコンテナのすゝめ - 研究室サーバーでもできる安全なコンテナ管理
kitsuya0828
3
390
AWS Lambda のトラブルシュートをしていて思うこと
kazzpapa3
2
200
Featured
See All Featured
Put a Button on it: Removing Barriers to Going Fast.
kastner
59
3.5k
Building an army of robots
kneath
302
43k
Mobile First: as difficult as doing things right
swwweet
222
8.9k
Fireside Chat
paigeccino
34
3k
The MySQL Ecosystem @ GitHub 2015
samlambert
250
12k
Being A Developer After 40
akosma
87
590k
Embracing the Ebb and Flow
colly
84
4.5k
Large-scale JavaScript Application Architecture
addyosmani
510
110k
Rebuilding a faster, lazier Slack
samanthasiow
79
8.7k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
280
13k
GraphQLとの向き合い方2022年版
quramy
43
13k
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
25
1.8k
Transcript
Savinder Puri DevOps Evangelist, Zensar Technologies, UK @savinderpuri
[email protected]
Savinder Puri DevOps Evangelist, Zensar Technologies, UK Engineering (Computers), Class
of 2000 Ambassador at DevOps Institute & CDF Published author (Available on Amazon worldwide) Reiki Grandmaster & Angelic Healer YOUR LOGO HERE
None
https://amzn.to/3gu5tu0
None
DevOps LOVES ‘Sec’. It adds the glitter to DevSecOps! Everyone
knows that Security isn’t a real tool/process, it’s a mindset
None
Everywhere that you go, add a bit of ‘sec’! That’s
how you make the security mindset actionable
None
Glitter the entire SDLC!!! PO, UX, Dev, Testers, Ops, Network...
everyone has a part to play!
https://digital.ai/periodic-table-of-devops-tools
https://www.sonatype.com/referencearchitecturetestdrive
None
Why can’t we get our actors together? “loss of control”
DevSecOps will give you the “Andon Cord”!
CI/CD Pipelines + Alerts (thresholds) + Discipline ------------------------------- = Andon
Cord ------------------------------- https://medium.com/@jjruescas/to-improve-pull-the-cord-ec309fa9d701
https://medium.com/@jjruescas/to-improve-pull-the-cord-ec309fa9d701 Jenkins CI/CD pipeline
None
Beware of the “SonarQube Circle!”
None
Follow the iterative approach here... Nothing succeeds like success!
None
With “Compliance-as-code (CaC)”, ‘ sec’ will go everywhere! That’s how
you make the security mindset actionable
https://www.jenkins.io/doc/pipeline/steps/sonar/ Jenkins Pipeline for SonarQube Quality Gate
https://bit.ly/34Ohadd Illustrative example with Qualys (love the representation!); there are
several other toolset options out there
None
Once you get ‘sec’ into the DNA, it just organically
spreads everywhere!
None
THANK YOU! Meet me in the Network Chat Lounge for
questions