Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
DevSecOps Best Practices- Secure Everything You Have
Search
Sena Yakut
April 21, 2024
0
93
DevSecOps Best Practices- Secure Everything You Have
Sena Yakut
April 21, 2024
Tweet
Share
More Decks by Sena Yakut
See All by Sena Yakut
Securing The Sky Strategies For Protecting Against Cloud Hacking
senayakut
0
67
Cloud Security From Scratch
senayakut
0
66
Cloud Security 101: Ultimate weapon against cyber threats
senayakut
0
92
Journey to the Cloud: An Introduction and Security Overview
senayakut
0
20
Explore Ten Ways to Secure The Cloud
senayakut
0
38
PartyRock-Your Security Supporters
senayakut
0
32
AWS_Security_Best_Practices.pdf
senayakut
0
570
Exploring Cloud Security in the Landscape of Future Technologies
senayakut
0
30
Are Your APIs Really Secure? Are You Sure?
senayakut
0
23
Featured
See All Featured
Building Better People: How to give real-time feedback that sticks.
wjessup
356
18k
Learning to Love Humans: Emotional Interface Design
aarron
267
39k
Code Reviewing Like a Champion
maltzj
515
39k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
660
120k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
14
8.4k
How GitHub Uses GitHub to Build GitHub
holman
468
290k
What’s in a name? Adding method to the madness
productmarketing
PRO
17
2.7k
What the flash - Photography Introduction
edds
64
11k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
34
8.9k
Visualization
eitanlees
137
14k
jQuery: Nuts, Bolts and Bling
dougneiner
60
7.2k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
21
1.6k
Transcript
DevSecOps Best Practices: Secure Everything You Have April 20, 2024
Sena Yakut
About me! DevSecOps Best Practices: Secure Everything You Have Sena
Yakut Senior Cloud Security Engineer senayakut.com sena_yakutt sena-yakut Lyrebird Studio
Agenda My Recommendations What, Why and How? Secure in Every
Step
We don't live in a perfect world. Even the smallest
thing you do is worth its weight in gold.
We need lots of people to do all of these.
Do whatever you can.
We do not focus on tools. You can choose whatever
you want. Your architecture, Your team, Your budget
Plan - Threat modeling, - Secure code standards, - IDE
plugins
Plan You can read my blog: Use Amazon CodeWhisperer for
Your AWS Security
Code - Static Application Security Testing (SAST), - Software Composition
Analysis, - Supply Chain Attacks, - Secure Pipelines, - Secret Scanning
Code Static Application Security Testing (SAST)
Code Software Composition Analysis
Code Software Composition Analysis
Code Secret Scanning
Build and Test - Dynamic Application Security Testing (DAST): Mobile
apps, web apps - Cloud Configuration Checks, - Vulnerability Management, - Penetration Testing, - API Testing
Build and Test
Build and Test
Release and Deploy -Access management -Live site pentesting -Configuration checks
Operate and Monitor - Alerts and Monitoring, - Threat Intelligence,
- Log Analysis, - Asset Inventory and Monitoring
Operate and Monitor
Operate and Monitor
Cultural Aspect -Automation alone will not solve the problems. -Encourage
your security mindset. -Avoid the blame game. -Build relationships with teams, don’t isolate.
DevSecOps Best Practices: Secure Everything You Have Sena Yakut Senior
Cloud Security Engineer senayakut.com sena_yakutt sena-yakut Lyrebird Studio