devseccon london 2017: how far left do you want to go with security? by javier salado

15
Join the conversation #DevSecCon BY JAVIER SALADO How far left do you want to go with Security?

Upload: devseccon-limited

Post on 21-Jan-2018

136 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Join the conversation #DevSecCon

BY JAVIER SALADO

How far left do you want to

go with Security?

Page 2: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Oh no! Yet another “shift left” presentation…

Page 3: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

So… how far left should we go with security?

Page 4: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

“Classical” Software development Life Cycle

Analysis Design Testing Deployment Coding

Time

Page 5: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Here comes Agile and DevOps to the rescue

Page 6: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Here comes Agile and DevOps to the rescue

Page 7: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Enterprise security is still a silo

Page 8: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

DevSecOps: No more silos, all hands on deck

Page 9: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

DevSecOps Security Policy

Security & QA review

Application Security protection

Defects & Vulnerabilities Fix Plan

Security Audit

Security flaws analytics

Update Baseline: New Starting Point

Redefine security policy

Security & QA review

Security & QA review

Page 10: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Tools + automation = integration

Page 11: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Integration Security Policy

Security & QA review IDE + CI

Application Security protection Issue tracker

Defects & Vulnerabilities Fix Plan Issue tracker

Security Audit CD

Security flaws analytics Issue tracker

Update Baseline: New Starting Point CD

Redefine security policy

Manual task

Security & QA review IDE + CI

Security & QA review IDE + CI

Page 12: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Outsourcing

Page 13: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

DevSecOps Collaborative environment

Security Policy

Security Policy

Cloud Collaborative Environment

Security Policy

Security Reviews

Security Audits

Security Policy

Security Reviews

Security Audits

Security Policy

Security Review results

Security Audit results

DevSecOps stakeholders

Outsourced development teams

Security Reviews

Security Reviews

Security Audits

Page 14: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Conclusions and references

• 2016 State of DevOps Report by Puppet and Dora research & assessment

• Starting and Scaling DevOps in the Enterprise by Gary Gruver

• 2017 IDG Enterprise Security Priorities

• www.kiuwan.com

Last but not least… Some thousands of hours working with customers for the last 25 years

Page 15: DevSecCon London 2017: How far left do you want to go with security? by Javier Salado

Join the conversation #DevSecCon

Thank you [email protected]

@Javier_Salado

www.kiuwan.com