SlideShare ist ein Scribd-Unternehmen logo
1 von 24
NETWORK SECURITY AT
THE SPEED OF DEVOPS
Anner Kushnir, VP Technology
Anner Kushnir
VP Technology
WELCOME
Have a question? Submit it via the chat
This webinar is being recorded!
Slides and recording will be sent to you after the webinar
2
WHAT IS DEVOPS?
• DevOps is a software engineering culture and
practice that aims at unifying software
development (Dev) and software operation (Ops).
• The main characteristic of the DevOps movement
is to strongly
advocate automation and monitoring at all steps
of software construction,
from integration, testing, releasing to
deployment and infrastructure management.
• DevOps aims at shorter development
cycles, increased deployment frequency, more
dependable releases, in close alignment with
business objectives.
code
build
test
deploy
operate
monitor
3
DEVOPS SECURITY
What DevOps Should Be
What DevOps Is
DEVOPS SECURITY
Resource
Minutes
StorageServer
Minutes
Security /
Connectivity
WeeksTime to Provision
How often is network connectivity slowing down
DevOps processes in your organization?
• Never
• Once a month
• Once a week
• Once a day
• Not practicing DevOps yet, I am here to learn
POLL
Please vote using the “votes from audience” tab in your BrightTALK panel
6
FROM OUR CUSTOMERS
“The process is broken. Developers are required to ask for
things no developer should even know about.”
“Things that should take 20 minutes drag for days and weeks.”
Senior application architect at large financial institute
“Everything works great, until some change needs to be done
in the firewalls. Then you open a ServiceNow ticket, then wait
for 2 weeks without knowing what will happen.”
Senior DevOps consultant working with large banks
“AlgoSec is the missing link”
7
ALGOSEC FOR DEVOPS
Network Connectivity is a painful bottleneck in the Application
Delivery pipeline
The Solution: Business-driven Automation
Bake network security into the DevOps pipeline
• Security is no longer a bottleneck – App Developers happy
Human intervention only when required
• Security still has full control and visibility – Security happy
• Business application connectivity automatically documented –
Everyone’s happy!
8
CI/CD PIPELINE
Palo Alto Networks Proprietary and Confidential
9
Test
environments
Integration
Performance
Run all tests
Production
Developer
Commits
Code
Compile &
Package
Unit
tests
Bring up test
environments
Connectivity
Deploy
9
CONNECTIVITY BLOCK (ZOOM IN)
Connectivity
as Code
BusinessFlow
Changed?
Yes
No
No
Yes
Success
Fail
Traffic Simulation
Query
FireFlow
10
BUILDING BLOCKS
END-TO-END NETWORK VISIBILITY
Find which security devices are in the path, and whether they allow
application traffic
Firewalls, Routers, Cloud, SDN
11 | Confidential
BUILDING BLOCKS
ZERO-TOUCH CHANGE
AUTOMATION
12
• Find which firewalls/policies require change
• Automatic risk check – continuous compliance
• Customizable flow – thresholds, approvals
• Automatic design and push of changes
• End-to-end - Multi-vendor, multi-platform
• Optimized changes, eliminate human error
• Full documentation and audit trail
BUILDING BLOCKS
BUSINESS APPLICATION REPOSITORY
Application owners (“Top down”)
• Manage application connectivity
• Describe as logical flows
• No need to know the network
• All application details in one place
• Connectivity, Risks, Compliance,
Vulnerabilities
BusinessFlow
13
ALGOBOT - POWER TO THE (APP) PEOPLE
• Personal network security policy assistant
• Exposes AlgoSec capabilities to App Developers
• Self Service, Empowered
• Use cases:
• Check on application’s connectivity status
• Check whether network security needs to be involved
• Easily check change requests status
• Bonus: less headache for network security
14
BUILDING BLOCKS
BUSINESS APPLICATION REPOSITORY
Network Security (“bottom up”)
• Automatic business context for every rule, firewall, host
• Audits, recertification
• Understand Business impact
• Cleanup, Maintenance, Security incidents
• No more “reverse engineering”
15
• AlgoSec APIs
• AlgoSec Python SDK
• Build your own flow, powered by AlgoSec
• AlgoSec “role” for Ansible
• AlgoSec cookbook for Chef
BUILDING BLOCKS
INTEGRATION
16
WHAT JUST HAPPENED HERE
• Majority of application changes – automatically processed
• Either already works, or pre-approved and immediately implemented
• When security approval is required – Change Request automatically opened
• Application connectivity repository – automatically updated
• Immediate application context – for security incidents, network/server migrations, maintenance,
etc.
• Continuous compliance is retained
• Security has full control over policy and approvals
• Full audit trail and documentation
17
ADDITIONAL RESOURCES
18
WEBINAR SLIDES
3- PART BLOG SERIES
WHITEPAPER
SOLUTION BROCHURE
PROF. WOOL COURSE
DEVOPS DEMO
ANSIBLE ROLE
CHEF COOKBOOK
PYTHON SDK
Please click on images to access links
• DevOps is all about empowering
application developers
• AlgoSec DevOpsifies Network
Security into the CI/CD pipeline
• Continuous compliance is retained
• Business applications repository
automatically created
• Business context baked into network
security operations
SUMMARY
Q & A
https://www.algosec.com/webinars
The premier event for AlgoSec
customers and channel partners
Australia, July 31- Aug 3 | Americas, October 15-18
For more info:
https://www.algosec.com/algosummit/
THANK YOU!
Questions can be emailed to
marketing@algosec.com

Weitere ähnliche Inhalte

Was ist angesagt?

Cisco aci and AlgoSec webinar
Cisco aci and AlgoSec webinar Cisco aci and AlgoSec webinar
Cisco aci and AlgoSec webinar
Maytal Levi
 

Was ist angesagt? (20)

Building an AppSec Pipeline: Keeping your program, and your life, sane
Building an AppSec Pipeline: Keeping your program, and your life, saneBuilding an AppSec Pipeline: Keeping your program, and your life, sane
Building an AppSec Pipeline: Keeping your program, and your life, sane
 
Flight East 2018 Presentation–A DevOps State of Mind: Continuous Security wit...
Flight East 2018 Presentation–A DevOps State of Mind: Continuous Security wit...Flight East 2018 Presentation–A DevOps State of Mind: Continuous Security wit...
Flight East 2018 Presentation–A DevOps State of Mind: Continuous Security wit...
 
SecDevOps: The New Black of IT
SecDevOps: The New Black of ITSecDevOps: The New Black of IT
SecDevOps: The New Black of IT
 
SecDevOps 2.0 - Managing Your Robot Army
SecDevOps 2.0 - Managing Your Robot ArmySecDevOps 2.0 - Managing Your Robot Army
SecDevOps 2.0 - Managing Your Robot Army
 
we45 - SecDevOps Concept Presentation
we45 - SecDevOps Concept Presentationwe45 - SecDevOps Concept Presentation
we45 - SecDevOps Concept Presentation
 
Speeding Up Secure Software Development
Speeding Up Secure Software DevelopmentSpeeding Up Secure Software Development
Speeding Up Secure Software Development
 
Create and Manage a Micro-Segmented Data Center – Best Practices
Create and Manage a Micro-Segmented Data Center – Best PracticesCreate and Manage a Micro-Segmented Data Center – Best Practices
Create and Manage a Micro-Segmented Data Center – Best Practices
 
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA ProgramAppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
AppSec Fast and Slow: Your DevSecOps CI/CD Pipeline Isn’t an SSA Program
 
Continuous Delivery
Continuous DeliveryContinuous Delivery
Continuous Delivery
 
Application Security from the Inside Out
Application Security from the Inside OutApplication Security from the Inside Out
Application Security from the Inside Out
 
we45 SecDevOps Presentation - ISACA Chennai
we45 SecDevOps Presentation - ISACA Chennaiwe45 SecDevOps Presentation - ISACA Chennai
we45 SecDevOps Presentation - ISACA Chennai
 
Taking AppSec to 11 - BSides Austin 2016
Taking AppSec to 11 - BSides Austin 2016Taking AppSec to 11 - BSides Austin 2016
Taking AppSec to 11 - BSides Austin 2016
 
Observability in highly distributed systems
Observability in highly distributed systemsObservability in highly distributed systems
Observability in highly distributed systems
 
Splitting the Check on Compliance and Security
Splitting the Check on Compliance and SecuritySplitting the Check on Compliance and Security
Splitting the Check on Compliance and Security
 
Cisco aci and AlgoSec webinar
Cisco aci and AlgoSec webinar Cisco aci and AlgoSec webinar
Cisco aci and AlgoSec webinar
 
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOpsYou Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
You Build It, You Secure It: Higher Velocity and Better Security with DevSecOps
 
DevSecOps - Building Rugged Software
DevSecOps - Building Rugged SoftwareDevSecOps - Building Rugged Software
DevSecOps - Building Rugged Software
 
Mark Wall - F5 Agility 2017 - F5 Automation The Journey - PPT
Mark Wall - F5 Agility 2017 - F5 Automation The Journey - PPTMark Wall - F5 Agility 2017 - F5 Automation The Journey - PPT
Mark Wall - F5 Agility 2017 - F5 Automation The Journey - PPT
 
Simplify Dev with Complicated Security Tools
Simplify Dev with Complicated Security ToolsSimplify Dev with Complicated Security Tools
Simplify Dev with Complicated Security Tools
 
The Coming Earthquake in IIS and SQL Configuration Management
The Coming Earthquake  in IIS and SQL Configuration ManagementThe Coming Earthquake  in IIS and SQL Configuration Management
The Coming Earthquake in IIS and SQL Configuration Management
 

Ähnlich wie 2018 07-24 network security at the speed of dev ops - webinar

How to Adopt Infrastructure as Code
How to Adopt Infrastructure as CodeHow to Adopt Infrastructure as Code
How to Adopt Infrastructure as Code
NGINX, Inc.
 

Ähnlich wie 2018 07-24 network security at the speed of dev ops - webinar (20)

How to go from waterfall app dev to secure agile development in 2 weeks
How to go from waterfall app dev to secure agile development in 2 weeks How to go from waterfall app dev to secure agile development in 2 weeks
How to go from waterfall app dev to secure agile development in 2 weeks
 
Putting the Sec into DevOps
Putting the Sec into DevOpsPutting the Sec into DevOps
Putting the Sec into DevOps
 
Back To Basics
Back To BasicsBack To Basics
Back To Basics
 
AppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptxAppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptx
 
AppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptxAppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptx
 
DevSecOps - It can change your life (cycle)
DevSecOps - It can change your life (cycle)DevSecOps - It can change your life (cycle)
DevSecOps - It can change your life (cycle)
 
Testing in the new age of DevOps
Testing in the new age of DevOpsTesting in the new age of DevOps
Testing in the new age of DevOps
 
Dev ops
Dev opsDev ops
Dev ops
 
Chefdevseccon2015
Chefdevseccon2015Chefdevseccon2015
Chefdevseccon2015
 
SplunkLive! London 2016 Splunk for Devops
SplunkLive! London 2016 Splunk for DevopsSplunkLive! London 2016 Splunk for Devops
SplunkLive! London 2016 Splunk for Devops
 
Are your DevOps and Security teams friends or foes?
Are your DevOps and Security teams friends or foes?Are your DevOps and Security teams friends or foes?
Are your DevOps and Security teams friends or foes?
 
HouSecCon 2019: Offensive Security - Starting from Scratch
HouSecCon 2019: Offensive Security - Starting from ScratchHouSecCon 2019: Offensive Security - Starting from Scratch
HouSecCon 2019: Offensive Security - Starting from Scratch
 
DEVNET-1117 Open Source DevCenter Launched within DevNet
DEVNET-1117	Open Source DevCenter Launched within DevNetDEVNET-1117	Open Source DevCenter Launched within DevNet
DEVNET-1117 Open Source DevCenter Launched within DevNet
 
IP Expo Nordic: Successful Practices for Continuous Delivery
IP Expo Nordic: Successful Practices for Continuous DeliveryIP Expo Nordic: Successful Practices for Continuous Delivery
IP Expo Nordic: Successful Practices for Continuous Delivery
 
Scale security for a dollar or less
Scale security for a dollar or lessScale security for a dollar or less
Scale security for a dollar or less
 
What is DevOps?
What is DevOps?What is DevOps?
What is DevOps?
 
OpenStack Enabling DevOps
OpenStack Enabling DevOpsOpenStack Enabling DevOps
OpenStack Enabling DevOps
 
How to Adopt Infrastructure as Code
How to Adopt Infrastructure as CodeHow to Adopt Infrastructure as Code
How to Adopt Infrastructure as Code
 
Journey to the center of DevOps - v6
Journey to the center of DevOps - v6Journey to the center of DevOps - v6
Journey to the center of DevOps - v6
 
Strengthen and Scale Security for a dollar or less
Strengthen and Scale Security for a dollar or lessStrengthen and Scale Security for a dollar or less
Strengthen and Scale Security for a dollar or less
 

Mehr von AlgoSec

Build and enforce defense in depth - an algo sec-cisco tetration webinar
Build and enforce defense in depth - an algo sec-cisco tetration webinarBuild and enforce defense in depth - an algo sec-cisco tetration webinar
Build and enforce defense in depth - an algo sec-cisco tetration webinar
AlgoSec
 
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy ManagementCisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
AlgoSec
 

Mehr von AlgoSec (20)

best practices-managing_security_in_the hybrid cloud
 best practices-managing_security_in_the hybrid cloud best practices-managing_security_in_the hybrid cloud
best practices-managing_security_in_the hybrid cloud
 
compliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinarcompliance made easy. pass your audits stress-free webinar
compliance made easy. pass your audits stress-free webinar
 
The state of the cloud csa survey webinar
The state of the cloud csa survey webinarThe state of the cloud csa survey webinar
The state of the cloud csa survey webinar
 
2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...
2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...
2021 02-17 v mware-algo-sec securely accelerate your digital transformation w...
 
2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar2021 01-27 reducing risk of ransomware webinar
2021 01-27 reducing risk of ransomware webinar
 
Compliance made easy. Pass your audits stress-free.
Compliance made easy. Pass your audits stress-free.Compliance made easy. Pass your audits stress-free.
Compliance made easy. Pass your audits stress-free.
 
2021 01-13 reducing risk-of_ransomware
2021 01-13 reducing risk-of_ransomware2021 01-13 reducing risk-of_ransomware
2021 01-13 reducing risk-of_ransomware
 
Cloud migrations made simpler safe secure and successful migrations
Cloud migrations made simpler   safe secure and successful migrationsCloud migrations made simpler   safe secure and successful migrations
Cloud migrations made simpler safe secure and successful migrations
 
Microsegmentation from strategy to execution
Microsegmentation from strategy to executionMicrosegmentation from strategy to execution
Microsegmentation from strategy to execution
 
Build and enforce defense in depth - an algo sec-cisco tetration webinar
Build and enforce defense in depth - an algo sec-cisco tetration webinarBuild and enforce defense in depth - an algo sec-cisco tetration webinar
Build and enforce defense in depth - an algo sec-cisco tetration webinar
 
Radically reduce firewall rules with application-driven rule recertification
Radically reduce firewall rules with application-driven rule recertificationRadically reduce firewall rules with application-driven rule recertification
Radically reduce firewall rules with application-driven rule recertification
 
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
2020 09-30 overcoming the challenges of managing a hybrid environment - aws a...
 
2020 04-07 webinar slides -turning network security alerts into action change...
2020 04-07 webinar slides -turning network security alerts into action change...2020 04-07 webinar slides -turning network security alerts into action change...
2020 04-07 webinar slides -turning network security alerts into action change...
 
Cessation of Misconfigurations: Common Network Misconfiguration Risks & How t...
Cessation of Misconfigurations: Common Network Misconfiguration Risks & How t...Cessation of Misconfigurations: Common Network Misconfiguration Risks & How t...
Cessation of Misconfigurations: Common Network Misconfiguration Risks & How t...
 
Put out audit security fires, pass audits -every time
Put out audit security fires, pass audits -every time Put out audit security fires, pass audits -every time
Put out audit security fires, pass audits -every time
 
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy ManagementCisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
Cisco ACI & Hybrid Networks - Breaking Down Silos with Central Policy Management
 
2019 08-13 selecting the right security policy management solution
2019 08-13 selecting the right security policy management solution2019 08-13 selecting the right security policy management solution
2019 08-13 selecting the right security policy management solution
 
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
2019 06-26 effective multi-vendor management -fortinet algo sec webinar final
 
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint WebinarCisco Firepower Migration | Cisco and AlgoSec Joint Webinar
Cisco Firepower Migration | Cisco and AlgoSec Joint Webinar
 
2019 02-20 micro-segmentation based network security strategies (yoni geva)
2019 02-20 micro-segmentation based network security strategies (yoni geva)2019 02-20 micro-segmentation based network security strategies (yoni geva)
2019 02-20 micro-segmentation based network security strategies (yoni geva)
 

Kürzlich hochgeladen

+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
Health
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
masabamasaba
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
masabamasaba
 

Kürzlich hochgeladen (20)

Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
 
tonesoftg
tonesoftgtonesoftg
tonesoftg
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
%in Stilfontein+277-882-255-28 abortion pills for sale in Stilfontein
 
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park %in kempton park+277-882-255-28 abortion pills for sale in kempton park
%in kempton park+277-882-255-28 abortion pills for sale in kempton park
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
WSO2CON 2024 - Building the API First Enterprise – Running an API Program, fr...
 
What Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the SituationWhat Goes Wrong with Language Definitions and How to Improve the Situation
What Goes Wrong with Language Definitions and How to Improve the Situation
 
VTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learnVTU technical seminar 8Th Sem on Scikit-learn
VTU technical seminar 8Th Sem on Scikit-learn
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 
WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?WSO2CON 2024 - Does Open Source Still Matter?
WSO2CON 2024 - Does Open Source Still Matter?
 
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
%in kaalfontein+277-882-255-28 abortion pills for sale in kaalfontein
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni%in Benoni+277-882-255-28 abortion pills for sale in Benoni
%in Benoni+277-882-255-28 abortion pills for sale in Benoni
 
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
%+27788225528 love spells in Atlanta Psychic Readings, Attraction spells,Brin...
 
%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand%in Midrand+277-882-255-28 abortion pills for sale in midrand
%in Midrand+277-882-255-28 abortion pills for sale in midrand
 

2018 07-24 network security at the speed of dev ops - webinar

  • 1. NETWORK SECURITY AT THE SPEED OF DEVOPS Anner Kushnir, VP Technology Anner Kushnir VP Technology
  • 2. WELCOME Have a question? Submit it via the chat This webinar is being recorded! Slides and recording will be sent to you after the webinar 2
  • 3. WHAT IS DEVOPS? • DevOps is a software engineering culture and practice that aims at unifying software development (Dev) and software operation (Ops). • The main characteristic of the DevOps movement is to strongly advocate automation and monitoring at all steps of software construction, from integration, testing, releasing to deployment and infrastructure management. • DevOps aims at shorter development cycles, increased deployment frequency, more dependable releases, in close alignment with business objectives. code build test deploy operate monitor 3
  • 5. What DevOps Is DEVOPS SECURITY Resource Minutes StorageServer Minutes Security / Connectivity WeeksTime to Provision
  • 6. How often is network connectivity slowing down DevOps processes in your organization? • Never • Once a month • Once a week • Once a day • Not practicing DevOps yet, I am here to learn POLL Please vote using the “votes from audience” tab in your BrightTALK panel 6
  • 7. FROM OUR CUSTOMERS “The process is broken. Developers are required to ask for things no developer should even know about.” “Things that should take 20 minutes drag for days and weeks.” Senior application architect at large financial institute “Everything works great, until some change needs to be done in the firewalls. Then you open a ServiceNow ticket, then wait for 2 weeks without knowing what will happen.” Senior DevOps consultant working with large banks “AlgoSec is the missing link” 7
  • 8. ALGOSEC FOR DEVOPS Network Connectivity is a painful bottleneck in the Application Delivery pipeline The Solution: Business-driven Automation Bake network security into the DevOps pipeline • Security is no longer a bottleneck – App Developers happy Human intervention only when required • Security still has full control and visibility – Security happy • Business application connectivity automatically documented – Everyone’s happy! 8
  • 9. CI/CD PIPELINE Palo Alto Networks Proprietary and Confidential 9 Test environments Integration Performance Run all tests Production Developer Commits Code Compile & Package Unit tests Bring up test environments Connectivity Deploy 9
  • 10. CONNECTIVITY BLOCK (ZOOM IN) Connectivity as Code BusinessFlow Changed? Yes No No Yes Success Fail Traffic Simulation Query FireFlow 10
  • 11. BUILDING BLOCKS END-TO-END NETWORK VISIBILITY Find which security devices are in the path, and whether they allow application traffic Firewalls, Routers, Cloud, SDN 11 | Confidential
  • 12. BUILDING BLOCKS ZERO-TOUCH CHANGE AUTOMATION 12 • Find which firewalls/policies require change • Automatic risk check – continuous compliance • Customizable flow – thresholds, approvals • Automatic design and push of changes • End-to-end - Multi-vendor, multi-platform • Optimized changes, eliminate human error • Full documentation and audit trail
  • 13. BUILDING BLOCKS BUSINESS APPLICATION REPOSITORY Application owners (“Top down”) • Manage application connectivity • Describe as logical flows • No need to know the network • All application details in one place • Connectivity, Risks, Compliance, Vulnerabilities BusinessFlow 13
  • 14. ALGOBOT - POWER TO THE (APP) PEOPLE • Personal network security policy assistant • Exposes AlgoSec capabilities to App Developers • Self Service, Empowered • Use cases: • Check on application’s connectivity status • Check whether network security needs to be involved • Easily check change requests status • Bonus: less headache for network security 14
  • 15. BUILDING BLOCKS BUSINESS APPLICATION REPOSITORY Network Security (“bottom up”) • Automatic business context for every rule, firewall, host • Audits, recertification • Understand Business impact • Cleanup, Maintenance, Security incidents • No more “reverse engineering” 15
  • 16. • AlgoSec APIs • AlgoSec Python SDK • Build your own flow, powered by AlgoSec • AlgoSec “role” for Ansible • AlgoSec cookbook for Chef BUILDING BLOCKS INTEGRATION 16
  • 17. WHAT JUST HAPPENED HERE • Majority of application changes – automatically processed • Either already works, or pre-approved and immediately implemented • When security approval is required – Change Request automatically opened • Application connectivity repository – automatically updated • Immediate application context – for security incidents, network/server migrations, maintenance, etc. • Continuous compliance is retained • Security has full control over policy and approvals • Full audit trail and documentation 17
  • 18. ADDITIONAL RESOURCES 18 WEBINAR SLIDES 3- PART BLOG SERIES WHITEPAPER SOLUTION BROCHURE PROF. WOOL COURSE DEVOPS DEMO ANSIBLE ROLE CHEF COOKBOOK PYTHON SDK Please click on images to access links
  • 19. • DevOps is all about empowering application developers • AlgoSec DevOpsifies Network Security into the CI/CD pipeline • Continuous compliance is retained • Business applications repository automatically created • Business context baked into network security operations SUMMARY
  • 20. Q & A
  • 22. The premier event for AlgoSec customers and channel partners Australia, July 31- Aug 3 | Americas, October 15-18 For more info: https://www.algosec.com/algosummit/
  • 23.
  • 24. THANK YOU! Questions can be emailed to marketing@algosec.com

Hinweis der Redaktion

  1. There are several resources available for you – you can link to them directly through the attachments tab on your right.   Ansible https://galaxy.ansible.com/algosec/algosec/ & Python SDK https://github.com/algosec/algosec-python A whitepaper on DevOpsifying Network Security: https://www.algosec.com/lp/devopsifying-network-security/ The AlgoSec Network Security & DevOps Solution Brochure: https://www.algosec.com/wp-content/uploads/2017/01/170112_algosec_devops_solution_brochure.pdf Chef Cookbook: https://supermarket.chef.io/cookbooks/algosec Several AlgoSec Blog posts: https://www.algosec.com/blog/category/devops/ & Chef’s Blog: https://blog.chef.io/2018/07/17/algosec-cookbook-certified-by-the-chef-partner-cookbook-program/   As well as several video files: The DevOps Demo available on YouTube: https://www.youtube.com/watch?v=VFIE7XXBf3c Professor Wool’s Whiteboard 4-Video Courses on the best practices for incorporating security into DevOps https://www.algosec.com/professor-wool/best-practices-incorporating-security-devops/ And the webinar slides, which we will be uploading shortly
  2. Now, let’s open up the floor for some Q & A questions.
  3. NEED TO UPDATE
  4. And, before we part – we welcome you to connect with us through our social networks in LinkedIn, Facebook, Twitter and our blog.