Anzeige
Anzeige

Más contenido relacionado

Destacado(20)

Anzeige
Anzeige

[Poland] SecOps live cooking with OWASP appsec tools

  1. SecOps live cooking with OWASP appsec tools Maciej Lasyk OWASP EEE – Kraków 2015-10-06
  2. Join Fedora Infrastructure! → learn Ansible → join the security team! → use Fedora Security Lab (spin) http://fedoraproject.org/en/join-fedora
  3. Agenda? →about delivery pipeline →demos →manual testing →automation →delivery pipeline
  4. Agenda? →about delivery pipeline →demos →manual testing →automation →delivery pipeline
  5. Agenda? →about delivery pipeline →demos →manual testing →automation →delivery pipeline
  6. Agenda? →about delivery pipeline →demos →manual testing →automation →delivery pipeline
  7. Agenda? →about delivery pipeline →demos →manual testing →automation →delivery pipeline
  8. DEV INTEGRATION TEST PROD Delivery Pipeline & security testing
  9. DEV INTEGRATION TEST PROD Feedback loop! Delivery Pipeline!
  10. DEV INTEGRATION TEST PROD Feedback loop! Delivery Pipeline! → UAT → Performance → Security
  11. DEV INTEGRATION TEST containers PROD Feedback loop! Delivery Pipeline! → UAT → Performance → Security Experimentation gives you improvements! Continuous security scanning
  12. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  13. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  14. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  15. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  16. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  17. → shortening the cycle time → viability of scanning windows → burndown charts - security testing slice is usually tiny → security testing has to be faster → providing instant feedback → CD is a goal Delivery Pipeline!
  18. Manual testing demo #1 OWASP webgoat, OWASP hackademic story test-app vs OWASP ZAP
  19. Manual testing demo #1 OWASP webgoat, OWASP hackademic story test-app vs OWASP ZAP
  20. Manual testing demo #2 Fedora Pagure vs OWASP Dependency Check
  21. Automation tools → Ansible (www.ansible.com) → Jenkins (jenkins-ci.org) → GoCD (www.go.cd)
  22. Automation tools → Ansible (www.ansible.com) → Jenkins (jenkins-ci.org) → GoCD (www.go.cd)
  23. Automation tools → Ansible (www.ansible.com) → Jenkins (jenkins-ci.org) → GoCD (www.go.cd)
  24. Automation demo #1 Installing Jenkins w/Ansible
  25. Linux Containers - Docker → Docker? → Docker Registry
  26. Linux Containers - Docker → Docker? → Docker Registry
  27. Automation demo #2 OWASP ZAP && Dependency Check + Docker
  28. Automation demo #3 OWASP ZAP && Dependency Check + Docker + Jenkins
  29. Automation demo #4 Containerization of security tools
  30. Docker inside Docker? Pros and cons
  31. Automation demo #5 What about false positives / negatives?
  32. Automation demo #6 Full delivery pipeline
  33. Summary Should we replace classical pentests with automation?
  34. SecOps live cooking with OWASP appsec tools Maciej Lasyk OWASP EEE – Kraków 2015-10-06
Anzeige