SlideShare ist ein Scribd-Unternehmen logo
1 von 37
Downloaden Sie, um offline zu lesen
DevSecOps In
the Year 2018
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Who are these people?
James Wickett
Head of Research @ Signal Sciences
Ernest Mueller
Director of Engineering Opeations @ AlienVault
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Get the slides:
james@signalsciences.com
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
bit.ly/devops-courses
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
What is this
DevSecOps
you speak of?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
The original DevOps Deep Thoughts were created by
the hilarious and awesome Josh Zimmerman
(@TheJewberwocky) as Not Jack Handey which is
parody of Deep Thoughts by Jack Handey.
These DevSecOps Deep Thoughts are not nearly as
funny nor deep, but hey what do you expect of a
parody of a parody?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
DevSecOps is the
extension of the DevOps
culture for the inclusion
of Security
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
"Companies are spending a great deal on security,
but we read of massive computer-related attacks.
Clearly something is wrong. The root of the problem
is twofold: we’re protecting the wrong things, and
we’re hurting productivity in the process."
Thinking Security, Steven M. Bellovin
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
For your
consideration:
Is DevSecOps InfoSec's
best chance of survival?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
The survey says...
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
2,076 People
Responded
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Major Findings from the
DevSecOps Community
Survey 2018
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
74% of respondents
report mature or growing
in maturity of DevOps
Practices
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
48% of developers say
security is important but
dont have enough time to
spend on it
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
73% of mature devops
shops say breaches drive
interest in DevSecOps
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
1-in-3 report breaches
are due to web
application vulns
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
72% of respondents see
security pros in the role
of "nag"
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
"many security teams
work with a worldview
where their goal is to
inhibit change as much
as possible"
James Wickett (@wickett) | Ernest Mueller
(@ernestmueller)
Yet, 91% agree security is
part of everyone's role
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Questions for
Austin, TX
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
We want this to be a conversation. Try to keep the
answers to 30s or less to give everyone a chance to
get involved in the conversation.
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
1. What do you wish
security people would
know about DevOps?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
2. What do you wish
devops people would
know about security?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
3. Have you done or seen
done a real win by using
DevOps and security
together?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
4. What would you like to
see to further your
DevSecOps efforts?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Questions?
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Get the Report!
bit.ly/devsecops-report-2018
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Get the slides:
james@signalsciences.com
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
Thank You
James Wickett (@wickett) | Ernest Mueller (@ernestmueller)

Weitere ähnliche Inhalte

Mehr von James Wickett

Mehr von James Wickett (20)

A Pragmatic Union: Security and SRE
A Pragmatic Union: Security and SREA Pragmatic Union: Security and SRE
A Pragmatic Union: Security and SRE
 
The Security, DevOps, and Chaos Playbook to Change the World
The Security, DevOps, and Chaos Playbook to Change the WorldThe Security, DevOps, and Chaos Playbook to Change the World
The Security, DevOps, and Chaos Playbook to Change the World
 
Pragmatic Pipeline Security
Pragmatic Pipeline SecurityPragmatic Pipeline Security
Pragmatic Pipeline Security
 
A Tale of Woe, Chaos, and Business
A Tale of Woe, Chaos, and BusinessA Tale of Woe, Chaos, and Business
A Tale of Woe, Chaos, and Business
 
A DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and PeopleA DevSecOps Tale of Business, Engineering, and People
A DevSecOps Tale of Business, Engineering, and People
 
DevOpsDays Austin: Security in the FaaS Lane
DevOpsDays Austin: Security in the FaaS LaneDevOpsDays Austin: Security in the FaaS Lane
DevOpsDays Austin: Security in the FaaS Lane
 
Serverless Security: A How-to Guide @ SnowFROC 2019
Serverless Security: A How-to Guide @ SnowFROC 2019Serverless Security: A How-to Guide @ SnowFROC 2019
Serverless Security: A How-to Guide @ SnowFROC 2019
 
Release Your Inner DevSecOp
Release Your Inner DevSecOpRelease Your Inner DevSecOp
Release Your Inner DevSecOp
 
Security in the FaaS Lane
Security in the FaaS LaneSecurity in the FaaS Lane
Security in the FaaS Lane
 
The New Security Playbook: DevSecOps
The New Security Playbook: DevSecOpsThe New Security Playbook: DevSecOps
The New Security Playbook: DevSecOps
 
The Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CDThe Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CD
 
The DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD PipelineThe DevSecOps Builder’s Guide to the CI/CD Pipeline
The DevSecOps Builder’s Guide to the CI/CD Pipeline
 
DevSecOps and the CI/CD Pipeline
 DevSecOps and the CI/CD Pipeline DevSecOps and the CI/CD Pipeline
DevSecOps and the CI/CD Pipeline
 
DevSecOps and the New Path Forward
DevSecOps and the New Path ForwardDevSecOps and the New Path Forward
DevSecOps and the New Path Forward
 
The Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CDThe Emergent Cloud Security Toolchain for CI/CD
The Emergent Cloud Security Toolchain for CI/CD
 
AppSec California 2018: The Path of DevOps Enlightenment for InfoSec
AppSec California 2018: The Path of DevOps Enlightenment for InfoSecAppSec California 2018: The Path of DevOps Enlightenment for InfoSec
AppSec California 2018: The Path of DevOps Enlightenment for InfoSec
 
LambHack: A Vulnerable Serverless Application
LambHack: A Vulnerable Serverless ApplicationLambHack: A Vulnerable Serverless Application
LambHack: A Vulnerable Serverless Application
 
Defense-Oriented DevOps for Modern Software Development
Defense-Oriented DevOps for Modern Software DevelopmentDefense-Oriented DevOps for Modern Software Development
Defense-Oriented DevOps for Modern Software Development
 
Innotech Austin 2017: The Path of DevOps Enlightenment for InfoSec
Innotech Austin 2017: The Path of DevOps Enlightenment for InfoSecInnotech Austin 2017: The Path of DevOps Enlightenment for InfoSec
Innotech Austin 2017: The Path of DevOps Enlightenment for InfoSec
 
Serverless Security at LASCON 2017
Serverless Security at LASCON 2017Serverless Security at LASCON 2017
Serverless Security at LASCON 2017
 

Kürzlich hochgeladen

%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
masabamasaba
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
Health
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
chiefasafspells
 
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
VictoriaMetrics
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Medical / Health Care (+971588192166) Mifepristone and Misoprostol tablets 200mg
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
masabamasaba
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
masabamasaba
 

Kürzlich hochgeladen (20)

Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
Crypto Cloud Review - How To Earn Up To $500 Per DAY Of Bitcoin 100% On AutoP...
 
Architecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the pastArchitecture decision records - How not to get lost in the past
Architecture decision records - How not to get lost in the past
 
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa%in tembisa+277-882-255-28 abortion pills for sale in tembisa
%in tembisa+277-882-255-28 abortion pills for sale in tembisa
 
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
MarTech Trend 2024 Book : Marketing Technology Trends (2024 Edition) How Data...
 
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
%+27788225528 love spells in Boston Psychic Readings, Attraction spells,Bring...
 
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
+971565801893>>SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHAB...
 
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
Love witchcraft +27768521739 Binding love spell in Sandy Springs, GA |psychic...
 
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
Large-scale Logging Made Easy: Meetup at Deutsche Bank 2024
 
Announcing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK SoftwareAnnouncing Codolex 2.0 from GDK Software
Announcing Codolex 2.0 from GDK Software
 
WSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security ProgramWSO2CON 2024 - How to Run a Security Program
WSO2CON 2024 - How to Run a Security Program
 
WSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaSWSO2CON 2024 Slides - Open Source to SaaS
WSO2CON 2024 Slides - Open Source to SaaS
 
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
Abortion Pill Prices Tembisa [(+27832195400*)] 🏥 Women's Abortion Clinic in T...
 
AI & Machine Learning Presentation Template
AI & Machine Learning Presentation TemplateAI & Machine Learning Presentation Template
AI & Machine Learning Presentation Template
 
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park %in ivory park+277-882-255-28 abortion pills for sale in ivory park
%in ivory park+277-882-255-28 abortion pills for sale in ivory park
 
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
%+27788225528 love spells in Huntington Beach Psychic Readings, Attraction sp...
 
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
%+27788225528 love spells in Knoxville Psychic Readings, Attraction spells,Br...
 
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
WSO2CON 2024 - Cloud Native Middleware: Domain-Driven Design, Cell-Based Arch...
 
WSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go PlatformlessWSO2CON2024 - It's time to go Platformless
WSO2CON2024 - It's time to go Platformless
 
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
WSO2CON 2024 - API Management Usage at La Poste and Its Impact on Business an...
 
tonesoftg
tonesoftgtonesoftg
tonesoftg
 

DevSecOps in the Year 2018

  • 1. DevSecOps In the Year 2018 James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 2. Who are these people? James Wickett Head of Research @ Signal Sciences Ernest Mueller Director of Engineering Opeations @ AlienVault James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 3. Get the slides: james@signalsciences.com James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 4.
  • 5. bit.ly/devops-courses James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 6. What is this DevSecOps you speak of? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 7.
  • 8.
  • 9. The original DevOps Deep Thoughts were created by the hilarious and awesome Josh Zimmerman (@TheJewberwocky) as Not Jack Handey which is parody of Deep Thoughts by Jack Handey. These DevSecOps Deep Thoughts are not nearly as funny nor deep, but hey what do you expect of a parody of a parody? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 10. DevSecOps is the extension of the DevOps culture for the inclusion of Security James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 11. "Companies are spending a great deal on security, but we read of massive computer-related attacks. Clearly something is wrong. The root of the problem is twofold: we’re protecting the wrong things, and we’re hurting productivity in the process." Thinking Security, Steven M. Bellovin James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 12. For your consideration: Is DevSecOps InfoSec's best chance of survival? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 13. The survey says... James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 14.
  • 15. 2,076 People Responded James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 16. Major Findings from the DevSecOps Community Survey 2018 James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 17. 74% of respondents report mature or growing in maturity of DevOps Practices James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 18. 48% of developers say security is important but dont have enough time to spend on it James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 19. 73% of mature devops shops say breaches drive interest in DevSecOps James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 20. 1-in-3 report breaches are due to web application vulns James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 21. 72% of respondents see security pros in the role of "nag" James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 22. "many security teams work with a worldview where their goal is to inhibit change as much as possible" James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 23. Yet, 91% agree security is part of everyone's role James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 24.
  • 25.
  • 26.
  • 27.
  • 28. Questions for Austin, TX James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 29. We want this to be a conversation. Try to keep the answers to 30s or less to give everyone a chance to get involved in the conversation. James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 30. 1. What do you wish security people would know about DevOps? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 31. 2. What do you wish devops people would know about security? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 32. 3. Have you done or seen done a real win by using DevOps and security together? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 33. 4. What would you like to see to further your DevSecOps efforts? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 34. Questions? James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 35. Get the Report! bit.ly/devsecops-report-2018 James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 36. Get the slides: james@signalsciences.com James Wickett (@wickett) | Ernest Mueller (@ernestmueller)
  • 37. Thank You James Wickett (@wickett) | Ernest Mueller (@ernestmueller)