devopsconnect 2015apr20

15
WINDFALL WINS DEVOPS DRIVES AGILE SECURITY & COMPLIANCE Presented on April 20, 2015 by Julie Tsai, Industry Professional & DevOps Practitioner RSA CONFERENCE 2015 - DEVOPS CONNECT

Upload: julie-tsai

Post on 16-Jul-2015

214 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Devopsconnect 2015apr20

W I N D F A L L W I N SD E V O P S D R I V E S A G I L E

S E C U R I T Y & C O M P L I A N C E

Presented on April 20, 2015

by Julie Tsai, Industry Professional & DevOps Practitioner

R S A C O N F E R E N C E 2 0 1 5 - D E V O P S C O N N E C T

Page 2: Devopsconnect 2015apr20

The

DevOps

Unicorn!

Image Ref: http://howard118maddiew.wikispaces.com, courtesy Creative Commons Attribution Share-Alike 3.0 License

D E V O P S : M Y T H ? O R …

Page 3: Devopsconnect 2015apr20

Image Ref: http://www.modernmythology.net, courtesy CC Attribution-NonCommercial-NoDerivs 3.0 Unported License

( R ) E V O L U T I O N , T H E U L T I M A T E

H Y B R I D ?

Page 4: Devopsconnect 2015apr20

Dev & Ops

co-existing

harmoniously?

Image Ref: https://www.pinterest.com/pin/18084835974424623/, courtesy Pinterest Terms of Use

W H A T I S D E V O P S ?

Page 5: Devopsconnect 2015apr20

Gartner: “DevOps Needs to Become DevOpsSec”

S O F T D E V

N E W S W

P R O D U C T S &

D E M A N D

T E C H O P S

R E L I A B I L I T Y ,

P E R F O R M A N C

E & S C A L I N G

I N F O S E C

C O N F I D E N T I A L I T Y

, I N T E G R I T Y &

A V A I L A B I L I T Y

DEV

OPS

SEC

N O W , D E V O P S S E C ?

Page 6: Devopsconnect 2015apr20

Image Ref: http://commons.wikimedia.org, courtesy CC Attribution ShareAlike 3.0 License

D E V O P S E C V A L U E 1 :

A U T O M A T I O N

Page 7: Devopsconnect 2015apr20

Image Ref: https://www.flickr.com, courtesy CC Attribution Non-Commercial ShareAlike 2.0 License

D E V O P S E C V A L U E 2 : V I S I B I L I T Y

Page 8: Devopsconnect 2015apr20

Image Ref: http://pixabay.com, courtesy CC Deeds CC0

D E V O P S E C V A L U E 3 :

A C C O U N T A B I L I T Y

Page 9: Devopsconnect 2015apr20

1. Published

Versioned

Configs in

SCM

Ref: Updated from an older presentation of mine at http://www.slideshare.net

2. Central

Master Server

of

Gold Configs

3. Auto Config

Propagation to

Enforce on

Endpoints

4. Monitoring

+ Alerting —>

Centralized

Logging

5. Event-

Driven

Self-Healing

from Configs

T H E D E V O P S S E C V I R T U O U S

C I R C L E

Page 10: Devopsconnect 2015apr20

• Pic?

Image Ref: http://pixabay.com, courtesy CC Deeds CC0

C A S E S T U D Y 1 - P C I

Page 11: Devopsconnect 2015apr20

Image Ref: http://pixabay.com courtesy CC Deeds CC0

C A S E S T U D Y 2 - S O X

Page 12: Devopsconnect 2015apr20

Image Ref: http://pixabay.com/courtesy CC Deeds CC0

C A S E S T U D Y 3 - I P O - R E A D I N E S S

Page 13: Devopsconnect 2015apr20

• Executive Support & Necessary Empowerment

• Know What - and How - To Measure Real Progress

• Clear of Roadblocks

C A U T I O N A R Y T A L E S

Page 14: Devopsconnect 2015apr20

Presentations and tutorials uploaded at

http://www.slideshare.net/jtslideshare

A P P E N D I X

Page 15: Devopsconnect 2015apr20

• Creative Commons and Public Domain

• Ex-teractive crew - esp. Ops Director and team

• Auditors that you want to work with: ZZ Servers &

DRG. Knight Financial Plans and Services

• Personal

• OSS & GNU Foundation

A C K N O W L E D G M E N T S