devopsconnect 2015apr20
TRANSCRIPT
W I N D F A L L W I N SD E V O P S D R I V E S A G I L E
S E C U R I T Y & C O M P L I A N C E
Presented on April 20, 2015
by Julie Tsai, Industry Professional & DevOps Practitioner
R S A C O N F E R E N C E 2 0 1 5 - D E V O P S C O N N E C T
The
DevOps
Unicorn!
Image Ref: http://howard118maddiew.wikispaces.com, courtesy Creative Commons Attribution Share-Alike 3.0 License
D E V O P S : M Y T H ? O R …
Image Ref: http://www.modernmythology.net, courtesy CC Attribution-NonCommercial-NoDerivs 3.0 Unported License
( R ) E V O L U T I O N , T H E U L T I M A T E
H Y B R I D ?
Dev & Ops
co-existing
harmoniously?
Image Ref: https://www.pinterest.com/pin/18084835974424623/, courtesy Pinterest Terms of Use
W H A T I S D E V O P S ?
Gartner: “DevOps Needs to Become DevOpsSec”
S O F T D E V
N E W S W
P R O D U C T S &
D E M A N D
T E C H O P S
R E L I A B I L I T Y ,
P E R F O R M A N C
E & S C A L I N G
I N F O S E C
C O N F I D E N T I A L I T Y
, I N T E G R I T Y &
A V A I L A B I L I T Y
DEV
OPS
SEC
N O W , D E V O P S S E C ?
Image Ref: http://commons.wikimedia.org, courtesy CC Attribution ShareAlike 3.0 License
D E V O P S E C V A L U E 1 :
A U T O M A T I O N
Image Ref: https://www.flickr.com, courtesy CC Attribution Non-Commercial ShareAlike 2.0 License
D E V O P S E C V A L U E 2 : V I S I B I L I T Y
Image Ref: http://pixabay.com, courtesy CC Deeds CC0
D E V O P S E C V A L U E 3 :
A C C O U N T A B I L I T Y
1. Published
Versioned
Configs in
SCM
Ref: Updated from an older presentation of mine at http://www.slideshare.net
2. Central
Master Server
of
Gold Configs
3. Auto Config
Propagation to
Enforce on
Endpoints
4. Monitoring
+ Alerting —>
Centralized
Logging
5. Event-
Driven
Self-Healing
from Configs
T H E D E V O P S S E C V I R T U O U S
C I R C L E
• Pic?
Image Ref: http://pixabay.com, courtesy CC Deeds CC0
C A S E S T U D Y 1 - P C I
Image Ref: http://pixabay.com courtesy CC Deeds CC0
C A S E S T U D Y 2 - S O X
Image Ref: http://pixabay.com/courtesy CC Deeds CC0
C A S E S T U D Y 3 - I P O - R E A D I N E S S
• Executive Support & Necessary Empowerment
• Know What - and How - To Measure Real Progress
• Clear of Roadblocks
C A U T I O N A R Y T A L E S
Presentations and tutorials uploaded at
http://www.slideshare.net/jtslideshare
A P P E N D I X
• Creative Commons and Public Domain
• Ex-teractive crew - esp. Ops Director and team
• Auditors that you want to work with: ZZ Servers &
DRG. Knight Financial Plans and Services
• Personal
• OSS & GNU Foundation
A C K N O W L E D G M E N T S