london cd - continuous delivery vs copious regulation

39
Ian Watson Head of DevOps Email : [email protected] Twitter : @purplemarauder Continuous very vs Copious lations

Upload: ian-watson

Post on 22-Mar-2017

225 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: London CD - Continuous Delivery vs Copious Regulation

Ian WatsonHead of DevOps

Email : [email protected] : @purplemarauder

Continuous Delivery

vs Copious

Regulations

Page 2: London CD - Continuous Delivery vs Copious Regulation

Can you really achieve Continuous Delivery in the highly regulated world of financial services?

Page 3: London CD - Continuous Delivery vs Copious Regulation

Is it easy to achieve Continuous Delivery in the highly regulated world of financial services?

Page 4: London CD - Continuous Delivery vs Copious Regulation
Page 5: London CD - Continuous Delivery vs Copious Regulation
Page 6: London CD - Continuous Delivery vs Copious Regulation

We needed to change

Page 7: London CD - Continuous Delivery vs Copious Regulation

Searching for unicorns

Page 8: London CD - Continuous Delivery vs Copious Regulation

Who is watching?

Page 9: London CD - Continuous Delivery vs Copious Regulation
Page 10: London CD - Continuous Delivery vs Copious Regulation

Goal: regulate the use of “personal data”

DPA(Data Protection Act)

Page 11: London CD - Continuous Delivery vs Copious Regulation

Goal: Europe-wide regulation of the use of “personal data”

GDPR(General Data Protection Regulation)

Page 12: London CD - Continuous Delivery vs Copious Regulation

Goal: Protect Cardholder Data

PCI DSS(Payment Card Industry Data Security Standard)

Page 13: London CD - Continuous Delivery vs Copious Regulation

Goal: Make financial markets work well – for individuals, for business, large and small, and for the economy as a whole

FCAThe Financial Conduct Authority

Page 14: London CD - Continuous Delivery vs Copious Regulation

Let’s do this!

Page 15: London CD - Continuous Delivery vs Copious Regulation
Page 16: London CD - Continuous Delivery vs Copious Regulation

CONTINUOUS

Delivery

Page 17: London CD - Continuous Delivery vs Copious Regulation
Page 18: London CD - Continuous Delivery vs Copious Regulation
Page 19: London CD - Continuous Delivery vs Copious Regulation

What does this mean for technology choices

Page 20: London CD - Continuous Delivery vs Copious Regulation

“Cloud” is just outsourcing

Our aim is to avoid imposing inappropriate barriers to firms’ ability to outsource to innovative and developing areas, while ensuring that risks are appropriately identified and managed.

Page 21: London CD - Continuous Delivery vs Copious Regulation

No one ever got fired for buying…..

Page 22: London CD - Continuous Delivery vs Copious Regulation
Page 23: London CD - Continuous Delivery vs Copious Regulation

Hybrid might be the answer

Page 24: London CD - Continuous Delivery vs Copious Regulation

(Not so) Safe Harbour

Page 25: London CD - Continuous Delivery vs Copious Regulation
Page 26: London CD - Continuous Delivery vs Copious Regulation
Page 27: London CD - Continuous Delivery vs Copious Regulation

How much meta data?

Page 28: London CD - Continuous Delivery vs Copious Regulation

Continuous Delivery drives excellent behaviours from a regulatory compliance perspective*

*as well as a few really useful side effects like, speed, quality and reliability

Page 29: London CD - Continuous Delivery vs Copious Regulation

Segregation of Duties

Page 30: London CD - Continuous Delivery vs Copious Regulation

Corollary

Enterprise DevOps

=

Specialisation + Collaboration

Page 31: London CD - Continuous Delivery vs Copious Regulation

How autonomous is an autonomous team?

Page 32: London CD - Continuous Delivery vs Copious Regulation

Traceability

Page 33: London CD - Continuous Delivery vs Copious Regulation

Traceability

Page 34: London CD - Continuous Delivery vs Copious Regulation

Security

Page 35: London CD - Continuous Delivery vs Copious Regulation

Patching

Page 36: London CD - Continuous Delivery vs Copious Regulation

Auditability(standardisation)

Page 37: London CD - Continuous Delivery vs Copious Regulation

Auditability(immutable Infrastructure)

Page 38: London CD - Continuous Delivery vs Copious Regulation

Treat all your data as if you are likely to be audited as a regulated body…

….even if you’re not

Page 39: London CD - Continuous Delivery vs Copious Regulation