owf14 - plenary session : david jones, chief solutions architect, sonatype

26
The True State of Open Source Security 11,000 Voices

Upload: open-world-forum

Post on 20-Jun-2015

186 views

Category:

Data & Analytics


0 download

DESCRIPTION

The benefits of using open source software are well known, well documented and well leveraged by organisations all over the world. The risks of using open source software are not always as well understood. The risks are real and there’s always more which can be done to manage risk but at what cost? Attend this keynote for a discussion on the results of a four-year, industry-wide study on application security practices, policies, and trends related to open source development. To date, over 11,000 professionals have participated in the study. Among the surprising survey results that will be discussed: 1-in-3 organizations had or suspected an open source breach in the past 12 months Only 16% of participants must prove they are not using components with known vulnerabilities 64% don't track changes in open source vulnerability data

TRANSCRIPT

Page 1: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

The True State of Open Source Security

11,000 Voices

Page 2: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

11,140 OVER THE FOUR YEAR STUDY

PEOPLE SHARED THEIR VIEWS

Page 3: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Again…why open source?

Page 4: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Reach the desired outcome in the most efficient way: • using the least amount of effort

• with the smallest total cost

• (and maybe in the shortest possible time)

Page 5: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

90%

Page 6: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Righto, and security fits in this picture how?

Page 7: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Danger Driven Development!

Page 8: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Unmanaged Risk => Technical Debt => Less Efficiency => {future} Cost

Page 9: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

[lots of something] x [cost] = Lots of Cost

Page 10: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Be aware of avoidable cost

Actively manage avoidable risk

Page 11: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

So let’s manage our risk and enable open source use?

Page 12: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Half of organizations continue to run without an open source policy.

Page 13: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Only 21% of organisations must prove they are using secure components.

Page 14: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

But I already manage my risk!

Page 15: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Even when component versions are updated 4-5 times a year to fix known security, license or quality issues1.

The majority of developers don’t track component vulnerability over time.

Page 16: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

PARTICIPANTS NOTED

SUCCESSFUL OR SUSPECTED OPEN SOURCE RELATED BREACHES IN PAST 12 MONTHS

Page 17: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Ok, so what next?

Page 18: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Have a strategy for enabling open source within your organisation

Page 19: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Understand what open source you are using

Page 20: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Make any process predictable, make it repeatable, automate it

Make the right way the easy way

Page 21: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Get the people with the right skills involved in the right places

Turn data into useable information

Give developers the information they need to

make informed decisions

Page 22: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Utilise iterative risk management, not point in time. Things change

Page 23: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Make it fast!

Make it precise!

Make it contextual!

Page 24: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

sometimes the best solutions are the ones

people don’t even realise are there

Page 25: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

WANT ALL THE SURVEY RESULTS?

www.sonatype.com/2014survey

Page 26: OWF14 - Plenary Session : David Jones, Chief Solutions Architect, Sonatype

Thank you and build safely!