why secdevops will save the cloud

36
WHY SECDEVOPS WILL SAVE THE CLOUD By Bill Young, Sr. Infrastructure Engineer for Threat Stack

Upload: threat-stack

Post on 15-Dec-2014

412 views

Category:

Technology


1 download

DESCRIPTION

DevOps unite: Infrastructure as code took the community by storm. Various Configuration Management solutions started making themselves available, code was written, and progress was made. But something was still missing. The cloud has left us questioning our surroundings. Who has access, what are the controls, what services are publicly available and which are safely kept behind “locked” doors? What is our risk, and how efficiently was it assessed?

TRANSCRIPT

Page 1: Why SecDevOps Will Save The Cloud

WHY SECDEVOPS WILL SAVE THE CLOUD

By Bill Young, Sr. Infrastructure Engineer for Threat Stack

Page 2: Why SecDevOps Will Save The Cloud

THE WORLD HAS CHANGED !

!

!

!

!

!

!

It’s in the Earth. It’s in the packet loss.

Page 3: Why SecDevOps Will Save The Cloud

This is the age of the cloud.

Page 4: Why SecDevOps Will Save The Cloud

We were not without our skeptics,

but we knew what was happening.

Page 5: Why SecDevOps Will Save The Cloud

A revolution was on our doorstep. !

!

!

!

!

!

!

!

We wanted it all!

Page 6: Why SecDevOps Will Save The Cloud

We wanted it yesterday.

Page 7: Why SecDevOps Will Save The Cloud

Configuration Management

Automation Orchestration

Continuous Integration Delivery

Page 8: Why SecDevOps Will Save The Cloud

New concepts were born… !

Titles were given… !

!

and philosophies of win floated around the web like confetti.

Page 9: Why SecDevOps Will Save The Cloud

…we weren’t sure where we were going, but we knew where we didn’t want to be…

Page 10: Why SecDevOps Will Save The Cloud

Configuration drift!

Tedious provisioning of systems!

Lack of acceptance!

Unit tests!

Page 11: Why SecDevOps Will Save The Cloud

Our fears were real, so we sought answers.

Page 12: Why SecDevOps Will Save The Cloud

DevOps is born.

Page 13: Why SecDevOps Will Save The Cloud

“This is the solution we’ve been

searching for!”

Page 14: Why SecDevOps Will Save The Cloud

So, what is a “DevOp”?

We’ve all heard the jargon, the marketing pitches,

!

but what is it really?

Page 15: Why SecDevOps Will Save The Cloud

def·i·ni·tion !

!

DevOps is not a team, nor an organizational role. !

It is a philosophy of collaboration.

Page 16: Why SecDevOps Will Save The Cloud

“In the long history of humankind (and animal kind, too) those who learned to collaborate and improvise most

effectively have prevailed.” - Charles Darwin

Page 17: Why SecDevOps Will Save The Cloud

For years, we’ve sectioned off teams

Developers to the left Operations to the right

Security teams…where did they go? Who knows, really…

Page 18: Why SecDevOps Will Save The Cloud

!

Applications and services were developed and passed over the wall to Operations

where they pieced things together to create a working environment.

Page 19: Why SecDevOps Will Save The Cloud

It was how we “got shit done.”

Page 20: Why SecDevOps Will Save The Cloud

Yet, something had always been missing.

Page 21: Why SecDevOps Will Save The Cloud

Where was the bottleneck? How do we optimize our development and deployment pipelines?”

!

!

Things need to be faster! Mush! Mush! Fellow Engineers!

Page 22: Why SecDevOps Will Save The Cloud

DevOps, unite!

Page 23: Why SecDevOps Will Save The Cloud

!

Configuration Management solutions became available! !

Code was written! !

Progress was made!

Infrastructure as Code Took the Community By STORM!

Page 24: Why SecDevOps Will Save The Cloud

…but something was still missing. !

Something of incredible value!

Page 25: Why SecDevOps Will Save The Cloud

SECURITY!

Page 26: Why SecDevOps Will Save The Cloud
Page 27: Why SecDevOps Will Save The Cloud

Were we really foolish enough to believe that these progressive methodologies would save us from something

so integral to our success? !

!

Security, why have we forsaken you?

Page 28: Why SecDevOps Will Save The Cloud

Who has access? What are the controls? What services are publicly available? Which are safely kept behind “locked” doors? What is our risk? How efficiently was it assessed?

The cloud has left us questioning our surroundings

Page 29: Why SecDevOps Will Save The Cloud

If you have yet to ask yourself those questions,

it will only be a matter of time before you are

one of the Lost.

Page 30: Why SecDevOps Will Save The Cloud

What is it?! !

Where did it come from?! !

Is it just another silly buzzword?

Suddenly, the SecDevOps Methodology appeared

Page 31: Why SecDevOps Will Save The Cloud

It is natural progression.

Page 32: Why SecDevOps Will Save The Cloud

Without complete ownership of our systems and their supporting environments,

we need to protect ourselves.

Page 33: Why SecDevOps Will Save The Cloud

That’s why SecDevOps, or SecOps, is a natural extension of DevOps

Page 34: Why SecDevOps Will Save The Cloud

The rate of change leaves little room for Security teams to properly assess risk in applications and infrastructure code.

!

!

Without bringing Security into the fold, we will continue to be at risk of ever-looming threats.

Page 35: Why SecDevOps Will Save The Cloud

By integrating our Security tool-chains into our DevOps pipeline,

we can effectively mitigate our risks and continue our journey

towards a secure, automated infrastructure.

The Solution.

Page 36: Why SecDevOps Will Save The Cloud

Start Implementing SecDevOps Today with Threat Stack!

!

!

threatstack.com