Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ......

Post on 20-Aug-2020

1 views 0 download

transcript

AchievingSecure ContinuousDelivery(cont..)--lightningtalk--

Nikos/Jesus/Lucian

April2018

Typicaldiscussions…

X

Painpoints

Sameproblemin2018!

Difficultaccessto(uncorrelated)vulnerabilitydata

Noclearviewonthesecurityriskofaspecificbuildorrelease

Norealagreedsecuritygate(notriggerthreshold)

Shortmemory!Toolsgeteasilyforgottenorabandoned…

ProducthasaRoadmapandSecurityis(always)not(always)partofit

Securityrequirementsappear(darkmagic!)whenprojectisalmostfinished

Securitysign-offisabottleneck[choke]

Securitytestingtools!Lotsoftools!!Andreports!!!

WhenamIfinallysecureenough?Never!saysMordac.

TheWant

Automation&centralisationofapplicationsecuritytesting

Riskbasedapproachtoapplicationdelivery&deployment

SecurityChampionsprocessandresponsibilities

Wherewearenow

Zed Attack Proxy

Security

DeveloperJenkins

SecurityJenkins

3.Checkmypolicy

2.HowdoesThreadfixreceiveresults4.Howweinform

1.HowdoesJenkinsruntools

Threadfixpolicies

Fixingthestuff

Next?Whatisbestforyouandyourbusinesses‘appetite?

GetaDevSecOpsteamtobuildandmaintaintoolz&stuffforyou£££

OWASPproject(Pipelines?)tosupportallfreetoolinputsintoonecentralrepo

(Somehow)workwithcommercialtoolproviderstosupportthat

InspireandempoweryourSecurityChampions

Q/A