+ All Categories
Home > Documents > Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ......

Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ......

Date post: 20-Aug-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
13
Achieving Secure Continuous Delivery (cont..) --lightning talk-- Nikos / Jesus / Lucian April 2018
Transcript
Page 1: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

AchievingSecure ContinuousDelivery(cont..)--lightningtalk--

Nikos/Jesus/Lucian

April2018

Page 2: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Typicaldiscussions…

X

Page 3: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Painpoints

Sameproblemin2018!

Difficultaccessto(uncorrelated)vulnerabilitydata

Noclearviewonthesecurityriskofaspecificbuildorrelease

Norealagreedsecuritygate(notriggerthreshold)

Shortmemory!Toolsgeteasilyforgottenorabandoned…

ProducthasaRoadmapandSecurityis(always)not(always)partofit

Securityrequirementsappear(darkmagic!)whenprojectisalmostfinished

Securitysign-offisabottleneck[choke]

Securitytestingtools!Lotsoftools!!Andreports!!!

WhenamIfinallysecureenough?Never!saysMordac.

Page 5: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

TheWant

Automation&centralisationofapplicationsecuritytesting

Riskbasedapproachtoapplicationdelivery&deployment

SecurityChampionsprocessandresponsibilities

Page 7: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Wherewearenow

Zed Attack Proxy

Security

Page 8: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

DeveloperJenkins

Page 9: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

SecurityJenkins

3.Checkmypolicy

2.HowdoesThreadfixreceiveresults4.Howweinform

1.HowdoesJenkinsruntools

Page 10: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Threadfixpolicies

Page 11: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Fixingthestuff

Page 12: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Next?Whatisbestforyouandyourbusinesses‘appetite?

GetaDevSecOpsteamtobuildandmaintaintoolz&stuffforyou£££

OWASPproject(Pipelines?)tosupportallfreetoolinputsintoonecentralrepo

(Somehow)workwithcommercialtoolproviderstosupportthat

InspireandempoweryourSecurityChampions

Page 13: Achieving Secure Continuous Delivery (cont..)...Apr 26, 2016  · Continuous Delivery (cont..) ... Product has a Roadmap and Security is (always) not (always) part of it Security requirements

Q/A


Recommended