Stalled at the intersection of dev ops and security v2

13
Matthew Barker, Technical Director, Sonatype 1 STALLED AT THE INTERSECTION OF DEVOPS AND SECURITY

Transcript of Stalled at the intersection of dev ops and security v2

Page 1: Stalled at the intersection of dev ops and security v2

Matthew Barker, Technical Director, Sonatype1

STALLED AT THE INTERSECTION OF

DEVOPS AND SECURITY

Page 2: Stalled at the intersection of dev ops and security v2

WHAT WE HAVE!

2

Page 3: Stalled at the intersection of dev ops and security v2

WHAT WE REALLY NEED!

3

Page 4: Stalled at the intersection of dev ops and security v2

SOFTWARE DEVELOPMENT MOVES FASTER THAN SECURITY

WHY ARE WE STALLED

4

Explosive Use of Components Agile and Devops

Enterprise ScaleUse of Complex

Frameworks

Page 5: Stalled at the intersection of dev ops and security v2

5

WE TAKE SECURITY SERIOUSLY!

Page 6: Stalled at the intersection of dev ops and security v2

WHY ARE WE STALLED

6

ARE WE SERIOUS ABOUT SECURITY?• Card

Skimmers (9%)

• Insider Misuse (8%)

• Crimeware (4%)

• DoS Attacks (1%)

See the problem?

Page 7: Stalled at the intersection of dev ops and security v2

ARE WE SECURING OUR SOFTWARE SUPPLY CHAIN?

7

Page 8: Stalled at the intersection of dev ops and security v2

COST OF ASSESSING VULNERABILITIES LATE IN SLC

8

Page 9: Stalled at the intersection of dev ops and security v2

SOME RECENT APPLICATION ATTACKS

9

Page 10: Stalled at the intersection of dev ops and security v2

HOW DO WE MOVE TO THE DEVOPS-SECURITY ACCELERATED INTERSECTION?

WHAT IS NEEDED

10

Fast and Continuous Accurate

Integrates Into Modern Devops tools

Scalable

Policy Driven

Manages Supply Chain

Prioritizes Vulnerabilities

Page 11: Stalled at the intersection of dev ops and security v2

Component Selection DEVELOPMENT BUILD AND DEPLOY PRODUCTIONCOMPONENT

SELECTION

PUBLICREPOSITORIES

A CONTINUOUS APPROACH

PRECISELY IDENTIFY

COMPONENTS & RISKS

REMEDIATE EARLY IN

DEVEOPMENT

AUTOMATE POLICY

ACROSS THE SLC

MANAGE RISK ACROSS ENTIRE

PORTFOLIO

CONTINUOUSLYMONITOR FOR

NEW RISKS

11

Page 12: Stalled at the intersection of dev ops and security v2

A Modern Security Scanning Architecture

Modern Component Data Service

TICKET TRACKING

Command Line Scannerwith return value

Real time policy check

Email Alerts

Includes production monitoring

IDE INTEGRATIONFast, up to date, and accurate

API

Policy Server with Stored

Analysis

CI INTEGRATION