SlideShare a Scribd company logo
2
Most read
4
Most read
10
Most read
DevSecOps
A.R.M. NIZZAD
CTO | SENIOR LECTURER | RESEARCHER | SOFTWARE ENGINEER | DIGITAL MEDIA
STRATEGIST | TECHNICAL W RITER | FREELANCER
Outline
DevOps DevSecOps Characteristics Practices
Benefits Implementation Challenges
DevOps
DevOps is a set of practices that works to automate and
integrate the processes between software development and IT
teams, so they can build, test, and release software faster and
more reliably
DevSecOps
DevSecOps is a further development
of the DevOps concept that, besides
automation, addresses the issues of
code quality and reliability assurance.
DevSecOps Characteristics
DevOps Culture Automation Measurement Sharing
DevSecOps Practices
• Threat modeling and risk assessments
• Continuous testing
• Monitoring and logging
• Security as code
• Red-Team and security drills
Benefits of
Implementing
DevSecOpsSHIFTING SECURITY
TO THE LEFT
AUTOMATING
SECURITY
VALUE
Implementing DevSecOps
Different Security implementation models have been proposed by
researchers and experts in the field of Security with respect to
DevSecOps.
• Three pillars of a DevSecOps model
• OWASP DevSecOps Maturity Model
• Deloitte’s transformational pillars in DevSecOps
Three pillars of a DevSecOps model
• Test-driven security
• Monitoring and responding to attacks
• Assessing risks and maturing security
OWASP DevSecOps Maturity Model
LEVEL 1: BASIC
UNDERSTANDING OF
SECURITY PRACTICES
LEVEL 2: ADOPTION OF
BASIC SECURITY PRACTICES
LEVEL 3: HIGH ADOPTION
OF SECURITY PRACTICES
LEVEL 4: ADVANCED
DEPLOYMENT OF SECURITY
PRACTICES AT SCALE
Deloitte’s transformational pillars in
DevSecOps
Governance
People
Technology
Process
Challenges in
implementing
DevSecOpsKEEPING UP WITH
DEVOPS
ORGANIZATIONAL
CHALLENGES
TOOLS AND
PRACTICES
DevOps is not a Goal, But a never-ending process of continual Improvement
Thank you

More Related Content

What's hot (20)

PDF
The State of DevSecOps
DevOps Indonesia
 
PDF
2019 DevSecOps Reference Architectures
Sonatype
 
PDF
DevSecOps - The big picture
Stefan Streichsbier
 
PPTX
DevSecOps : an Introduction
Prashanth B. P.
 
PDF
Introduction to DevSecOps
Setu Parimi
 
PPTX
DevSecOps
Cheah Eng Soon
 
PPTX
Devops ppt
Sulekha IT Training
 
PPTX
DevSecOps
Joel Divekar
 
PDF
Demystifying DevSecOps
Archana Joshi
 
PDF
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
PDF
The New Security Playbook: DevSecOps
James Wickett
 
PDF
DevOps overview 2019-04-13 Nelkinda April Meetup
Shweta Sadawarte
 
PDF
Introduction to DevOps
Ravindu Fernando
 
PDF
DevSecOps | DevOps Sec
Rubal Jain
 
PPTX
Introduction to DevOps
Hawkman Academy
 
PDF
DevSecOps Basics with Azure Pipelines
Abdul_Mujeeb
 
PPTX
How to Get Started with DevSecOps
CYBRIC
 
PPTX
DevOps Overview
Sagar Mody
 
PPTX
DevSecOps reference architectures 2018
Sonatype
 
PPTX
Transforming Organizations with CI/CD
Cprime
 
The State of DevSecOps
DevOps Indonesia
 
2019 DevSecOps Reference Architectures
Sonatype
 
DevSecOps - The big picture
Stefan Streichsbier
 
DevSecOps : an Introduction
Prashanth B. P.
 
Introduction to DevSecOps
Setu Parimi
 
DevSecOps
Cheah Eng Soon
 
DevSecOps
Joel Divekar
 
Demystifying DevSecOps
Archana Joshi
 
DevSecOps: What Why and How : Blackhat 2019
NotSoSecure Global Services
 
The New Security Playbook: DevSecOps
James Wickett
 
DevOps overview 2019-04-13 Nelkinda April Meetup
Shweta Sadawarte
 
Introduction to DevOps
Ravindu Fernando
 
DevSecOps | DevOps Sec
Rubal Jain
 
Introduction to DevOps
Hawkman Academy
 
DevSecOps Basics with Azure Pipelines
Abdul_Mujeeb
 
How to Get Started with DevSecOps
CYBRIC
 
DevOps Overview
Sagar Mody
 
DevSecOps reference architectures 2018
Sonatype
 
Transforming Organizations with CI/CD
Cprime
 

Similar to DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and challenges (20)

PPTX
DevSecOps-Explained-converted.pptx
Gurajalanaganarasimh
 
PPTX
The Importance of DevOps Security and the Emergence of DevSecOps
Dev Software
 
PPTX
DevSecOps Training Bootcamp - A Practical DevSecOps Course
Tonex
 
PPTX
What is devsecops and what is the characteristics of it
amalsalah25
 
PDF
DevSecOps Implement Making Security Central to Your DevOps Pipeline
Enov8
 
PPTX
DevSecOps: Integrating Security Into DevOps! {Business Security}
Algoworks Inc
 
PPTX
DevOps DevSecOps Based on Training Materials
RifqiMultazamOfficia
 
PPTX
Dev secops indonesia-devsecops as a service-Amien Harisen
Nadira Bajrei
 
PDF
You build it - Cyber Chicago Keynote
John Willis
 
PPTX
Introduction to DevSecOps OWASP Ahmedabad
kunwaratul hax0r
 
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
PDF
The Challenges of Scaling DevSecOps
WhiteSource
 
PPTX
DevSecOps Integrating Security in to the DevOps Lifecycle
Robert Risch
 
PPTX
Devsec ops
VipinYadav257
 
PDF
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
PPTX
How DevSecOps Can Help You Deliver Software Faster and Safer.pptx
Dev Software
 
PPTX
Devops
penetration Tester
 
PPTX
Ensuring Secure and Efficient Operations with DevOps Security
Dev Software
 
PDF
Why You Should Implement DevSecOps Approach?
Enov8
 
PDF
Securing DevOps Lifecycle
DevOps Indonesia
 
DevSecOps-Explained-converted.pptx
Gurajalanaganarasimh
 
The Importance of DevOps Security and the Emergence of DevSecOps
Dev Software
 
DevSecOps Training Bootcamp - A Practical DevSecOps Course
Tonex
 
What is devsecops and what is the characteristics of it
amalsalah25
 
DevSecOps Implement Making Security Central to Your DevOps Pipeline
Enov8
 
DevSecOps: Integrating Security Into DevOps! {Business Security}
Algoworks Inc
 
DevOps DevSecOps Based on Training Materials
RifqiMultazamOfficia
 
Dev secops indonesia-devsecops as a service-Amien Harisen
Nadira Bajrei
 
You build it - Cyber Chicago Keynote
John Willis
 
Introduction to DevSecOps OWASP Ahmedabad
kunwaratul hax0r
 
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
The Challenges of Scaling DevSecOps
WhiteSource
 
DevSecOps Integrating Security in to the DevOps Lifecycle
Robert Risch
 
Devsec ops
VipinYadav257
 
Strengthen and Scale Security Using DevSecOps - OWASP Indonesia
Mohammed A. Imran
 
How DevSecOps Can Help You Deliver Software Faster and Safer.pptx
Dev Software
 
Ensuring Secure and Efficient Operations with DevOps Security
Dev Software
 
Why You Should Implement DevSecOps Approach?
Enov8
 
Securing DevOps Lifecycle
DevOps Indonesia
 
Ad

Recently uploaded (20)

PDF
Proactive Server and System Monitoring with FME: Using HTTP and System Caller...
Safe Software
 
PDF
DoS Attack vs DDoS Attack_ The Silent Wars of the Internet.pdf
CyberPro Magazine
 
PDF
Hyderabad MuleSoft In-Person Meetup (June 21, 2025) Slides
Ravi Tamada
 
PDF
Enhancing Environmental Monitoring with Real-Time Data Integration: Leveragin...
Safe Software
 
PDF
Dev Dives: Accelerating agentic automation with Autopilot for Everyone
UiPathCommunity
 
PDF
Unlocking FME Flow’s Potential: Architecture Design for Modern Enterprises
Safe Software
 
PDF
Understanding AI Optimization AIO, LLMO, and GEO
CoDigital
 
PPSX
Usergroup - OutSystems Architecture.ppsx
Kurt Vandevelde
 
PDF
Automating the Geo-Referencing of Historic Aerial Photography in Flanders
Safe Software
 
PDF
5 Things to Consider When Deploying AI in Your Enterprise
Safe Software
 
PDF
Next level data operations using Power Automate magic
Andries den Haan
 
PDF
FME as an Orchestration Tool with Principles From Data Gravity
Safe Software
 
PPTX
2025 HackRedCon Cyber Career Paths.pptx Scott Stanton
Scott Stanton
 
PDF
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 
PDF
“Scaling i.MX Applications Processors’ Native Edge AI with Discrete AI Accele...
Edge AI and Vision Alliance
 
PDF
Redefining Work in the Age of AI - What to expect? How to prepare? Why it mat...
Malinda Kapuruge
 
PPTX
01_Approach Cyber- DORA Incident Management.pptx
FinTech Belgium
 
PDF
Quantum AI Discoveries: Fractal Patterns Consciousness and Cyclical Universes
Saikat Basu
 
PDF
LLM Search Readiness Audit - Dentsu x SEO Square - June 2025.pdf
Nick Samuel
 
PDF
Pipeline Industry IoT - Real Time Data Monitoring
Safe Software
 
Proactive Server and System Monitoring with FME: Using HTTP and System Caller...
Safe Software
 
DoS Attack vs DDoS Attack_ The Silent Wars of the Internet.pdf
CyberPro Magazine
 
Hyderabad MuleSoft In-Person Meetup (June 21, 2025) Slides
Ravi Tamada
 
Enhancing Environmental Monitoring with Real-Time Data Integration: Leveragin...
Safe Software
 
Dev Dives: Accelerating agentic automation with Autopilot for Everyone
UiPathCommunity
 
Unlocking FME Flow’s Potential: Architecture Design for Modern Enterprises
Safe Software
 
Understanding AI Optimization AIO, LLMO, and GEO
CoDigital
 
Usergroup - OutSystems Architecture.ppsx
Kurt Vandevelde
 
Automating the Geo-Referencing of Historic Aerial Photography in Flanders
Safe Software
 
5 Things to Consider When Deploying AI in Your Enterprise
Safe Software
 
Next level data operations using Power Automate magic
Andries den Haan
 
FME as an Orchestration Tool with Principles From Data Gravity
Safe Software
 
2025 HackRedCon Cyber Career Paths.pptx Scott Stanton
Scott Stanton
 
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 
“Scaling i.MX Applications Processors’ Native Edge AI with Discrete AI Accele...
Edge AI and Vision Alliance
 
Redefining Work in the Age of AI - What to expect? How to prepare? Why it mat...
Malinda Kapuruge
 
01_Approach Cyber- DORA Incident Management.pptx
FinTech Belgium
 
Quantum AI Discoveries: Fractal Patterns Consciousness and Cyclical Universes
Saikat Basu
 
LLM Search Readiness Audit - Dentsu x SEO Square - June 2025.pdf
Nick Samuel
 
Pipeline Industry IoT - Real Time Data Monitoring
Safe Software
 
Ad

DevSecops: Defined, tools, characteristics, tools, frameworks, benefits and challenges