SlideShare a Scribd company logo
LinkedIn.com/in/LarryMaccherone
Security
at the Speed of
Software Development
A lean/agile transformation approach
to achieving a DevSecOps culture
Larry Maccherone
LinkedIn.com/in/LarryMaccherone
LinkedIn.com/in/LarryMaccherone
Only 21% of [companies] believe
that their organization's present
culture and practices support
collaboration across development,
operations and security.
~Freeform Dynamics
(IT industry analyst)
LinkedIn.com/in/LarryMaccherone
Larry Maccherone
Larry_Maccherone@Comcast.com
Larry Maccherone
LinkedIn.com/in/LarryMaccherone
LinkedIn.com/in/LarryMaccherone
Dev[Sec]Ops is…
empowered engineering teams
taking ownership
of how their product
performs in production
[including security]
Dev[Sec]Ops  different decisions
LinkedIn.com/in/LarryMaccherone
Dev[Sec]Ops Results
• Dramatically faster time to market 
happier customers  more revenue
• 5x lower rate of failures caused by changes1
• 96x faster recovery from downtime failures1
It’s scary to QA and Security, but “moving fast and breaking
things” leads to dramatically lower rates of customer
experienced defects and vulnerabilities
1Puppet’s 2017 State of DevOps Report
What is Software Security?
LinkedIn.com/in/LarryMaccherone
When you say “security” to a developer,
he/she thinks…
Authentication &
authorization
Encryption
LinkedIn.com/in/LarryMaccherone
The bad guys…
Don’t attack the bank vault door
(breaking auth/encryption)
They try to bust through the walls
(vulnerabilities in the non-security
parts of your code)
Build-security-in
Software security
puts focus on
the bank vault walls
DevSecOps
puts focus on
the people, practices, and tools
used to build
the bank vault walls
Security practices on DevOps continuum  DevSecOps
• Static/IAST analysis
• Abuse case tests
• Code review
• Interrupt-the-pipeline
code analysis
• Threat modeling  backlog items
• Analyze/Predict  backlog items
• Design complies with policy?
• Test security features
• Common abuse cases
• Pen testing (Vuls found  Test scripts)
• Compliance validation (PCI, etc.)
• Fuzzing
• If we do X will it mitigate Y?
• Capacity forecasting
• Learning  Update
playbooks and Training
• Configuration validation
• Feature toggles/Traffic
shaping configuration
• Secrets management
• Log information for
after-incident analysis
• Intrusion detection
• App attack
detection
• Restore/maintain service
for non-attack usage
• RASP auto respond
• Roll-back or toggle off
• Block attacker
• Shut down services
• Analysis  Learning
• Defect/Incident 3-step
• New attack surface?
Plan to update threat model
That’s a lot of stuff!
How do we get
engineering teams to adopt?
A 3-part framework
for adopting new practices and
Dev[Sec]Ops culture change
1
Win the hearts and minds
of developers
LinkedIn.com/in/LarryMaccherone
Lack of TRUST
between
dev teams
and
security teams
Build security in
more than bolt it on
Rely on empowered engineering teams
more than security specialists
Implement features securely
more than security features
Rely on continuous learning
more than end-of-phase gates
Build on culture change
more than policy enforcement
DevSecOpsManifestoComcastSDL
GuidingPrinciples
We, the Security Team…
Recognize that Engineering Teams…
• Want to do the right thing
• Are closer to the business context and will
make smart trade-off decisions between
security and other risks
• Want information and assistance so they
can improve our security posture
Pledge to…
• Lower the cost/effort side
of any investment in
developer security tools or
practices
• Assist 2x as much with
preventative initiatives as
we beg for your assistance
reacting to security
incidents
Understand that…
• We are no longer gate keepers but rather tool-smiths and advisors
Credibility + Reliability + Empathy
Trust = ————————————————
Apparent self-interest
https://www.devsecopsdays.com/articles/trust-algorithm-applied-to-devsecops
2
Easy for dev teams
to know what the right thing is
and
easy to do it
DevSecOps self-assessment
After self-assessment
ask the team to pick some
to turn dark(er) green
in the next quarter
3
Management gets:
Transparency of rollout status
A mechanism to set goals
LinkedIn.com/in/LarryMaccherone
Visualizing an org’s
Dev[Sec]Ops practices
Many DevSecOps tools
are just DevOps lipstick
on a
traditional tool pig
DevSecOps tools talk
Tomorrow 12:30-1pm
Woodrow Wilson A
LinkedIn.com/in/LarryMaccherone
What’s
next?
• DevSecOps tools talk tomorrow
12:30-1pm – Woodrow Wilson A
• Read about the Trust Algorithm
https://www.devsecopsdays.com/articles/
trust-algorithm-applied-to-devsecops
• Connect with me
LinkedIn.com/in/LarryMaccherone
• Rate the talk in your app
• Questions?

More Related Content

What's hot (20)

PDF
Enterprise Application Migration
VMware Tanzu
 
PPTX
Is Private Cloud Right for Your Organization
Dave Roberts
 
PPTX
Achieving DevSecOps Outcomes with Tanzu Advanced - Spanish
VMware Tanzu
 
PDF
Delivering-Off-The-Shelf Software with Kubernetes- November 12, 2020
VMware Tanzu
 
PDF
Governance for your Modern Application Platform - November 4, 2020
VMware Tanzu
 
PDF
Cloud-native Data
cornelia davis
 
PDF
Pivotal Platform: A First Look at the October Release
VMware Tanzu
 
PDF
Cloud Native DevOps
Jim Bugwadia
 
PDF
Tanzu Standard
VMware Tanzu
 
PDF
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
PDF
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
Novell
 
PPTX
Aaron Swain at VMware Tanzu Public Sector Connect 2021
VMware Tanzu
 
PPTX
Continuous Everything in a Multi-cloud and Multi-platform Environment
VMware Tanzu
 
PDF
Getting Security in the Loop: Building Balanced Teams
VMware Tanzu
 
PDF
Kubernetes on vSphere Presentation- July 23, 2020
VMware Tanzu
 
PPTX
StripeCon 2021: A Cloud-Native approach to running Silverstripe on Google Clo...
Jon Su
 
PDF
vSphere7 with Tanzu
VMware Tanzu
 
PPTX
Enable DevSecOps using JIRA Software
AUGNYC
 
PDF
Deploying Kafka on vSphere with Kubernetes Using the Confluent Operator (Just...
confluent
 
PDF
Welcome to the Metrics
VMware Tanzu
 
Enterprise Application Migration
VMware Tanzu
 
Is Private Cloud Right for Your Organization
Dave Roberts
 
Achieving DevSecOps Outcomes with Tanzu Advanced - Spanish
VMware Tanzu
 
Delivering-Off-The-Shelf Software with Kubernetes- November 12, 2020
VMware Tanzu
 
Governance for your Modern Application Platform - November 4, 2020
VMware Tanzu
 
Cloud-native Data
cornelia davis
 
Pivotal Platform: A First Look at the October Release
VMware Tanzu
 
Cloud Native DevOps
Jim Bugwadia
 
Tanzu Standard
VMware Tanzu
 
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
Novell
 
Aaron Swain at VMware Tanzu Public Sector Connect 2021
VMware Tanzu
 
Continuous Everything in a Multi-cloud and Multi-platform Environment
VMware Tanzu
 
Getting Security in the Loop: Building Balanced Teams
VMware Tanzu
 
Kubernetes on vSphere Presentation- July 23, 2020
VMware Tanzu
 
StripeCon 2021: A Cloud-Native approach to running Silverstripe on Google Clo...
Jon Su
 
vSphere7 with Tanzu
VMware Tanzu
 
Enable DevSecOps using JIRA Software
AUGNYC
 
Deploying Kafka on vSphere with Kubernetes Using the Confluent Operator (Just...
confluent
 
Welcome to the Metrics
VMware Tanzu
 

Similar to DevSecOps: Security at the Speed of DevOp (20)

PPTX
Fortify-Application_Security_Foundation_Training.pptx
VictoriaChavesta
 
PPTX
Fortify-Application_Security_Foundation_Training.pptx
YoisRoberthTapiadeLa
 
PPTX
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
PDF
Protecting Agile Transformation through Secure DevOps (DevSecOps)
Eryk Budi Pratama
 
PDF
Application Security Testing for Software Engineers: An approach to build sof...
Michael Hidalgo
 
PPTX
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
PDF
Building Security Into Your Cloud IT Practices
Mighty Guides, Inc.
 
PPTX
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
Turja Narayan Chaudhuri
 
PPTX
Does Anyone Remember Enterprise Security Architecture?
rbrockway
 
PPTX
Devsec ops
VipinYadav257
 
PDF
Why is The IT industry moving towards a DevSecOps approach?
Enov8
 
PDF
Developer Velocity
Stephanie Locke
 
PPTX
State of DevSecOps - GTACS 2019
Stefan Streichsbier
 
PDF
DevSecOpsMaturityModel.pdf
cdsk335
 
PPTX
A journey from dev ops to devsecops
Veritis Group, Inc
 
PPTX
MS. Cybersecurity Reference Architecture
angelohammond
 
DOCX
The Importance of DevOps Security in 2023.docx
Xavor Corporation - Redefining Health Technology
 
PDF
DevOps and Devsecops- What are the Differences.
Techugo
 
PPTX
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
PPTX
State of DevSecOps - DevOpsDays Jakarta 2019
Stefan Streichsbier
 
Fortify-Application_Security_Foundation_Training.pptx
VictoriaChavesta
 
Fortify-Application_Security_Foundation_Training.pptx
YoisRoberthTapiadeLa
 
State of DevSecOps - DevSecOpsDays 2019
Stefan Streichsbier
 
Protecting Agile Transformation through Secure DevOps (DevSecOps)
Eryk Budi Pratama
 
Application Security Testing for Software Engineers: An approach to build sof...
Michael Hidalgo
 
SCS DevSecOps Seminar - State of DevSecOps
Stefan Streichsbier
 
Building Security Into Your Cloud IT Practices
Mighty Guides, Inc.
 
DOIS22 Why you need Cloud-agnostic practices to fuel your DevSecOps adoption ...
Turja Narayan Chaudhuri
 
Does Anyone Remember Enterprise Security Architecture?
rbrockway
 
Devsec ops
VipinYadav257
 
Why is The IT industry moving towards a DevSecOps approach?
Enov8
 
Developer Velocity
Stephanie Locke
 
State of DevSecOps - GTACS 2019
Stefan Streichsbier
 
DevSecOpsMaturityModel.pdf
cdsk335
 
A journey from dev ops to devsecops
Veritis Group, Inc
 
MS. Cybersecurity Reference Architecture
angelohammond
 
The Importance of DevOps Security in 2023.docx
Xavor Corporation - Redefining Health Technology
 
DevOps and Devsecops- What are the Differences.
Techugo
 
Secure Your DevOps Pipeline Best Practices Meetup 08022024.pptx
lior mazor
 
State of DevSecOps - DevOpsDays Jakarta 2019
Stefan Streichsbier
 
Ad

More from VMware Tanzu (20)

PDF
Spring into AI presented by Dan Vega 5/14
VMware Tanzu
 
PDF
What AI Means For Your Product Strategy And What To Do About It
VMware Tanzu
 
PDF
Make the Right Thing the Obvious Thing at Cardinal Health 2023
VMware Tanzu
 
PPTX
Enhancing DevEx and Simplifying Operations at Scale
VMware Tanzu
 
PDF
Spring Update | July 2023
VMware Tanzu
 
PPTX
Platforms, Platform Engineering, & Platform as a Product
VMware Tanzu
 
PPTX
Building Cloud Ready Apps
VMware Tanzu
 
PDF
Spring Boot 3 And Beyond
VMware Tanzu
 
PDF
Spring Cloud Gateway - SpringOne Tour 2023 Charles Schwab.pdf
VMware Tanzu
 
PDF
Simplify and Scale Enterprise Apps in the Cloud | Boston 2023
VMware Tanzu
 
PDF
Simplify and Scale Enterprise Apps in the Cloud | Seattle 2023
VMware Tanzu
 
PPTX
tanzu_developer_connect.pptx
VMware Tanzu
 
PDF
Tanzu Virtual Developer Connect Workshop - French
VMware Tanzu
 
PDF
Tanzu Developer Connect Workshop - English
VMware Tanzu
 
PDF
Virtual Developer Connect Workshop - English
VMware Tanzu
 
PDF
Tanzu Developer Connect - French
VMware Tanzu
 
PDF
Simplify and Scale Enterprise Apps in the Cloud | Dallas 2023
VMware Tanzu
 
PDF
SpringOne Tour: Deliver 15-Factor Applications on Kubernetes with Spring Boot
VMware Tanzu
 
PDF
SpringOne Tour: The Influential Software Engineer
VMware Tanzu
 
PDF
SpringOne Tour: Domain-Driven Design: Theory vs Practice
VMware Tanzu
 
Spring into AI presented by Dan Vega 5/14
VMware Tanzu
 
What AI Means For Your Product Strategy And What To Do About It
VMware Tanzu
 
Make the Right Thing the Obvious Thing at Cardinal Health 2023
VMware Tanzu
 
Enhancing DevEx and Simplifying Operations at Scale
VMware Tanzu
 
Spring Update | July 2023
VMware Tanzu
 
Platforms, Platform Engineering, & Platform as a Product
VMware Tanzu
 
Building Cloud Ready Apps
VMware Tanzu
 
Spring Boot 3 And Beyond
VMware Tanzu
 
Spring Cloud Gateway - SpringOne Tour 2023 Charles Schwab.pdf
VMware Tanzu
 
Simplify and Scale Enterprise Apps in the Cloud | Boston 2023
VMware Tanzu
 
Simplify and Scale Enterprise Apps in the Cloud | Seattle 2023
VMware Tanzu
 
tanzu_developer_connect.pptx
VMware Tanzu
 
Tanzu Virtual Developer Connect Workshop - French
VMware Tanzu
 
Tanzu Developer Connect Workshop - English
VMware Tanzu
 
Virtual Developer Connect Workshop - English
VMware Tanzu
 
Tanzu Developer Connect - French
VMware Tanzu
 
Simplify and Scale Enterprise Apps in the Cloud | Dallas 2023
VMware Tanzu
 
SpringOne Tour: Deliver 15-Factor Applications on Kubernetes with Spring Boot
VMware Tanzu
 
SpringOne Tour: The Influential Software Engineer
VMware Tanzu
 
SpringOne Tour: Domain-Driven Design: Theory vs Practice
VMware Tanzu
 
Ad

Recently uploaded (20)

PPTX
Function & Procedure: Function Vs Procedure in PL/SQL
Shani Tiwari
 
PPTX
PCC IT Forum 2025 - Legislative Technology Snapshot
Gareth Oakes
 
PPTX
iaas vs paas vs saas :choosing your cloud strategy
CloudlayaTechnology
 
PDF
Virtual Threads in Java: A New Dimension of Scalability and Performance
Tier1 app
 
PPTX
Transforming Lending with IntelliGrow – Advanced Loan Software Solutions
Intelli grow
 
PDF
Why Are More Businesses Choosing Partners Over Freelancers for Salesforce.pdf
Cymetrix Software
 
PDF
Show Which Projects Support Your Strategy and Deliver Results with OnePlan df
OnePlan Solutions
 
PPTX
UI5con_2025_Accessibility_Ever_Evolving_
gerganakremenska1
 
PDF
Windows 10 Professional Preactivated.pdf
asghxhsagxjah
 
PDF
Message Level Status (MLS): The Instant Feedback Mechanism for UAE e-Invoicin...
Prachi Desai
 
PPTX
Cutting Optimization Pro 5.18.2 Crack With Free Download
cracked shares
 
PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
Shane Coughlan
 
PPT
Brief History of Python by Learning Python in three hours
adanechb21
 
PDF
How to Download and Install ADT (ABAP Development Tools) for Eclipse IDE | SA...
SAP Vista, an A L T Z E N Company
 
PPTX
prodad heroglyph crack 2.0.214.2 Full Free Download
cracked shares
 
PDF
SAP GUI Installation Guide for macOS (iOS) | Connect to SAP Systems on Mac
SAP Vista, an A L T Z E N Company
 
PDF
Instantiations Company Update (ESUG 2025)
ESUG
 
PPTX
API DOCUMENTATION | API INTEGRATION PLATFORM
philipnathen82
 
PDF
Code and No-Code Journeys: The Maintenance Shortcut
Applitools
 
PDF
Optimizing Tiered Storage for Low-Latency Real-Time Analytics at AI Scale
Alluxio, Inc.
 
Function & Procedure: Function Vs Procedure in PL/SQL
Shani Tiwari
 
PCC IT Forum 2025 - Legislative Technology Snapshot
Gareth Oakes
 
iaas vs paas vs saas :choosing your cloud strategy
CloudlayaTechnology
 
Virtual Threads in Java: A New Dimension of Scalability and Performance
Tier1 app
 
Transforming Lending with IntelliGrow – Advanced Loan Software Solutions
Intelli grow
 
Why Are More Businesses Choosing Partners Over Freelancers for Salesforce.pdf
Cymetrix Software
 
Show Which Projects Support Your Strategy and Deliver Results with OnePlan df
OnePlan Solutions
 
UI5con_2025_Accessibility_Ever_Evolving_
gerganakremenska1
 
Windows 10 Professional Preactivated.pdf
asghxhsagxjah
 
Message Level Status (MLS): The Instant Feedback Mechanism for UAE e-Invoicin...
Prachi Desai
 
Cutting Optimization Pro 5.18.2 Crack With Free Download
cracked shares
 
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
Shane Coughlan
 
Brief History of Python by Learning Python in three hours
adanechb21
 
How to Download and Install ADT (ABAP Development Tools) for Eclipse IDE | SA...
SAP Vista, an A L T Z E N Company
 
prodad heroglyph crack 2.0.214.2 Full Free Download
cracked shares
 
SAP GUI Installation Guide for macOS (iOS) | Connect to SAP Systems on Mac
SAP Vista, an A L T Z E N Company
 
Instantiations Company Update (ESUG 2025)
ESUG
 
API DOCUMENTATION | API INTEGRATION PLATFORM
philipnathen82
 
Code and No-Code Journeys: The Maintenance Shortcut
Applitools
 
Optimizing Tiered Storage for Low-Latency Real-Time Analytics at AI Scale
Alluxio, Inc.
 

DevSecOps: Security at the Speed of DevOp

Editor's Notes

  • #23: Add a step to the threat modeling row for how well they are doing it. Risk driven.
  • #26: We need a way to tie into the org leadership to get their input on what they want to do next. This visualization is fine, but we need an engagement model for execs and other management layers.