26
DevOps & Security James Turnbull Puppet Labs DEVOPSDAYS AUSTIN 2012

Security Loves DevOps: DevOpsDays Austin 2012

  • View
    2.918

  • Download
    1

Embed Size (px)

DESCRIPTION

Discusses the intersection between security and DevOps and how Security people can leverage DevOps and vice versa.

Citation preview

Page 1: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

DevOps & Security

James TurnbullPuppet Labs

Page 2: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Who me?

• Puppet Labs employee• Security boffin• Open source fan• Author• Australian• Expletives

Page 3: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

More introductions

Does anyone here work in Security?

Page 4: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Three things I hated about Security

1. Not being liked2. Not being effective3. Not being happy

Page 5: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Meme theft…

Page 6: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

What IT think Security do

Page 7: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

What the business think Security do

Page 8: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

What Security people think they do

Page 9: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

What Security Isn’t

Page 10: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

What Security Is (or Should Be)

• Partnership not conflict• Servicing and Protecting all customers• Allowing increased risk appetite• Enabling the business to do business

Page 11: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

The Intersection

Page 12: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Security people are people too

Page 13: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Security people are people too

• Developer People• Ops People• DBA People• Network People• Storage People

Page 14: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

DevOps & Security

You should care about security too!

Page 15: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

DevOps & Security

Evolution is mutual

Page 16: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Getting Security to Listen

It’s all about the culture

Page 17: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Getting Security to Listen

Destroy the blame culture

Page 18: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Getting Security to Listen

Speak the same language

Page 19: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Getting Security to Listen

"Risk management is the process of identifying vulnerabilities and threats to the information

resources used by an organization in achieving business objectives, and deciding what

countermeasures, if any, to take in reducing risk to an acceptable level, based on the value of

the information resource to the organization.”- CISA

Page 20: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Getting Security to Listen

Let the business do business with the right controls

Page 21: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Talking Controls

• Provisioning & Deployment: Efficiency • Configuration Management: Inconsistency is

the enemy of security• Incident Management: Information is King• Audit: Magic away auditors

Page 22: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Ideas for Collaboration

Page 23: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

DevOps & Security

• Get roles and responsibilities right• Security people are (skilled) people too• Risk Register diving

Page 24: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Dev & Security

• Put Security people into Dev• Gather security requirements early• Designed for security == Deployed sanely &

securely

Page 25: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Ops & Security

• Embed Security into Ops escalation• Invite Security to post-mortems• Expose Security to your metrics & data

Page 26: Security Loves DevOps: DevOpsDays Austin 2012

DEVOPSDAYS AUSTIN 2012

Thanks

James [email protected]

@kartarhttp://www.kartar.net