Achieving Secure Continuous Delivery (cont..) --lightning talk-- - - PowerPoint PPT Presentation

achieving secure
SMART_READER_LITE
LIVE PREVIEW

Achieving Secure Continuous Delivery (cont..) --lightning talk-- - - PowerPoint PPT Presentation

Achieving Secure Continuous Delivery (cont..) --lightning talk-- Nikos / Jesus / Lucian April 2018 Typical discussions X Pain points Same problem in 2018! Security requirements appear (dark magic!) when project is almost finished


slide-1
SLIDE 1

Achieving Secure
 Continuous Delivery (cont..)


  • -lightning talk--

Nikos / Jesus / Lucian April 2018

slide-2
SLIDE 2

Typical discussions…

X

slide-3
SLIDE 3

Pain points

Same problem in 2018! Difficult access to (uncorrelated) vulnerability data No clear view on the security risk of a specific build or release No real agreed security gate (no trigger threshold) Short memory! Tools get easily forgotten or abandoned… Product has a Roadmap and Security is (always) not (always) part of it

Security requirements appear (dark magic!) when project is almost finished Security sign-off is a bottleneck [choke] Security testing tools! Lots of tools!! And reports!!! When am I finally secure enough? Never! says Mordac.

slide-4
SLIDE 4

Tools!!

Link HERE

SAST list HERE DAST list HERE Dependency Checking Tools list HERE Container Security tools HERE Google list HERE Others HERE

slide-5
SLIDE 5

The Want

Automation & centralisation of application security testing Risk based approach to application delivery & deployment Security Champions process and responsibilities

slide-6
SLIDE 6

Existing initiatives

Lots!!!

OWASP AppSec Pipeline OWASP OWTF OWASP Defect Dojo Others talking about this HERE HERE HERE HERE HERE HERE HERE HERE HERE HERE HERE HERE HERE HERE

OWASP Israel

OWASP AppSec Pipeline

Christian Schneider

STDD

SAMPLE

slide-7
SLIDE 7

Where we are now

Zed Attack Proxy

Security

slide-8
SLIDE 8

Developer Jenkins

slide-9
SLIDE 9

Security Jenkins

  • 3. Check my policy
  • 2. How does Threadfix receive results
  • 4. How we inform
  • 1. How does Jenkins run tools
slide-10
SLIDE 10

Threadfix policies

slide-11
SLIDE 11

Fixing the stuff

slide-12
SLIDE 12

Next?

What is best for you and your businesses‘ appetite? Get a DevSecOps team to build and maintain toolz&stuff for you £££ OWASP project (Pipelines?) to support all free tool inputs into one central repo (Somehow) work with commercial tool providers to support that Inspire and empower your Security Champions

slide-13
SLIDE 13

Q/A