The Road to Rugged
Shannon Lietz
The Road to Rugged Shannon Lietz Who I am 25+ years Technology and - - PowerPoint PPT Presentation
The Road to Rugged Shannon Lietz Who I am 25+ years Technology and Security Experience Most of my career has been about being Rugged! Background in Security R&D Working with the Cloud before it was called the Cloud --
Shannon Lietz
Security Experience
about being Rugged!
it was called the “Cloud”
and Scrum
No one enjoys getting woken up to solve for someone else’s mistakes, especially security breaches!!
installer
Page 3 of 267
Security Configuration Procedures
V 3.6.0.1.1, January 2011
UBERSECRET
Frozen in Time
Why does it take so long for features?
YOU YOUR CUSTOMER CISO Hopefully it’s not going to be another round of “No’s”…
Bang Head Here
But - What if Security can be Rugged?
DevSec Ops
Security Engineering Experiment, Automate, Test Security Operations Hunt, Detect, Contain Compliance Operations Respond, Manage, Train Security Science Learn, Measure, Forecast
Problem Statement
Welcome DevSecOps!!
What if Security were no longer just theory?
What if you could check Security via API? Or Self-Service?
Account Grade:
Heal Account?
Complian ce Operatio ns Security Operatio ns Security Science Security Engineer ing
Ops Sec Dev
AppSec
NEW NEW N E W
Migrate App Security into DevOps Teams
Security Defects
Testing into CICD
Issues
Scanners Instrumentation Secure Components
Red Team Via Security Engineering
Enforce in Real-time with Compliance Operations
Issues in Real-time
controls
Operations & Red Team
Blue Team via Security Operations
insights security science security tools & data AWS accounts S3 Glacier EC2 CloudTrail ingestion threat intel
faster: Facebook, Netflix, LinkedIn, AWS, Intuit
Security: Joe Sullivan, Jason Chan, Gene Kim, Josh Corman
DevOpsSec, 33k+ Cloud Security