SlideShare una empresa de Scribd logo
1 de 29
Descargar para leer sin conexión
1
DevOps:
Lead, Follow, Or Get Out of the Way
A CISO Perspective
Presented by:
Tim Virtue
CISO, Texas.gov
The Lawyers Made Me Do It
 Any references to specific organizations, people,
products, or services, are purely examples or learning
opportunities and neither criticisms nor
endorsements
 The views presented are strictly my own and may or
may not represent any organizations or affiliations I
have (mostly because they have not seen the light
yet )
 It’s OK to agree to disagree, but anyone who gets
that worked up over slides needs a vacation
ABC Soup & Street Cred
 CISSP, CCSK, CISA, CIPP/G, CFE, ITIL V3, CVE, QGVM,
blah blah blah…
 Over 15 years experience in Security, Risk
Management and IT
 Executive Master of Science in Information Systems
from a top business school
 Cyber Security Instructor, Author & Speaker
 Not bragging – just showing perspective & credibility
– if DevOps can sell me, you can sell it to the greater
security community and your organization
 Something to be
ignored
 Something Security
should try and stop
 Something done in
isolation
 A system or tool
implementation
What DevOps Is Not
What is DevOps?
 Many things to many people
 A trendy buzzword, but with a powerful ideology
 Not just for “The Unicorn Companies”
 For today, lets focus on key concepts such as Agile,
Culture, Quality, Automation & Tools
 For a great in depth discussion read “What Is
DevOps?” by the Agile admin:
http://theagileadmin.com/what-is-devops/
DevOps: My Initial Thoughts
3 Ring Circus
Like I didn’t
have enough
problems when
they
(Development &
Operations)
worked
independently –
now they want
us to work
together –
Seriously???
Puppets, Chefs,
& Vagrants –
These are now
in the
environment – I
don’t know
what this
means, but your
telling me not
to worry –
Really???
We struggle with a few
security basics already
– and now you want to
do everything faster –
Fantastic!
 Once I began to
understand the DevOps
shift and that it means
more than a suite of new
tools, I began to feel a little
better
 Communication,
Collaboration and
Integration – these sound
like good things that we
can use more of
 Everyone is doing it –
How bad could it be?
A Light At The End of The Tunnel – But I Still Think It
Could Be A Train
 CIA – Confidentiality,
Integrity, Availability
 Slower is better
 Separation of Duties
 Documentation
 Security Says No!
Traditional Security 101
How Security Sees Itself
How Security Sees Development & Operations
How Development & Operations See Security
Security Says…
NO!!!
How We All Should Be Seen
Dev OpsSec
Faster releases means faster
security fixes
More automation = Less manual
processes (read less human error
& reduced insider threats)
More visibility and involvement
with stakeholders
Time For A Change
 Security not only embraces but leads a Security
driven DevOps Culture
 We control our own destiny rather than fight an
inevitable and uphill battle
 We manage by risk based approach – but still
achieve our compliance requirements
SecDevOps
DevOps Security
 Happens a lot faster, if not “real time”
 Automation
 Less Documentation
 “Blurred” segregation of duties
 Security needs to say yes with secure, flexible,
solutions that address CIA and not loose focus on
what we are really trying to protect
 Collaboration
• Work together so the output is
more like SecDevOps
 Communication
• Share what you are doing and
why
• Learn to speak the DevOps
language but share Security
perspectives too
 Innovation
• Work with to find solutions to
support traditional Security 101
goals while supporting new
methodologies
How Do We
Get There?
 It is happening one way
or the other – better to
control our own destiny
rather than fight an
uphill battle
 Let us all work
collaboratively to get
our needs met
 Let us show you how it
can benefit you
How Do We Sell This?
 Faster releases means
faster security fixes and
less vulnerabilities
 More automation = Less
manual processes (read
less human error &
insider threats)
 More visibility and
involvement with
stakeholders
CISO Benefits – If DevOps Security Is Done Right
Some Other Things To Consider
 Security leaders will need to invest time in the
transition so you can help meet existing security
requirements while supporting the mission
 Start small and prove this works
 Get the CISO onboard, he can be your biggest
advocate
 This is a huge shift – it will take time – practice
traditional organizational change management
techniques
 Lead by example
 More & Improved Collaboration
and Communication
 More open minds and increased
knowledge
 Flexible solutions that address the
intent of CIA while not getting
hung up on “Old School” and we
have always done it that way
methodologies
 Become change agents in the
security community (including risk
managers, auditors, compliance
professionals)
What Needs
To Change -
Security
 More & Improved Collaboration
and Communication
 Innovative ways to support
traditional security objectives
while embracing DevOps
 Put the “No” in Technology and
start speaking the language of
risk management
 Build in security through out the
entire DevOps Lifecycle
What Needs
To Change -
DevOps
Where To Start
 Focusing on technology and
ignoring organizational culture
 Lack of creativity
 Lack of executive support
 Only select teams/individuals
adopting new methodologies
 Loosing sight business goals and
desired outcomes
Cause of
Failure
 Proper training
 Starting small
 Alignment with business
 Creating a culture of agility
 Incremental improvement
 Focus on the intent of security
requirements
 Risk based approach
Cause of
Success
 Start today
• You invested the time in this session
– take the next step
 Avoid overthinking
• You don’t need to rollout the perfect
solution
 Iterative approach
• Crawl, Walk, Run
 Be constructively dissatisfied
• Deliver continuous improvement
 Lead by example & and build
controls into the process
Call to Action
Thank You!
 Help me spread the message to others
 Build security into your organizational DevOps
culture so that it looks more like SecDevOps
Please check me out on LinkedIn
http://www.linkedin.com/in/timvirtue
Or follow me on Twitter
https://twitter.com/timvirtue
 Tim Virtue
• Chief Information Security Officer
• Tim.Virtue@egov.comContact Me
DevOps:  Lead, Follow or Get Out of the Way - A CISO Perspective

Más contenido relacionado

La actualidad más candente

Mistake proofing presentation
Mistake proofing presentation Mistake proofing presentation
Mistake proofing presentation leanadvisors
 
Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...Google
 
Agile is all about learning
Agile is all about learningAgile is all about learning
Agile is all about learningDavid Michel
 
Innovation Decentralized
Innovation DecentralizedInnovation Decentralized
Innovation DecentralizedSalesforce.org
 
Cloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security PractitionerCloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security PractitionerAdrian Sanabria
 
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detectionAgile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detectionMichael Palotas
 
Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)Angie Chang
 
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPackCONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPackDevOpsDays Tel Aviv
 
Colin Domoney -
Colin Domoney -  Colin Domoney -
Colin Domoney - DevSecCon
 
How to Build a Healthy On-Call Culture
How to Build a Healthy On-Call CultureHow to Build a Healthy On-Call Culture
How to Build a Healthy On-Call CultureAtlassian
 
Quality Without Heroics
Quality Without HeroicsQuality Without Heroics
Quality Without HeroicsThoughtworks
 
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"David Dylan Thomas
 
10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthostsInternet World
 

La actualidad más candente (16)

Mistake proofing presentation
Mistake proofing presentation Mistake proofing presentation
Mistake proofing presentation
 
DevOps not a Toolbox
DevOps not a ToolboxDevOps not a Toolbox
DevOps not a Toolbox
 
Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...Integrating Project Management with Service Management Best Practices Event B...
Integrating Project Management with Service Management Best Practices Event B...
 
Agile is all about learning
Agile is all about learningAgile is all about learning
Agile is all about learning
 
Innovation Decentralized
Innovation DecentralizedInnovation Decentralized
Innovation Decentralized
 
Cloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security PractitionerCloud, DevOps and the New Security Practitioner
Cloud, DevOps and the New Security Practitioner
 
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detectionAgile bodensee - Agile Testing: Bug prevention vs. bug detection
Agile bodensee - Agile Testing: Bug prevention vs. bug detection
 
Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)Girl Geek X Indeed Talks (January 18, 2018)
Girl Geek X Indeed Talks (January 18, 2018)
 
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPackCONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
CONFIGURATION MANAGEMENT IN THE CLOUD NATIVE ERA, SHAHAR MINTZ, EggPack
 
Colin Domoney -
Colin Domoney -  Colin Domoney -
Colin Domoney -
 
How to Build a Healthy On-Call Culture
How to Build a Healthy On-Call CultureHow to Build a Healthy On-Call Culture
How to Build a Healthy On-Call Culture
 
Quality Without Heroics
Quality Without HeroicsQuality Without Heroics
Quality Without Heroics
 
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
Agile Living: Or How I Learned to Stop Worry and Never Be "Done"
 
Lean
LeanLean
Lean
 
Brians Presn
Brians PresnBrians Presn
Brians Presn
 
10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts10-steps to the cloud for SMBs, fasthosts
10-steps to the cloud for SMBs, fasthosts
 

Similar a DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Brian Harden
 
Effective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptxEffective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptxRezi Purnama
 
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...FiSTB
 
Applying Lean Security To The Business
Applying Lean Security To The BusinessApplying Lean Security To The Business
Applying Lean Security To The BusinessAndrew Storms
 
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...Scrum Day Bandung
 
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps SolutionsLet’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps SolutionsCerebrum Infotech
 
Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Security Innovation
 
A Culture Transformed: Instilling DevOps Ways of Working
A Culture Transformed:  Instilling DevOps Ways of Working A Culture Transformed:  Instilling DevOps Ways of Working
A Culture Transformed: Instilling DevOps Ways of Working Christine (Chrys) Sills
 
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon
 
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's PerspectiveDevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's PerspectiveCprime
 
DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015Shannon Lietz
 
Practically applying agile
Practically applying agilePractically applying agile
Practically applying agileEduserv
 
DevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile ManagementDevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile ManagementInspectie van het Onderwijs
 
The Journey to DevSecOps
The Journey to DevSecOpsThe Journey to DevSecOps
The Journey to DevSecOpsShannon Lietz
 

Similar a DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective (20)

Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019Its not a bug it's a feature - Seattle B sides 2019
Its not a bug it's a feature - Seattle B sides 2019
 
Effective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptxEffective-Safety-Culture from System - leadership - culture.pptx
Effective-Safety-Culture from System - leadership - culture.pptx
 
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...Huib Schoots Testing in modern times - a story about Quality and Value - Test...
Huib Schoots Testing in modern times - a story about Quality and Value - Test...
 
Applying Lean Security To The Business
Applying Lean Security To The BusinessApplying Lean Security To The Business
Applying Lean Security To The Business
 
DevOps for Managers
DevOps for ManagersDevOps for Managers
DevOps for Managers
 
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
How (can) Scrum and DevOps Walk Together to Build a High-Quality Product Deli...
 
Modeling and Measuring DevOps Culture
Modeling and Measuring DevOps CultureModeling and Measuring DevOps Culture
Modeling and Measuring DevOps Culture
 
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps SolutionsLet’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
Let’s Talk With Luis Jaime Gomez Vazquez About DevOps Solutions
 
Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?
 
A Culture Transformed: Instilling DevOps Ways of Working
A Culture Transformed:  Instilling DevOps Ways of Working A Culture Transformed:  Instilling DevOps Ways of Working
A Culture Transformed: Instilling DevOps Ways of Working
 
What is DevOps?
What is DevOps?What is DevOps?
What is DevOps?
 
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
 
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's PerspectiveDevSecOps Value & Its Organizational Impact: A CSO's Perspective
DevSecOps Value & Its Organizational Impact: A CSO's Perspective
 
DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015DevSecCon KeyNote London 2015
DevSecCon KeyNote London 2015
 
DevSecCon Keynote
DevSecCon KeynoteDevSecCon Keynote
DevSecCon Keynote
 
Practically applying agile
Practically applying agilePractically applying agile
Practically applying agile
 
Top 10 devops values
Top 10 devops valuesTop 10 devops values
Top 10 devops values
 
Introduction to DevOps
Introduction to DevOpsIntroduction to DevOps
Introduction to DevOps
 
DevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile ManagementDevOps unraveled - Nyenrode masterclass on Agile Management
DevOps unraveled - Nyenrode masterclass on Agile Management
 
The Journey to DevSecOps
The Journey to DevSecOpsThe Journey to DevSecOps
The Journey to DevSecOps
 

Más de Texas.gov

Beyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile CapabilitiesBeyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile CapabilitiesTexas.gov
 
Mobile Trends
Mobile TrendsMobile Trends
Mobile TrendsTexas.gov
 
Texas.gov Presents: Battle of Programming Languages
Texas.gov Presents:  Battle of Programming LanguagesTexas.gov Presents:  Battle of Programming Languages
Texas.gov Presents: Battle of Programming LanguagesTexas.gov
 
Fee Pay Lite Screenshots
Fee Pay Lite ScreenshotsFee Pay Lite Screenshots
Fee Pay Lite ScreenshotsTexas.gov
 
Commissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo SlidesCommissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo SlidesTexas.gov
 
Hackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve ResultsHackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve ResultsTexas.gov
 
Texas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common GoalTexas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common GoalTexas.gov
 
NACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you ComputeNACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you ComputeTexas.gov
 
THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?Texas.gov
 

Más de Texas.gov (9)

Beyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile CapabilitiesBeyond Strategy: Building Your Mobile Capabilities
Beyond Strategy: Building Your Mobile Capabilities
 
Mobile Trends
Mobile TrendsMobile Trends
Mobile Trends
 
Texas.gov Presents: Battle of Programming Languages
Texas.gov Presents:  Battle of Programming LanguagesTexas.gov Presents:  Battle of Programming Languages
Texas.gov Presents: Battle of Programming Languages
 
Fee Pay Lite Screenshots
Fee Pay Lite ScreenshotsFee Pay Lite Screenshots
Fee Pay Lite Screenshots
 
Commissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo SlidesCommissary Shopping Cart Demo Slides
Commissary Shopping Cart Demo Slides
 
Hackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve ResultsHackathons: Embracing Collaboration to Achieve Results
Hackathons: Embracing Collaboration to Achieve Results
 
Texas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common GoalTexas.gov - Using Hackathons to Work Together Towards a Common Goal
Texas.gov - Using Hackathons to Work Together Towards a Common Goal
 
NACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you ComputeNACRC 2013 | Cloud Technology: Do you Compute
NACRC 2013 | Cloud Technology: Do you Compute
 
THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?THE ROAD FORGOTTEN: What's the roadmap for your website?
THE ROAD FORGOTTEN: What's the roadmap for your website?
 

Último

Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 

Último (20)

Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 

DevOps: Lead, Follow or Get Out of the Way - A CISO Perspective

  • 1. 1 DevOps: Lead, Follow, Or Get Out of the Way A CISO Perspective Presented by: Tim Virtue CISO, Texas.gov
  • 2. The Lawyers Made Me Do It  Any references to specific organizations, people, products, or services, are purely examples or learning opportunities and neither criticisms nor endorsements  The views presented are strictly my own and may or may not represent any organizations or affiliations I have (mostly because they have not seen the light yet )  It’s OK to agree to disagree, but anyone who gets that worked up over slides needs a vacation
  • 3. ABC Soup & Street Cred  CISSP, CCSK, CISA, CIPP/G, CFE, ITIL V3, CVE, QGVM, blah blah blah…  Over 15 years experience in Security, Risk Management and IT  Executive Master of Science in Information Systems from a top business school  Cyber Security Instructor, Author & Speaker  Not bragging – just showing perspective & credibility – if DevOps can sell me, you can sell it to the greater security community and your organization
  • 4.  Something to be ignored  Something Security should try and stop  Something done in isolation  A system or tool implementation What DevOps Is Not
  • 5. What is DevOps?  Many things to many people  A trendy buzzword, but with a powerful ideology  Not just for “The Unicorn Companies”  For today, lets focus on key concepts such as Agile, Culture, Quality, Automation & Tools  For a great in depth discussion read “What Is DevOps?” by the Agile admin: http://theagileadmin.com/what-is-devops/
  • 6. DevOps: My Initial Thoughts 3 Ring Circus Like I didn’t have enough problems when they (Development & Operations) worked independently – now they want us to work together – Seriously??? Puppets, Chefs, & Vagrants – These are now in the environment – I don’t know what this means, but your telling me not to worry – Really??? We struggle with a few security basics already – and now you want to do everything faster – Fantastic!
  • 7.  Once I began to understand the DevOps shift and that it means more than a suite of new tools, I began to feel a little better  Communication, Collaboration and Integration – these sound like good things that we can use more of  Everyone is doing it – How bad could it be? A Light At The End of The Tunnel – But I Still Think It Could Be A Train
  • 8.  CIA – Confidentiality, Integrity, Availability  Slower is better  Separation of Duties  Documentation  Security Says No! Traditional Security 101
  • 10. How Security Sees Development & Operations
  • 11. How Development & Operations See Security Security Says… NO!!!
  • 12. How We All Should Be Seen Dev OpsSec
  • 13. Faster releases means faster security fixes More automation = Less manual processes (read less human error & reduced insider threats) More visibility and involvement with stakeholders
  • 14. Time For A Change
  • 15.  Security not only embraces but leads a Security driven DevOps Culture  We control our own destiny rather than fight an inevitable and uphill battle  We manage by risk based approach – but still achieve our compliance requirements SecDevOps
  • 16. DevOps Security  Happens a lot faster, if not “real time”  Automation  Less Documentation  “Blurred” segregation of duties  Security needs to say yes with secure, flexible, solutions that address CIA and not loose focus on what we are really trying to protect
  • 17.  Collaboration • Work together so the output is more like SecDevOps  Communication • Share what you are doing and why • Learn to speak the DevOps language but share Security perspectives too  Innovation • Work with to find solutions to support traditional Security 101 goals while supporting new methodologies How Do We Get There?
  • 18.  It is happening one way or the other – better to control our own destiny rather than fight an uphill battle  Let us all work collaboratively to get our needs met  Let us show you how it can benefit you How Do We Sell This?
  • 19.  Faster releases means faster security fixes and less vulnerabilities  More automation = Less manual processes (read less human error & insider threats)  More visibility and involvement with stakeholders CISO Benefits – If DevOps Security Is Done Right
  • 20. Some Other Things To Consider  Security leaders will need to invest time in the transition so you can help meet existing security requirements while supporting the mission  Start small and prove this works  Get the CISO onboard, he can be your biggest advocate  This is a huge shift – it will take time – practice traditional organizational change management techniques  Lead by example
  • 21.  More & Improved Collaboration and Communication  More open minds and increased knowledge  Flexible solutions that address the intent of CIA while not getting hung up on “Old School” and we have always done it that way methodologies  Become change agents in the security community (including risk managers, auditors, compliance professionals) What Needs To Change - Security
  • 22.  More & Improved Collaboration and Communication  Innovative ways to support traditional security objectives while embracing DevOps  Put the “No” in Technology and start speaking the language of risk management  Build in security through out the entire DevOps Lifecycle What Needs To Change - DevOps
  • 24.  Focusing on technology and ignoring organizational culture  Lack of creativity  Lack of executive support  Only select teams/individuals adopting new methodologies  Loosing sight business goals and desired outcomes Cause of Failure
  • 25.  Proper training  Starting small  Alignment with business  Creating a culture of agility  Incremental improvement  Focus on the intent of security requirements  Risk based approach Cause of Success
  • 26.  Start today • You invested the time in this session – take the next step  Avoid overthinking • You don’t need to rollout the perfect solution  Iterative approach • Crawl, Walk, Run  Be constructively dissatisfied • Deliver continuous improvement  Lead by example & and build controls into the process Call to Action
  • 27. Thank You!  Help me spread the message to others  Build security into your organizational DevOps culture so that it looks more like SecDevOps Please check me out on LinkedIn http://www.linkedin.com/in/timvirtue Or follow me on Twitter https://twitter.com/timvirtue
  • 28.  Tim Virtue • Chief Information Security Officer • Tim.Virtue@egov.comContact Me