DevSecOps - Automating Security in DevOps
By : Jovin Lobo
Date: 11 Jun 2021
Time: 04:00 p.m.
Security is often added towards the end, in a typical DevOps cycle through a manual/automated review. In DevSecOps, security can be injected at every stage of a DevOps pipeline in an automated fashion. Having a DevSecOps pipeline enables an organization to
- Create a security culture amongst the already integrated “DevOps” team.
- Find and fix security bugs as early as possible in the SDLC.
- Promote the philosophy “Security is everyone’s problem” by creating Security champions within the organization.
- Integrate all security software centrally and utilize the results more effectively.
- Measure and shrink the attack surface.
In this talk, we shall focus on how a DevOps pipeline can easily be metamorphosed into a DevSecOps and the benefits which can be achieved with this. The talk will discuss a number of open-source tools and also the cultural changes needed to implement DevSecOps. The talk will also present various case studies on how critical bugs and security breaches affecting popular software and applications could have been prevented using a simple DevSecOps approach.
Jovin is an information security professional working as a Sr. Security Consultant at NotSoSecure. He has over 9 years of experience and specializes in Network and Application Security Assessments. In the recent past, he has been exploring the fascinating world of DevSecOps.
He has spoken at conferences like Cocon, nullcon, and GNUnify in the past. He loves exploring new technologies and enjoys scripting & coding.