GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deployment Firewall and DBOM
JamesAnderson135
93 views
18 slides
Jun 03, 2024
Slide 1 of 18
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
About This Presentation
Effective Application Security in Software Delivery lifecycle using Deployment Firewall and DBOM
The modern software delivery process (or the CI/CD process) includes many tools, distributed teams, open-source code, and cloud platforms. Constant focus on speed to release software to market, along wi...
Effective Application Security in Software Delivery lifecycle using Deployment Firewall and DBOM
The modern software delivery process (or the CI/CD process) includes many tools, distributed teams, open-source code, and cloud platforms. Constant focus on speed to release software to market, along with the traditional slow and manual security checks has caused gaps in continuous security as an important piece in the software supply chain. Today organizations feel more susceptible to external and internal cyber threats due to the vast attack surface in their applications supply chain and the lack of end-to-end governance and risk management.
The software team must secure its software delivery process to avoid vulnerability and security breaches. This needs to be achieved with existing tool chains and without extensive rework of the delivery processes. This talk will present strategies and techniques for providing visibility into the true risk of the existing vulnerabilities, preventing the introduction of security issues in the software, resolving vulnerabilities in production environments quickly, and capturing the deployment bill of materials (DBOM).
Speakers:
Bob Boule
Robert Boule is a technology enthusiast with PASSION for technology and making things work along with a knack for helping others understand how things work. He comes with around 20 years of solution engineering experience in application security, software continuous delivery, and SaaS platforms. He is known for his dynamic presentations in CI/CD and application security integrated in software delivery lifecycle.
Gopinath Rebala
Gopinath Rebala is the CTO of OpsMx, where he has overall responsibility for the machine learning and data processing architectures for Secure Software Delivery. Gopi also has a strong connection with our customers, leading design and architecture for strategic implementations. Gopi is a frequent speaker and well-known leader in continuous delivery and integrating security into software delivery.
OpsMx secures and intelligently automates software delivery
from developer to deployment, building on an
Open Software Delivery architecture and Al/ML-powered DevSecOps
QUE A O =
lel Google RE FAN Adobe ZE,
= OpsMx Delivery Shield
OpsMx Delivery Shield secures your application
lifecycle with continuous security posture
management, global visibility, and policy
enforcement.
AppSec Today
+ Too many tools that don't work together
e Disjointed data - no unified view
e “Shift Left” slowing down developers
OpsMx Offers
+ Faster, more secure application releases
e Automated compliance and enforcement
e Lower overall cost of AppSec
7 OpsMx
Security App Dev DevOps
OpsMx Delivery Shield
Application Security Posture Management
bata eco ooops Toe |
“an tect
Software Development Lfecycie
= Managing Application Security
In a DevOps World
à 2: BUILD -8- DEPLOY |-»[ OPERATE |
7% OpsMx
Old World
+ Centralized teams
+ Consistent Dev environment
Monolithic applications
« One path to production
= Managing Application Security 7% OpsMx
In a DevOps World
= Managing Application Security FX OpsMx
In a DevOps World
Service-based architecture
Frequent releases to multiple targets
Teams choose DevOps tools
Shift left security responsibilities
= AppSec Challenges We Hear
=s “Choose Your Own Adventure”
— Every team is using different
=e
— tools, different processes
Siloed Visibility
We have all the data that we
need, but it is siloed in separate
tools and data sets
fe)
80
Too Many Alerts
Each tool generates its own
alerts, but no rationalization
across them
7% OpsMx
Every Tools Adds Cost, Complexity
How can | stop paying for some
of the tools that | pay for today?
Overloaded Developers
“Shift Left” overloads
developers without reducing
security risks
Security Effectiveness
No good way to show the
overall results of the security
program.
= Challenges Addressed by OpsMx #YopsMx
SecOps / DevOps CISO / Exec Mgmt
+ Detect, prioritize, e = Shift-left without « Global security
remediate security burdening developers visibility
threats e Fits in the existing e Audit reports with
e Automated checks / SDLC workflow compliance checklist
controls e Security / fix e Easy to implement with
e Shift-left security recommendations to existing tools, central
e Blocks vulnerable Developers management
deployments + Developer visibility and e Lower TCO
+ Continue to leverage productivity + Eliminate tool sprawl