Showing posts with label DevOps. Show all posts
Showing posts with label DevOps. Show all posts

Thursday, October 31, 2019

Cyber Security As a Shared Service


Organizations often have a hard time wrapping their heads around the right placement for cyber security programs. But cyber security isn’t unique. 


Cyber is just one of many shared services.

Cyber
IAM.
DevOps.

All conceptually different but sharing an origin and continuing linkage to IT. That said, each also transcends IT in modern product driven enterprises. All part of the continuing conversation across the organization.

Saturday, October 12, 2019

Cattle Versus Pets In Securing DevOps Pipelines


Securing a devops pipeline can often be regarded as a special cyber security use case.



The thinking behind the specialness of that use case is that security within the development pipeline is so important that securing devops warrants having its own process. We even see security sometimes included in the name, devsecops. 

But devops is a business process. 

Just one of N key and critical business processes in the enterprise.

Although securing devops pipelines requires some specialized dev and build process knowledge, devops is simply one part of a security ecosystem that shares similar needs and requirements with a lot of other complex and sensitive business processes that also need to be secured. 

Common needs. Common process.

Identity and access.
Unauthorized sensitive data exposure.
Activity anomalies.
Compensating controls.

So, the security program methodology and process needs to transcend devops and escale across all business processes in the enterprise in a standardized way.  Like cattle, in herds.

Standards development.
Governance during execution
Common metrics.

If security programs maintain a very boutique approach for devops and have to establish different processes for the rest of the enterprise, the program won't scale. Each secured process will need individual attention very similar to pets.

Cattle versus pets. 

The additional work in developing scalable approaches is worth the time and resource savings.

Your program. Your scale.Your results.

Follow me on Twitter for discussion and the latest blog updates: @Opinionatedsec1. Or, start your own discussion using #crazygoodcyberteams on twitter or Linkedin and I'll read it.

SEE ALSO




Sunday, September 8, 2019

Unit Tests Won’t Tell You The Customer Experience


After furnishing houses in three countries over the past 12 years, I’ve bought more than my share of televisions over that time. It’s football season in the US and, despite my preference for a different brand, my local Costco rep and some promotional pricing convinced me to bring home a 2019 model LG TV.




Love the specs, image quality, and the TV in general, but….

Wednesday, August 28, 2019

An Application Security Defect Misunderstanding


Functional software defects and security defects aren’t different.



Both born from developers. Found with automated tools. Neither achieving a standard. 

Same remediation process. 

Yet, treated differently. In process. In perception. 


Monday, August 19, 2019

The Secure DevOps Edge


When one can see the edges, DevOps can be both a beautiful thing as well as a beautiful experience. 





Like all beautiful things or experiences, the beauty is found and defined at the edges. The iPhone, the Chris Craft, the steep cliff.  All beautiful because of their edges and because of the edges of the experience. The feel in the hand. The wind in the hair. The looks from others.


But to see the edges and be safe, you have to have vision. The vision to see what it is or express what it can be so it can be formed in the mind of others. No one talks about an iPhone by focusing on what it is not. No one hangs off the edge of a mountain because of what it is not.


No one has ever been successful at DevOps by having a vision around what it is not.