Best Practices for securing CI/CD Pipelines or how to get Security right | Victoria Almazova

  Рет қаралды 16,610

DevOps Conference

DevOps Conference

Күн бұрын

Speaker: Victoria Almazova (Microsoft) | devopsconferen...
DevOps practices are in a place, containers are everywhere, pipelines are flying. We do Agile. We do DevOps. Now we should focus on following security practices for protecting the deployed resources, too. This is a reason why DevSecOps is not a hype anymore and is gaining more prominence. There is a lot of information about DevSecOps, but how to do it properly? Where to start? What are the best practices?
In this session, we will walk through an end-to-end scenario where we will deploy infrastructure components and solutions securely to the cloud. We will build a pipeline with security in mind to protect and detect potential security flaws during the build. We will focus on main the principles that you can apply to the most popular and used solutions and tools.
You will learn essential concepts:
how to build an end-to-end CI/CD pipeline that builds the application and deploys infrastructure with security checks for the application, containers, and infrastructure;
what security tools are available for CI/CD pipelines and the best way to implement them into different Git workflows;
best practices and patterns of building security pipelines.
🤗 Join us at the next DevOpsCon: devopsconferen... | The Conference for Continuous Delivery, Microservices, Containers, Cloud & Lean Business
👉 Follow us on Twitter: / devops_con
👍 Like us on Facebook: / devopscon

Пікірлер: 17
@chivaljazz
@chivaljazz 2 жыл бұрын
Just cracked an interview of Devops with just your explanation and keywords. Victoria you are great
@bobby7739
@bobby7739 2 ай бұрын
Great presentation. Thanks for sharing and keeping this available.
@firmsoil7861
@firmsoil7861 4 жыл бұрын
Don't ever loose your fantastic sense of humor!
@djmoreno1100
@djmoreno1100 Жыл бұрын
Just watched the way through, great presentation. Will go back an take more notes soon. This info was very helpful. Thanks again.
@krneki6954
@krneki6954 3 жыл бұрын
even though it was about security, somehow i didnt fall asleep watching it. very nicely done. thank you!
@Numulagam
@Numulagam 2 жыл бұрын
lovely chart and movement of tasks around pipeline. thanks for being openminded to share and educate. regards from Singapore!
@andreelyusef3235
@andreelyusef3235 2 жыл бұрын
OMG as a cloud security person this is the story of my life!!
@djmoreno1100
@djmoreno1100 Жыл бұрын
Peace to the god.
@tiv4618
@tiv4618 2 жыл бұрын
What's interesting is there is an emphasis on a safe product. This would require a 'DevSafeSecOps' process to be implemented to consider safety properties of a system and safety analysis to be carefully considered as part of an agile process, especially for a safety related product or service.
@djmoreno1100
@djmoreno1100 Жыл бұрын
"How many of you have SUCCESSFULLY implemented DevOps?" @ 3:56. ....hilarious. Good vid.
@kanuj.bhatnagar
@kanuj.bhatnagar 2 жыл бұрын
While this talk places a lot of emphasis on the security to go shift-left in the software development cycle, there's no major mention of protection/security of data within those applications. PII data, for example. What're the best practices to ensure security of something as sensitive as the customer's addresses, phone numbers etc?
@emilesalem2558
@emilesalem2558 Жыл бұрын
I'm a bit confused as to why we should not stop continuous integration on security issues. I thought DevSecOps was about involving everyone in security. Isnt breaking the build the best way to involve devs? If the tools cause too much noise, isn't the problem with the tools? I guess it all depends on the team size. I can see in a 100:10:1 organization, you wouldn't want to stop CI on security checks. But in a 10:2:2 organization, it seems reasonable to fail builds.
@vichiees
@vichiees 4 жыл бұрын
very informative
@riccardo-964
@riccardo-964 Жыл бұрын
Every time she said "DevOps" I heard the "Devils" which are not that far apart really
10 ай бұрын
Reaching 30% of the talk and I hear her speaking about quite basic and obvious security things. And now I m reflecting on her special number 100:10:1 sort of complaining that 1 security is not enough and a daunting role to work alone with the other 10 and 100 devs. I find it a little bit pretentious, if not insulting, to assume that only her, as a security role, would only be concerned let alone be able to apply the best practices of security. Isn't it what a good developer should and probably taking into considerations in his/her everyday work?
Security in CI CD Pipelines: Tips for DevOps Engineers
57:05
Techstrong TV
Рет қаралды 4,7 М.
Players vs Corner Flags 🤯
00:28
LE FOOT EN VIDÉO
Рет қаралды 91 МЛН
🍉😋 #shorts
00:24
Денис Кукояка
Рет қаралды 3,8 МЛН
pumpkins #shorts
00:39
Mr DegrEE
Рет қаралды 74 МЛН
Как мы играем в игры 😂
00:20
МЯТНАЯ ФАНТА
Рет қаралды 3,4 МЛН
Life of a DevSecOps Engineer (w/ Aras "Russ" Memisyazici)
1:06:45
Cyberspatial
Рет қаралды 49 М.
THE THREE DISCIPLINES OF CI/CD SECURITY // DANIEL KRIVELEVICH
17:41
DevOpsDays Tel Aviv
Рет қаралды 2,7 М.
The IDEAL & Practical CI / CD Pipeline - Concepts Overview
22:36
Be A Better Dev
Рет қаралды 483 М.
The Three Faces of DevSecOps
42:14
InfoQ
Рет қаралды 15 М.
CI/CD: Top 10 Security Risks
31:55
RSA Conference
Рет қаралды 1,9 М.
Your CI/CD Pipelines Are Wrong - From Monoliths To Events
22:41
DevOps Toolkit
Рет қаралды 13 М.
A Cloud Security Architecture Workshop
52:00
RSA Conference
Рет қаралды 73 М.
Automating Security in Cloud Workloads with DevSecOps [SEC303]
57:53
Amazon Web Services
Рет қаралды 13 М.
Players vs Corner Flags 🤯
00:28
LE FOOT EN VIDÉO
Рет қаралды 91 МЛН