2017 DevOpsDays Chicago Talk
At DevOpsDays Chicago 2017 I gave a talk titled “Security, Don’t Fear The DevOps”. There’s a video online on YouTube. I had the good luck to be involved in DOD Chicago when it started up (before I moved to Portland) and I’ve got a love of that group, so I was super excited to get chosen to speak.
Abstract
A lot of security people have a bad attitude about DevOps. Heck, sometimes it’s for good reasons. Lots of vendors are selling “DevOps in a box”, they’ll come in and “do the DevOps for you”, etc. What can you end up with? Lots of people with root access to servers with real data on them, code being deployed straight into production without appropriate testing, dogs and cats living together, mass hysteria!
I’m here to show you that it doesn’t have to be that way. I come armed with data from several years of the State of DevOps Report that shows how enterprises are finding security wins in embracing DevOps. I’ll show results of that survey and talk about trends in what we’ve seen. As well, I’ll talk about processes that a security team can put into place to make measurable wins for their infosec program. Not in security? I’ll show you what you can do to help out and start shipping better software or services. This isn’t just for web app shops either, we’ll talk about doing this in enterprise IT where you don’t get the luxury of writing everything you have to run.