Navigating Cybersecurity: Insights from Industry Experts Caroline Wong & Nariman Aga-Tagiyev | DevOps Experience 2024
Transcript
Hi, my name is Caroline Wong. I'm the Chief Strategy Officer at Cobalt. I am delighted to be here with my friend Naren.
And today what we're gonna talk about is Oasp Sam. So I wanted to start out by sharing. I started my security career nearly two decades ago, leading information security teams at eBay and at Zynga these were incredible places to be working in cybersecurity.
And in both cases we were running online operations 24 by seven with millions of simultaneous users daily. 4% and is one of the first major electronic commerce shops enabled strangers to transact with each other over the internet. Zingo was growing incredibly rapidly as an early adopter of Amazon AWS.
In 2009, the Zynga game Farmville launched, and in just a few weeks, the game went from zero to 10 million daily active users. A few months later, it rose to 80 million daily active users. After eBay and Zynga, I published a book on security metrics, led a global product management team at Symantec, performed software security assessments at sgit.
And in 2016, I joined Co mal, where I currently oversee our delivery teams. I am so excited to introduce my friend Mann Ariman Riman and I met recently in San Francisco at the Thread Mod Con Threat Modeling Connect conference, and we discovered that we have a shared passion for frameworks and maturity models. Ariman, why don't you go ahead and introduce yourself.
Thank you Karlin so much. I'm very exciting for this podcast and to address our DevOps community. Uh, 'cause I have been in software development for a bit more than 20 years now.
I did it all. I did competitive programming. I did backend front end.
I did DevOps work for many years. I did cloud development and last eight years. I'm very closely involved in cybersecurity, doing that now, full-time, uh, but still sitting together with my DevOps friends and still the same room, uh, in my office.
And I work closely with them as cybersecurity architect. Uh, the company I work for, it's a huge corporate for European standards. Uh, we have about 8,000 developers, 25,000 people globally.
And my challenge, my goal, my role there is to roll out a scalable maturity program for application security. I do often see challenges that my DevOps colleagues, uh, having and want to talk a bit today about it. Um, so share with you Caroline, and with our audience, uh, in particular, if you want me to start with that.
Uh, my observation, uh, we are asked these days to adapt our build pipeline and to introduce security tools. If you are not asked, probably you are in the wrong organization. It's very hot topic.
Uh, all of companies these days expect that SaaS tool, dust tool, SCA tool, uh, scanners, uh, secret management, secret identification tools. But what I see is company invests a lot of money, but then, and we as DevOps guys, girls put lots of effort, but then these tools are hanging there and developers sometimes check them, sometimes not unless security officer or architect like me go after them and say, are you cleaning up the queue? Are you cleaning up the criticals or not?
Of course there are very mature companies that have this automated process, but I'm talking about this orange company that have a tool but not doing anything about it. And as a result, I believe that return on investment is very low and we need to look in a bigger picture. Like why, why developers or our our colleagues, non develop colleagues don't look at this.
So the finding the problems is easy. So you can in automate the tools and you can find more and more issues of problems, but it's hard to motivate the people to take the action for this. As I said, bigger picture is important and we need to have a right buy-in from management.
And the governance activities on cybersecurity side is very important. We need to make sure that software architects are involved, that we have a security champions program in place, that, uh, the, that we have some verification state activities that QA people are very interested to verify and look, uh, that from security perspective, quality gate are met. So there is a lot of stuff going on, and if you're only focusing on pushing your DevOps agenda, we will not succeed.
So we need to look at the big picture. And since 16th, the last eight years, uh, initially I was introduced to bce and I believe Caroline is your expertise domain. Uh, b and o ask these two frameworks.
We will tell about, about them in the moment. These two frameworks help you to assess where you stand in a company from cybersecurity maturity perspective, understand what's going on, and then plan with a very small steps how to improve for every each organization separately. Um, so I would suggest Lin, would you like to give few words about BCM?
Because we can share a screen, we can ex explain exactly what this framework is, and perhaps we influence more people to join us in this, uh, in this project. Yeah, so Mann and I are so excited to talk to you about oasp. Sam, you know, I wanna just actually share a couple of stories.
You know, reman made the observation, it's actually quite easy to find security problems. We have so many tools to do this, you know, and I remember when I was leading teams, security teams at eBay, we are hiring penetration testers. We have a responsible disclosure program.
We have many different scan types, and what happens is we actually build up these mountain of bugs. You know, this was a time when everyone is going into the office. And I remember thinking to myself, okay, the best way that I can get a developer to take some action on these bugs, I will go and I find their desk and I sit on their desk and I wait until they will come talk to me about it, you know, and maybe the next day I buy them a coffee or a cookie or something like this.
But actually this doesn't scale. The other place that I wanna share about is when I was at Zynga, at this time, I am reporting to the chief information security officer. The chief information security officer is reporting to the CIO.
And the CIO says to the chief information security officer, Hey, you, you have a lot of smart people on your team, and they seem to be really busy, but how could I possibly know if they are working on the right things? As Reman mentioned, I do have extensive experience with bs. Im, I had the pleasure of conducting more than three dozen bcim assessments.
And so that is where my familiarity with software security maturity models come up. So now what we'd like to do is introduce a little bit about oasp, Sam Ariman. Can you tell us what is a maturity framework and how does a maturity model help with software development?
Right? So here I give two examples on this page, but basically maturity framework, it's a structured way to assess what are doing for security. Uh, it helps you to the assessment, uh, especially is based on that.
It has a tools for that and the questions, the criteria to that assessment. And it has tools to help you to build your roadmap in a very small incremental steps. You can make plans face by face where you want to focus on, you do right prioritization with the right metrics.
Um, Caroline Wong a book about metrics, by the way, uh, that's very important for prioritization. And as you go, you reassess and your development teams will feel like they have some progress. The are only two competitors I'm showing here are Simon Oasp is a community driven project with lots of great people that are there to support you.
Uh, they have community calls there on conferences. This is a living project all the time. Shall we go to the next slide?
Uh, Carle, We shall. And actually just with that, I wanna provide one, um, difference about SAM and about besim. So whereas BS IM is a descriptive model, SAM is actually a prescriptive model.
Um, and there is a specific advantage, uh, to the prescriptive model of sam, uh, which I'll ask NAND for you to talk to us about. Uh, so what is this mappings all about, Right? So if you want to get an ISO certification or if your organization already has some frameworks that they want to comply, like NIST cybersecurity framework, um, you have to compete against them in the beginning.
But actually, if you want to get this ISO dismissed, the SAM is a place to start because it is a, as I say, prescriptive model. Um, it is explains how to reach there. You divide in small steps for every step.
There are community driven guidelines where you can find exact explanation how to achieve it. And of course there are lots of communities calls Slack channels where we can ask questions. So we all together as a security industry are helping to improve the overall maturity of our companies.
Of course, target audience here today are DevOps people, but I assume you have some interest with security if you are listening to this particular, uh, session. So if you are interested in security, as I said, you need to look at the bigger picture and not focus only on DevOps part. That's why we are talking about this ISO and, uh, frameworks.
Uh, 'cause probably it's time to push and time to promote more an organization to change the culture of the organization. And we are showing you different tools and how this framework can be used in your organization. Yeah, you know, I just wanna add a quick comment, which is to say, I think that when developers are looking at security activities and trying to, to decide what should I prioritize, I have limited time and I want to focus my attention on the most important things.
I do think that a model like this can be important so that a person or a team can consider the different activities to be done. Um, I think that there's a very difficult question to ask when it comes to cybersecurity, which is how much should we do and why? Uh, and I think one way to look at it is to use benchmarking to look at, okay, what, what sorts of things is our competition doing?
What sorts of things are our peers doing? And so Norman, I'll I'll invite you to, to tell our audience a little bit about the model that we have here. Okay, so as DevOps engineer, probably you are involved in the implementation category, secure build, secure deployment to make sure that the build process is secure, that your deployment is secure.
But if you're not happy and you see that there, there are some gaps, as I said, you need to focus on the bigger picture. And on this model you can see all other categories that we need to promote. Like for example, governance, all the, the buy in topics, the training, the security champions program.
In the design phase, when you start a new software, you want to do threat modeling. You want to assess the risks early enough. In implementation phase comes the place, the secure build, secure deployment, verification activities, the QA work, the assessment.
And after release you have the operations activities. So this model covers all of them. And as DevOps engineer, if you want to make a difference in the company and you want to promote improvement on cybersecurity side as well, my suggestion will be to take a SAM assessment form and without first getting the permission to use it for the full organization, do a same assessment for your department, for your business unit.
Invite somebody responsible for governance, for design developers, architects, and for verification for operations. See what is your score from one to three, from zero to three. And you'll be seen as this proactive person that is thinking about the security posture of the company.
And you can demonstrate where your gaps are. And probably then your scope will, of course you will still specialize on DevOps, but you will demonstrate the big picture, like where the problems are and why DevOps tools will introduce aren't so effectively used. Okay.
Okay. So this a bit, uh, deep diver to the, to the model. It has business functions, as I explained, for each function has group of practices divided in categories and each of them have streams.
Can also go to next slide please, Caroline. Okay. org, you can find exact description, what is the benefit of activity and what is activity all about, how it's supposed to be done.
There also guidelines, how to implement it. And every activity is actually divided into multiple levels of maturity. So the level one of that activity would be about what you should do as bare minimum level two is what you should do as a good company that cares about security.
And level three is when you're expert in security. In the next page, I can show you example for a demonstrated topic. For example, for secure build on level one, what is expected from you, the question is your full build process formally described.
Um, it should be clarity, right? org, the model will have exact quality criteria, exact questions that you need to ask yourself that you see here at the bottom left. Uh, if you say yes to all of these questions, you can answer yes to this question for this level one.
And for level two it's even more complicated. It'll say that is your build process automated. And level three is it type all reproducible, et cetera.
So level one is very simple. Uh, can you show the next page? And for answers, you also have multiple levels.
You can say yes, that's true for some applications, for half or for most application. And based on your answers, the Excel file or multiple tools available to the assessment, you'll see a score from zero to three, which is calculated pair business function, or for the whole of your organization that you can later demonstrate with nice charts and graphics. And yeah, as I mentioned, it's a community, it's a public, it's us behind it, it's me, it's Caroline, it's my other colleagues from the same team.
We are populating these, uh, guidelines. We are trying to write explanations, how to achieve the maturity. And you are all welcome to join this community too, to participate together with us.
Yeah, I just wanna say that the community I think is a very defining factor for Oasp Sam, because the thing about software development and security activities is that they are evolving all the time, you know, and it, in order to get involved with the group, then you can actually speak with people like riman who is overseeing application security for a group of 8,000 developers. You know, I'm happy to contribute what I know with regards to security metrics and my previous experience with bs, IM, um, so we really encourage folks to consider, become familiar with oasp. Sam, join us on one of these working group meetings.
Join us in the Slack channel, uh, and we really look forward to seeing you there. Uh, you can find Mann and I both on LinkedIn. Uh, so don't hesitate to send us a connection request.
You know, we'd love to learn more about what does DevOps look like in your environment, how are you thinking about software security, about maturity, about frameworks and so forth. Um, so hey, thank you so much for taking the time to spend with us today. We really appreciate it, and we hope to see you soon in an upcoming SAM meetup.
Thank you, Caroline. Thanks everybody for joining.