DevSecOps: The Train Has Left the Station | DevOps Connect: DevSecOps 2023
Trustworthy software is now a must. Customers want to rave about your software, but how can they if you’re not dedicated to security from the very start? This talk will give you tips and tricks for catching up and bringing your software program to the next level. Join us and learn more about why DevOps is now DevSecOps.
Transcript
All right, well welcome to the DevSecOps Days. If you are just joining us, if you're, you've been here for a while, uh, hope you had some good coffee and, uh, the train's left the station. That's what you need to know.
We gotta start there, right? DevSecOps has been around for over 10 years. Uh, I remember because I was one of those people who want, you know what, we need to figure out what to call this thing.
0. 0. And so DevSecOps and yeah, I know I made a whole bunch of people upset and DevOps and SEC dev op, and I'm sure everybody's got some something and there's plenty of, uh, drunk, uh, games that we had looking at different, uh, things like Barb and all kinds of fun stuff.
So, uh, getting us started, I have been in this industry for far too long. I'm what you call a dinosaur, uh, for those who are veterans, uh, I welcome you to Dinosaur Hood at some point. Uh, I've been in the industry for over 30 years.
I have two little girls and they like to do all sorts of things. I, I spend time with ballet and oh, actually I just got soccer recently. So there is hope.
And uh, you'll also find that I like to kickbox. I have been working on DevSecOps for quite some time. I have, uh, started a new venture.
I work at Ions as a faculty member. I'm on, it's 5 0 5. If you don't know what that is, you actually need to go and listen to it.
It's on uh, Spotify. Lots of fun. And I've been working on Hacker Girl for quite some time and you'll start to see that I'll have more time over the next few months to do a lot more there as well.
So I'm gonna, I'm gonna start with three things and we're gonna end with three things. That's my promise to you today. Now I'm gonna help you to pave the way for the next 10 years.
We've been doing this for 10 years, so we might as well talk about the next 10 years. All right, so the next 10 years, what are we trying to do? Are we working on security?
Who in here is a security practitioner? And that's a great question for rsa, who's a software engineer. All right, I love it.
We got some software engineers who's a ciso. Come on, you're in there somewhere. I know a co a couple, couple of CISOs.
What about everything else would you sell? Say your something else. Sure.
All right, there we go. So we've got a little bit of knowledge about what's in the community here. Um, hopefully I brought the right deck.
Sometimes that that changes over time. Uh, you know, my belief is that we're not here to talk about security. We're not here to talk about development.
We're not here to talk about ops. We're here to talk about software trust. Do you trust the software on your machines right now?
Have we done a good job over the last 10 years getting there? Do you have understanding of what's gonna get broken into on your laptop? What about all of the places you put your data?
Wouldn't you really like it if we focused on those three things for the next 10 years? Accessibility. What if people actually knew what you were talking about?
What if they had some understanding? What about transparency? I know anybody who's listened to it's 5 0 5 knows that I'm all about radical transparency and so is cisa and that's gonna bleed through eventually to everything that we do.
And thankfully because it's about darn time. And what about increasing accountability? Who here would love for everybody who works on software to be fully accountable for what they produce?
Raise your hands because I know every single one of you would like people to be accountable for what they produce. So how are we gonna get there? Well, I remember where it all started.
We had this rabbit and the hair conversation, I remember where I was, it was at is SSA and I started talking about DevSecOps and they couldn't shut me up. And I had this really cute PowerPoint by the way, my PowerPoint skills have gotten better over time, but not too good. So I'm still working on that.
Um, and speed the rabbit represents developers and at that time also DevOps. So we might wanna get them a t-shirt cuz they're basically running through life and furiously and security at the time, more like the tortoise. We know how that whole story works out.
You know, the tortoise eventually wins cuz you know, the hair got caught up in a whole bunch of things. It's actually a, a cool anecdote because it's kind of been true. I mean, you know, there's all these things that companies do and software developers do and while they still are kind of not working and there's all sorts of, uh, stuff I've talked about, like adversaries who hears a software developer who talks about adversaries in the very start of every project that they actually do.
Any hands come on. There's probably one or two. Oh, none in the audience yet.
Okay, you should, did you know that an adversary is just a customer you don't want? And if you're not talking about them early on in your software project, then they're gonna actually use your software because you're actually building as if they're actually part of that process. So then the other thing we did 2014, this was really cool, we set up a manifesto.
Cause everything you're gonna do in life starts with a manifesto, right? Right. Well you know, honestly we've done some good stuff here.
Like if I had to put a lot of check marks behind some of these things over the last 10 years as an industry in the security industry, in the development industry, if you start to look at what software is doing, we've made some cool strides. There's lots of vendors out there that actually do DevSecOps and they've fulfilled on many of these promises. Like, oh hey, compliance operations, how many companies are out there where you can actually now link up your software pipeline, get your compliance sorted out, get your certification at the end.
And there it is. There's a lot of those, right? We've, we've made some good strides.
Shared threat intelligence, uh, we've made, okay strides. I'd say that's an area of the industry I'd really like to inspire that if you actually had some threat intelligence and you could make it developer friendly, they would like to have it. Red team blue team, we know all that.
That's been going on for a while and we've had a lot more red teaming and a lot of bug bounties and things like that. So this is happening. We're also seeing an incredible amount of security services become APIs.
How many here deal with their security services as APIs? Most, some little bit. All right, we got a few.
Uh, and that's really good because APIs is our future. If you wanna use ai, you're gonna probably be stuck with an api. If you wanna do things that are gonna be progressive, this is where we're gonna end up working.
So the beginning, anybody know what a wardley map is? I like Wardley. Simon Wardley pretty amazing.
Likes to help you figure out what the future's gonna hold. Uh, and incredibly, this was done in 2016, it's seven years later. So you're starting to see a little bit of like things that I've been forecasting.
I tend to talk a lot about a different way of talking about the same things because my belief is that eventually the world will listen. Uh, and we'll do great things together. So interestingly enough, DevOps was born without security.
Security actually became a thing as I was growing up. I remember that software, they, they had this thing called the firewall. There wasn't a firewall when I actually started doing programming.
I know that's where I told you I was a dinosaur. Yeah, kind of fun, right? And the firewall got born and then there was IDs and then there was ips and then there was hips.
And well I could give you a lot of acronyms and then, you know, ultimately we probably wouldn't get to the end of my talk. But in reality what was very cool about all of this is that we started to see that DevSecOps was needed and it was gonna be a journey. And we weren't even talking about it yet, but the DevOps movement had been going on for quite some time when we started talking about this.
com was bought in 2005 and this was 2016 when we did this. So 11 years later we were still talking about how we were gonna move from the genesis to actually doing some of this. Why is that important?
Well if we want security to be built in and we want software to be safer sooner, well that means we actually have to get into the conversation with the people who press all the buttons. And today we've made some movement, I'm gonna go back again so you can see it. Here's how much movement we've made.
Can you see that? It's kind of fun, right? We went from here to here, we've moved 10 years, you know, we could move a lot faster though.
And then we actually need all your help. And the more you help and the more you lean in, the more this journey's gonna take off and move a lot faster. So what's interesting is there's been a whole lot of of other things that got born again, I'm gonna go back and then I'm gonna go forward.
Look at all that new stuff. We learned a bunch, right? We didn't even have those things.
We were kind of talking about sbam that was in its infancy, but like no one was really paying attention. Canary, anybody know what a canary is? Well if you've done development, you know what a canary is?
Uh oh. Kind of cool. We actually know that secure ability got added cuz I didn't know that you actually needed metrics back then.
Sorry, it was kind of like a foresight thing. Uh, and transparent security was there and well rugged software was there. So it was a belief that when we think about all of this, that the customer actually wants rugged software.
What? This is outrageous. Outrageous.
I wanna put something on my machine that's gonna actually last and be durable. Oh wait, maybe I don't even wanna put it on my machine. Maybe it could be web enabled.
And then this cloud thing came and I've got a whole bunch of other slides in the, in the deck somewhere where if you wanted to understand the origination of all this stuff, I did a whole bunch of mapping and research to help you understand that we're on this like faster and faster and faster loop and still we're kind of sitting back waiting and thinking it's gonna somehow kind of magically scoop us all up, right? Anybody think security's getting easier, more complicated, right? More acronyms.
Anybody we've had more added in the last 10 years. I can certainly tell you that. And what's interesting is the current landscape.
So I do a lot of research, I like to run a lot of surveys. I like to spend time with people who talk about things like metrics. You know what a, a maturity model is?
I, I suspect most do. Um, that number four there is metrics. So it's like most of the time that's where you spend your time talking about measuring if you really wanna do great things.
I don't know why that one is actually level four because actually it should be number one, you should start with measurement and outcomes in mind. And what's reality is we wait until the very last minute to talk about how we're gonna measure it and make sense of it. Because math is hard because adding and subtracting and multiplying, and by the way we have this really cool risk calculation.
We impact times likelihood. Is that the one that we all like? Do you know when you multiply impact times likelihood, you actually dampen the fact that you understand and can do anything about what's coming?
That your risk is actually more a, a chance of likelihood than it is of impact. And yet we talk to software developers about impact times likelihood. And guess what?
They really just need to know about likelihood because as security practitioners, that's what our job is. Our job is to forecast when somebody's gonna break in. Anybody here know when somebody's gonna break in?
No. Oh, come on guys. It's actually interesting because if you go back to that thing I said earlier, personas and categories, it's pretty easy.
Uh, anybody put content into their platform or allow a customer to put in URLs? Yeah, I know a whole bunch of platforms that allow for a customer to put in a URL and then you go to URL scan and you actually find those same URLs being used by adversaries. But no one talks about the fact that they're gonna add URLs into a platform at the very start and that adversaries could show up.
Interestingly, it's not that hard to figure that one out, that if you allow it and you don't check these URLs that something bad's gonna happen and ultimately it does. So one other cool thing is if you notice there that level three we have elite performers, they're writing it down, they're submitting it to auditors, they actually know what they're gonna do. They've got their operational definition.
If you don't know what an operational definition is, you should listen to John Willis next. He's incredible about helping you to understand how to get to the point where you could measure something. And uh, his research is something that I follow quite a bit.
Majority, majority are still sitting in level one and two. Are you doing DevSecOps as security? You might be doing it ad hoc.
You're not sure how to talk to auditors about it. They haven't quite caught up yet. Anybody know an auditor who's caught up with DevSecOps?
Gonna any hands? No. All right.
Sorry. Uh, we probably should work on that too. Anybody wanna work on DevSecOps?
Audit audit standards? Like that could be a thing and probably should be a thing if we really wanna do it. Well there's lots of opportunities when we talk about the future.
So that's 2023. So I'm gonna come back down to reality and focus again on three things. We're gonna focus on accessibility, transparency, and accountability for the next 10 years.
If we did nothing else and we just focused on those three, do you think that we would get better safer software sooner? We would. And the reason why is because we'll be having the right conversations.
So let's get started. Let's talk about accessibility. How many people have to study security every day to be good at it?
Most If you're a security practitioner daily, right? Right. I see you over there.
Um, I read lots of articles. I'm sure you all have some sort of like RSS reader. You're constantly having to like talk about something in the news.
You know what's interesting about the news? They talk about things that happened past tense and we're all listening to stuff that happened, but we're not really thinking about how we talk about it. So it's going to happen.
Uh, you know, they have this thing called customer driven innovation. What's really interesting about customer driven innovation is you go talk to customers and you go talk to them about what you need to do and why you need to do it. And fascinating.
They actually help you to figure out what the future is. What's also in there is language we should actually be talking about what language we use. Do you know that if you're having a conversation with somebody who has a language that's outdated, that in particular they're gonna be talking about things that happened and cultural problems and most of the friction of dev second ops comes from language problems, ever sat and talked to a developer and they don't have the same security language ever be a developer listening to a security person and not sure what they're talking about.
And when they stumble over 35 acronyms within one minute and didn't take a breath, that how about structure unbounded endless possibilities for adversaries. Kind of not true adversaries. If you do a Pareto analysis, if you look at the last 10 years, if you start to really figure these things out, they actually all line up against a structure.
And if we spent our time with that narrative, we'd actually do pretty good if we were trying to instruct somebody. So my belief is that empathy starts with understanding and it passes through awareness. Do we know who's aware of needing to do these things?
Well, so did you know that there's like a 20% churn within most companies that happens for developers and that not every company yet is doing DevSecOps And that means that culture is actually the first limited to great software. Did you know that the learning, uh, cycle that is actually depicted here is something that everybody goes through when they're joining a new company, when they're learning something new, they actually have to have awareness first, then understanding, then they commit. They're like, all right, now I know what I gotta do.
And they commit. They like swoop into action but they're kind of that wobbly toddler. Like, I don't really, I I'm trying it out and then all of a sudden they get great action, right?
How many folks think that action is happening right now in the security industry when it comes to software? No hands. All right, I kind of agree.
So why can't we get to understanding? Well anybody want a developer to spend half of their time learning the language of security? You got a whole bunch of stuff and I like was gonna run off the page and actually when I started counting, I actually thought I would put on all the little icons and then I filled up the slide and said, you know what?
That just doesn't look good. So I'm just gonna like shortcut and actually put down this is what it feels like to a developer. You just talked to me about NIST and you talked to me about ISO and then you talk to me about SOC two and then you talk to me about this and the next thing and the next thing and guess what?
I'm burnt out. I wanna go develop software cuz that's what I do. That's actually my job is to go figure out what customers want.
And when you figure out what you would like me to do, come back and talk to me. But like in my language, did you know you can probably put most security things into about eight or nine categories for a developer. Eight or nine.
Uh, started to do that last company company before that open test plans. Did you know if you tell a developer what you're gonna test them on before you test them on it, they actually get better at it. What open book tests or a thing ever send a kid to school and you tell them they're gonna have an open book test, they open the book and they still fail because it's not necessarily accessible.
They don't know how to read the book. They, if they still have to study, but at least they have some place to start, right? And ultimately if we wanna get better, we need to lean into things like the software engineering institute, why security language needs to get translated to developer.
Like we legitimately need to get to the point where we actually take all of the stuff we need to know. Cuz by the way, I don't want to change the security industry. I'm not trying to change all of us.
I just want us to actually par it down so that we have a fighting chance with adversaries and turn it into something that become operational for a developer. Smaller, much more concrete, easier to guide. All right?
And to me, structure, it's not unbounded. People, adversaries are over here and over there and actually they kind of all, most of it falls into these five things. And I know I've had a lot of people debate with me about access management versus authentication and we've had that go around and all that I'll tell you is authorization's just another type of zoning and containment.
So feel free to argue with me. We'll go around the merry-go-round a few times and I'll still hold to my belief that bad code is a firewalling problem. Bad code and authorization problems are your zoning and containment issue when it comes to translating it for developer.
Hey, by the way, when you code poorly, you're actually just opening the door on your firewall to somebody you don't intend. Again, going back to if you talk about adversaries at the very beginning, you're gonna probably practice well against the ones you don't want. So let's break over to number two, increase transparency, easy, integrated and productive.
Really transparency. So who all has returned to office? So I can press that button.
All right. And, and so you're excited about being in the office. It's a good thing.
I agree. All right. Some people don't like to go back to the office and the reason why is because they feel like they actually can be productive from anywhere.
And in some cases I've seen return to office be used as a method for determining why things aren't happening and why something isn't productive. And what's interesting about transparency, if you go look at all the narrative about DevOps and observability and a whole bunch of this stuff, the more transparency we create, actually people start to say it could become counterproductive. It could become less integrated.
Oh, it's not necessarily easy. So our job is to go from rocks and chisels. How many people actually feel like they hear from their developer teams and they're telling you how hard something is and why can't it be easier and can you just make it better?
Well they're kind of giving you that rock and chisel analogy. You're bringing me tools, you're bringing me stuff, but it's really just toil. And if you work for a software manufacturer, what you find out is actually that's what makes money software and it's for these people called users and well really most people want it easy.
So what's the job of security practitioners? Job of security practitioners is to make security easy for software. Pretty simple, right?
Anybody here feeling a little queasy that could not go well? Like gonna translate all this stuff? Yeah, that, that's been like the last 10 years for me is I got asked all these questions and like I was that person in the jungle with the machete going, I'll just take out all the questions, let's go.
Uh, and the easy button actually, it can be easier with, in some cases some companies have somewhere between 25 and 30 different adversary categories. And if you start with an adversary category, you can find out that you don't have to focus on everything, you have to focus on some things. Uh, I've mapped some of the companies to 35 adversary categories and when you use them, again, you can measure your way out.
And that's been quite interesting. Integrated. Are you integrated in your pipeline?
And if you don't know what this is, this is the actual software development pipeline. Um, the software development pipeline is something that every single group out there needs to figure out. And if you don't know what it is, you've got to actually start to understand that developers talk in this language at the very top.
That's what they talk about. They talk about developing software, they talk about their GitHub repository, they talk about GitLab, they talk about continuous integration. You can name off a bunch of products, but you know what, they don't really talk about security products.
I, I'm yet to see a lot of developers talk about specific security products unless it makes the security people go away, right? It's like a conversation starter. Hey, so what security tools are you using?
The ones that make you go away? Oh, okay, well that's fascinating. Uh, let's talk about which ones those are.
I bet you're missing a few. So we should work on those areas because uh, you still have things we should do together. And then what I find out is usually when I work with folks on the bottom layer, um, because there are gaps, there's actually still gaps in the ones that they think are covered.
Because ultimately you go back to that uh, impact versus likelihood and find out that the algorithms a little bit wrong. They want it to be productive. You've probably seen this diagram from me if you've watched me before, my belief is productive follows this pattern of software comes out the door.
There's a bunch of feedback loops that actually happen and there's ultimately a feedback loop that happens with adversaries and that data comes back in. Everybody look at logs. Anybody know what an IP is?
An IP address? Yeah, we all know what an IP address is, let's be honest. And what's really interesting is if you're a software developer and you're looking at your logs and you have a security person explaining to you what your logs are saying to you, they mismatch like, Hey, I actually know what's happening in my application, but you're telling me something totally foreign and different.
And we haven't really fused that language of understanding what logs mean. So third thing here is accountability needs to be measurable, action oriented and safe. You've heard these things, you know they're out there, right?
So measurable, I've spent a lot of time on that metric. It's a kpi. It's got companion metrics.
They're kind of cool. Actually, did you know that you don't need to worry about all your assets. I'm gonna start making everybody unhappy.
Those asset management folks that talk about attack surface. Yeah, attack surface management is great, but there's only a percentage of the attack surface that anybody needs to really care about. And it's the denominator of all the places that adversaries will actually go to and do something nasty.
And then they have these things called exploited targets. And what would really be awesome is if those exploited targets or exploited opportunities that are happening ended up in CBE or they got posted or people actually started to share them. And the reason why is because if they actually shared them, we'd all be able to actually respond to how software should be protected in our environments.
We'd be able to make better decisions. And you know when a KPI drops for a developer, like availability drops, they react. It's kind of cool.
It drives action. So how do you put something like this together? Here you go.
This is a gift. I've been talking about this for 10 years. I've enacted this now three times.
If you bring in all this security data, you do something with it, you correlate that data, right? And you use those adversary categories and you figure out how to talk about secure ability and you do your case management well and you put only the most important things in front of a developer when they fail and you do your root cause, you'll drive the most action you'll ever have had. You'll reduce the overall possibility of breaches.
You'll get to the point where it's actually a much happier environment and there's not a lot less security work to do. In fact, you're all gonna be super busy. You're gonna love working with ai.
Oh, I'm a data nerd, right? You're gonna all be data nerds too and you're gonna want this T-shirt. I know the guy who has it.
If you want one. Um, pretty spectacular existence. And the last thing here is safety.
If you wanna build trusted software, we actually have to operate like we're going to trust each other and it's a safe conversation. Kudos to all those companies that have lately had breaches and actually talked about them in a very transparent and open way. And if you think about it, that's been a big change.
We shouldn't be hiding behind mystery and secrecy. So I'm gonna wrap up with, this is the next 10 years, believe me or not, debate with me or not. You're going to see that diagram actually morph.
We're gonna have one software development pipeline and all of those tools that are kind of like on the fringe, they're gonna integrate. We're gonna see convergence over this next 10 years. And this is the beginning of ai.
You're gonna start to see that security is actually gonna become its own thing. We've seen some of those publications this week and we're gonna see this happen by 2033 because you're all gonna care that much and we're gonna get there together. So we can do this.
community, take my survey, give me some data, help me give you back that data, and let's figure out those metrics that are crucial and the pillars that we care about for trust. And that is rave. So if you wanna learn about it, come talk to us.
Brave. Thank you. Stay up there Shannon, please.
Thank you. Great. Thank you Shannon.
Yep.





