DevOps World London – Security, Compliance and SDLC – Manuel Schuller, Wipro
Manuel Schuller, Wipro DevOps specialist, shares insights into his upcoming DevOps World London panel, “Compliance, security, and risk management in the SDLC.” The panel will explore why “shift security everywhere” better fits DevOps philosophies, how to move from checklists to risk-based decisions, how to effect change that connects security, risk, and operations to value, and more. Register for DevOps World London at https://devopsworld.com.
Transcript
This is Textron tv. We have the pleasure of being joined by Manuel Schuler, who is a DevOps specialist. He works at Repro, but we're talking about DevOps world, London.
That's happening on December 5th. And, uh, Manuel's gonna be leading a panel. So welcome, Manuel.
Good to be chatting with you today. Thank you, Mitch. Very nice to, uh, attend.
Very not to be here. Yes, VIR virtually, right? We're talking across the world.
Yes, of course. Um, so the, my understanding is the panels about somebody, about compliance, security, and risk management, which I imagine you have a lot of experience in your background. Maybe say a little bit about, you know, that panel topic and you share with us a little bit about what you think you'll discuss on the panel.
Yeah, absolutely. Uh, this is a, a, a panel that, uh, that is very oriented on what's happening right now in a lot of companies. Uh, we, we are talking, so I make always make a difference between the trends, uh, that we are talking about.
Uh, the last trend is obviously, uh, generative ai, uh, on what, what it can bring to, uh, to all the things, the nice things that we're doing, uh, especially in DevSecOps. Uh, but there is always a, a, a little shift between the trends and what's happening right now. So what the companies, what the big corporations are implementing.
And currently what is very important is what we will discuss on the panel. Uh, how is security, uh, implemented in the, uh, SDLC? How do we manage the risk?
And what about the compliance, uh, when it comes to make sure that when we get something in production, okay, an application, whatever the production means, okay? We are not talking about technologies. It can be, and it should be independent of the technology.
Something running in production can be running on the mainframe. It can be running, uh, on, on a traditional system. It can be running in the cloud.
Uh, but what I really want, uh, to focus on that panel, what we really want to focus on is how do we make sure that everything running in, uh, in production has that compliance bit, uh, that has been verified and that we can prove, okay? So, notion of audit also, uh, that we will, uh, with no doubt discuss, uh, that we'll come into the discussion. So, uh, we, we expect, and by the way, uh, as you know, DevOps world is a tour, uh, this year.
So, uh, it's gone through, uh, three different locations in the, uh, in the US and one in Singapore. Uh, if I don't mistake. And, uh, we had the same, I was at the same, uh, panel in the DevOps world in New York, and we had very interesting discussions, uh, sometimes too short because we have to remain in the, uh, uh, in the time.
Uh, but we have very interesting discussions. Uh, let me mention just one on shifting left. Okay?
Okay, great. What, what does it mean shift left? We had, uh, passionate discussions, uh, because until, um, some time ago, uh, shift left was, okay, we'll bring everything left into the development.
So developers will do everything. They will be, uh, developers, but there will also be, uh, security specialists. There will be, uh, compliance specialists.
They will, uh, uh, look very far into, uh, ops automation. Uh, so everything will be done will be thought about over there. But the developers, uh, don't want to be security specialists.
They are developing Mm-Hmm. They're creating, uh, wonderful things, but they, they don't want to become security specialists. They just want to apply some security policies.
So the, the name first policies, compliance to policies. So we, we are in the same, in the same loop. Um, so they just want to apply policies.
They are very keen to apply these policies, but they don't want to be responsible of the definition of these policies. Mm-Hmm. So we had lot of discussions around that, uh, that topic.
So what does shift left really means? Shift security left or shift security, uh, everywhere. Uh, we should be able to, uh, have security checks anywhere in the, in the process that leads to, um, so I'm, I'm repeating that a lot, but that leads to the production.
Okay. I am, uh, in, in Wipro, we are doing a lot of implementation projects. And at the end of the day, what is important for most of our customers is how do we bring something with a decent level of quality with, uh, uh, compliance that we can prove?
How do we bring that into production? And how do we operate, uh, applications into production? So it'll be, uh, about all, all these, uh, all these things All in a, probably a short half an hour or so.
You know, I really like your, um, your security everywhere. 'cause if you think about more holistic, you can think about it as software, supply chain security. You can think about, you know, software security.
It, it's, it's throughout the SDL SDLC process, because even we can be applying the best policies of what the developer does and creating software, but we could, in the build process, introduce, you know, an insecure or, or a compromised image of something, right? So it can happen anywhere, or it may happen even in the test environment or early in the development. So you have to think about the entire process and how security is both built in and then maintained and protected as you're moving, moving workflow through, through the process.
And adding to what you were saying, we may, uh, introduce, uh, some security breaches without knowing them. Mm-Hmm. Absolutely.
Because they will be discovered tomorrow. Mm-Hmm. So how do we address that?
Uh, quite, um, complex problem of, uh, ensuring security while we are developing, uh, this is more or less what, what I was talking about, but also maintaining security and compliance while we are operating the software. The, so once the software is, uh, sent, thrown to production, uh, it's not finished at all. Okay?
Mm-Hmm. And this is the reason why. One, one of the reasons why, uh, DevOps is called DevOps Mm-Hmm.
Because the operation, uh, is a very important aspect of the, the software delivery, uh, supply chain software development, uh, is not, um, a, a complete, um, you, you, you do not address completely the problems during the development and delivery phase. Mm-Hmm. Okay.
This is also something that comes into the operation, and you have to maintain that compliance. Um, we, we also, uh, we will definitely talk, because it'll come, I know it'll come in the discussion about software bill of material. Mm-Hmm mm-Hmm.
Because one of the, uh, the way we can address, uh, what we were talking about is to have, and to maintain, to build and maintain a software bill of material. Because you can use it for, uh, proving everything that you have in your, in your applications, but you can also use it for impact analysis, know your software. Okay.
So it'll definitely, because it came at the, at the panel in New York, I believe it came also in the same panel. I was not there. But in the, uh, in the Silicon Valley, um, I did not have the, uh, the opportunity to look at the one that was, uh, run in Singapore.
But I have no doubt that it, it came in the discussion because today, uh, with the, um, I mean two years more than, uh, more than two years ago, two and a half years ago now, we had that executive order from, uh, president Biden on software bill of material. It had, it's been translated in the, uh, resilience Act, cyber Resilience Act in Europe, uh, that is to be applied, uh, right now. So we are in the moment where we have to insert the building, the bill of material and using the bill of material in our As DLC.
So it'll come into the picture. Definitely. Talk A little bit about, um, compliance.
It's not necessarily a developer's favorite word. 'cause it, it, it brings back thoughts of the days of filling out forms and spreadsheets, and did you do this? Yes.
Did you do that? No. Do you have a, a log of this?
Yes. Okay. Attach that file.
You know, that we've all been through that, and I think most of us probably prefer not to have to do that, but we know it's a, a necessary part of demonstrating, of having the attestation that we've, we've have complied with policies. How do you think about that in this sort of security everywhere world of DevOps too, where we have a lot of automation, a lot of data to back up what things were done and maybe what things weren't. We, we should be able, I mean, to, uh, to answer directly to the first part of your question, we should be able to remove all these, uh, forms and, uh, um, documents to fill.
And, uh, we, we should be able to remove that. And let me take a very simple example, uh, because we've, we've done it, okay. We've done it quite recently, uh, in a big bank, uh, with Wipro, where, uh, one of the challenges was to, uh, propose that automated compliance during the, uh, the SDLC, but to propose it as a service because, uh, in a big company, in a big corporation, uh, you have a lot of different processes just because it's history, okay?
Companies are, are acquiring each other. When you acquire a new company, you acquire also some working applications. And these applications have been developed with current processes that, that work.
So before, um, changing these processes, most of the, uh, uh, in most of the acquisitions, uh, current processes are still applied in, uh, acquired companies. And they were, they, they may be applied for a while. Um, so, uh, some of the compliance bits were, uh, already existing in some of the processes.
Not every, not every process, but some of the processes. And the purpose was to say, uh, I proposed compliance as a service, okay, compliance to the security, compliance to the needs of documentation, compliance of, uh, data management. Uh, we had a lot of chapters for the compliance, the main one being security, of course, but not only.
And, um, according to these chapters of security, some of them were, uh, already managed by the processes, some of them not. So we were, we would propose these, um, compliance, uh, bits as a service without, uh, involving I would say developers, developer's time without, uh, overcharging the developer activity. Mm-Hmm.
So it, it's really something that, uh, and so it's not directly about DevOps world that time, but I'm doing other presentations in other events about that, uh, that topic. So for those of you who are curious, you can, uh, type manual sch, uh, DevOps, um, presentations, um, to see how we achieve that. And it's, um, exactly in that, uh, that topic of, uh, proposing the compliance as a service.
Compliance should not be something that overcharge, uh, with forms, with, uh, things to fill, um, the, the, the teams. It should really be, I want to use the, uh, the, uh, the services of compliance knowing that at the end of my process before obtaining the, the, that kind of stamp, okay. Mm-Hmm.
That allows the, um, uh, the application to go to production. Uh, I will verify that I am compliance. So my compliance engine will verify everything.
Excellent. Well, between security everywhere kind addressing the shift left and how do you really, how, how do you really effectively do that? And, and we talked a little bit about compliance and compliance as a service.
We didn't even get to risk management. I know that's part of your panel too. We don't have time to delve into that.
So guess what? We'll have to come to get all of that and more. Yeah.
That's the only Solution you have to come. There you go, Lee. You gotta leave, leave everybody wanting a little bit more, right?
So, well, well, hopefully, uh, folks can, can attend. We'd love to have you at DevOps World London. It's on December 5th.
com and register There has all the details and location and the full agenda, including Manuel's, uh, panel conversation on compliance, security, and risk management. Well, we appreciate you sharing a little bit with us, giving us a preview and a little insight into both what you're talking about and kinda why, why these are important topics. And I'm sure it will resonate with a lot of people.
So wish you the best with the panel and have a great time. Thank you with them as well as everyone else attending. Thanks for, for sharing this with us, Manuel.
Thank you, Mitch. You bet. Have Good one.
Cheers.