Security, Compliance & DevOps – Tim Johnson, CloudBees
How can security and compliance professionals better engage as part of a DevSecOps initiative? Tim Johnson, CloudBees Director of Product Marketing, discusses how organizations are challenged to meet security requirements and regulatory compliance at the accelerated pace software is created through DevOps. He outlines how to engage with the software and DevOps communities at DevOps World, September 27-29. (https://devopsworld.com
Transcript
This is Textron TV. Of the great pleasure of welcoming back. Tim Johnson Tim is with Cloud bees and compliance and security space and he and I always have great conversations good to have you back Tim and thanks Mitch and Anthony to be here.
So and it's always fun to talk about my favorite and everyone's favorite topic of security and compliance riveting. No, it actually is really there is really entertaining tell folks a little bit about what you do at clubbies. Yeah.
I'm a product marketing manager for our new compliance product called Cloud Beast compliance, and I've got a background and then with with Crosby's from about five years now and I also have a background previously in security for quite a few years. So this this brings it all home a lot of time and devops and a lot of time and security. So this is ties it all together here.
That is the Reese's Peanut Butter Cup. We're trying to figure out how to create right the security and software right in them. Yeah.
Well we're so we have coming up here devops World on the 27th through the 29th to September. So that's too far down the road. And you know, I think one of the conversations I'm doing a lot of talks and I know you are too about It doesn't just like assigning the people the the security work to the software developers or having the operations people do development or vice versa.
You know, we really have to rethink about this holistically and you've got some thoughts but one of the questions is why would and how would we get? Meaningful conversations to happen with compliance security people and what are we doing at devops world to make that happen and I'm sure there's a lot of great stuff happening and I'm going to get your perspective on it too. So you could start wherever you want, but I think that's where we want to go.
Okay. So so one of the things in the about regulated Industries, is there the people that are paying the compliance tax the most and and the compliance tax is a term we've coined and it's it's the the efforts and cost. To do zero value add work that you have to do.
And it's amazing the the amount of pain that we we encounter with people who are struggling with with trying to be secured security and compliant because it's how do you assess whether or not you're secure and compliant and then how do you attest with confidence that you are? And oh, yeah. Do you have the data at the back that up?
and you know the one of the surveys we we did last year where they How do you provide the data to the regulators and one was just raw data, and the other was power points, you know good grief. Not much has changed in a year ouch. I just hurts clearing that yeah, it does and and the some of the things that we've we've heard from from companies especially regulated Industries is just how difficult it is.
We've been doing devops for a long time. Why is this still a problem and and Are totally biased to you is that the concept of shift left of like you mentioned earlier if we just dump it all on the developers early on magically everything is going to stay secure and compliant and and the the problems we've seen with that is one you're dealing with static data. So you're only taking a snapshot of that point.
and that is is then dead and then somebody has to go find it. You know, if you're doing an audit if you need to to, you know, assert to regulatory agency something gotta go find that data and it's it's to the point where a bank we know has a hundred people devoted full-time on a 90-day rotating basis. Just doing Auto work.
Oh but hundred people. right another one of our customers is a a global manufacturer of technology and everybody knows who they are. They've devoted they've compliance for them because they they sell stuff.
So the gdpr global company. They take credit cards so they got to be PCI Compliant. They sell in the federal government.
So there's fedramp compliance that they have to prove. There's all these different alphabet soups of regulations that they have to comply to. And then you look at the list of tools that they have.
And it looks like one of those Market guides from the analysts where there's like 40 or 50 tools and and the planning and you know 150 in the testing and it's that's what they deal with. No, there's not even a consumer reports version that I think would solve the problems exactly only web complicated. There's exactly and so their way of solving the problem is to fund 30 developers and spend 10 million dollars over two and a half years to get something that doesn't work.
Um, you know, and and that's just you know, we see that consistently across the board. And and if you think back about what the whole point of devops is You know flow making things go faster making things go easier being able to make sure you're working on the right thing. and being able to improve on that we're not there yet.
In the security and compliance is that last is the next major point of friction that's getting in the way of really digital transformation. You know you started off. Let's get our CI going.
Let's to get our CD and our pipelines going getting into release orchestration. That's great getting into Progressive delivery and then The department of slow steps in and says no no. Or with my cell carrier.
Twice a year, they take their entire devops tools team offline to do audit work. You got a problem with your pipeline. Oh talk to me and wait until first that's expensive.
Wow. Yes. Yes.
So yeah. Those are the things. These are the issues that we're dealing with there.
We're seeing out the market with with security and compliance on that. yeah, it's interesting and one of the early things that you said that I really resonate with two that kind of set up that whole conversation is the mindset of point in time. Yes, because the whole idea if you're creating flow you're doing things faster, which are really doing is you're you're creating continuous change.
Yes, and so point in time doesn't matter. It doesn't matter if you were compliant three weeks ago. Okay, that's really nice and thank great report that we produce that said we're compliant and we did we need to but that's not where we are today, right?
Yeah anywhere from anywhere in our tool chain and our software stack, but the supply chain of third party sass service provider, you know, yada yada. That's all changing and we don't control that. So it's it's a solidly moving Target.
I think it's a you know, a sort of like the the Galaxy that's propelling itself right out, right? It's just moving fast and it's getting further and further away from you. Yeah, and and the, you know, you talked about one of the problems with the the static snapshots is things change as you mentioned.
So if you're using a model pipeline, yes, you use these immutable components you spun up this this container according to the regulations in your own standards and yada yada. as part of that process did anybody make any changes to that after because but I'm now of course now that you know, the the one of the things about Bad actors, you know, it's it's very easy to talk about Bad actors because there's a lot of them out there in the state actors and then just actors and everything else. But there's there's also the the Enemy Within both the intentional and the unintentional on that and we have an example with a customer.
We were we were working on getting the products running and great. It's all running now got all the communications and protocols and permissions all set up great. Let's come back tomorrow and start making it work come back.
Nothing worked. When six hours later, we found that overnight a sis admin with a console. Went in and changed some some configurations.
Mmm. Now they worked. Their changed longer they're ticketing system.
But yeah, you know about it. No, we're yeah exactly and how do you know about that? And and one of the other things we're one of the real bad stories were heard was a tester lied about the results.
For a global bank and application. That was an online it was there there one of their main customer. Facing applications.
And so that lying about that test result. Meant that their customer database was exposed to the internet fortunately, they didn't have a breach but eventually that was discovered that stuff happens. Right?
So so most of the way people are trying to do compliance now when the shift left is do that snapshot point in time and We're good to go from there. And so, you know part of the theme of devops world is, you know devops really imagine. We have to reimagine the whole shift left in the whole devsecops Concepts from point in time and static to oh and overwhelming.
There's no little sidebar the day prakash or cr-ciso. Started on his first day on the job as ciso at a major Bank. He had 633,000 critical security alerts he had to deal with.
That sounds like a really bad day at the office. Yeah. That's a really bad first day at the office.
And then he how do you prioritize it? How do you sort through that what's noise what you know how that goes? Exactly.
Right? So we have to we have to get away from that. Thinking and move into you.
This has to be holistic. You have to look at the whole thing and has to be continuous. That's what's devops.
It's supposed to be supposed to be continuous and you have to have contacts. Because okay, you're running sneak and something Cuban and this and that and all these other tests and they come back with these genome flashing red lights. What does it mean?
If you're in the development stage, is that really an issue. Is that really a bad issue? Okay, as if the testing is this something and so forth so that developer experience that load that you dumping on the developer you have to deal with that.
They have to filter through all that that noise and figure out what to work on. engineering managers they have to You know, they're paid for innovation. Hmm, right they want to think they are.
Anyway, they should be this keptic. I'm sorry. I'm just you know, yeah, that's that's life too.
So, you know, they want developers to be happy and we're actually seeing customers where they're developers are saying this is too hard. I'm out of here. I'm going someplace where he told.
Yes. Yeah. Technical dad the backlog.
Yeah. That's why I want to go to work. Yeah, and and so they they want to keep developers innovating they want to keep them happy and and focus so they have to make decisions that they can defend.
Yeah, you have to fix this now versus no you actually don't have to fix that at all. It's not really an issue based on the context of where that thing is. And then the, you know risk team risk management risk stewards.
They have to make decisions on Okay. This is a bad thing. This needs to be fixed now and then go would take the evidence to whoever the owner of that asset is.
And so this is why you have to fix that now and then they have to prove up to their management that they are improving the risk posture the organization and then the ciso. They're the ones that have to raise their hands and a test that yeah, we are. We're good to go and change from being the department of slow to the Department of go.
Hmm. I know because that's all that's all in there. on that so And then just you know, the shared services and devops teams.
One of our one of our customers said at our customer advisory boards, just we want to get the risk and the security and the compliance and the development people out of our office so we can focus on our job. Which okay, what they really mean is they want to become a strategic partner with these other organizations. So if they can do something that's going to material improve the developer experience through the tools that they're implementing they can create, you know evidence as a service.
So whoever wants to a CEO or a sea level can come in and immediately on demand. Do an assessment and attestation of their risk posture. You know that that lands back on the devops teams because they're the ones I got the tools to make it go.
Yeah, so that that's that's where people need to be thinking about. How do we get to that point I guess in this is your points said another way. There's got to be a better way.
Okay. Yes exactly beside you hanging out in my office or being you know it in years. Yeah.
And again, yeah, it's not working and and the number of companies that we've encountered where they are trying to develop this on their own is just just amazing because you know at the end of the day people companies really don't want to do that at a sea level. They need to fix the problem. But if you create this thing internally now, you've got technical debts who's going to support it.
Oh, you're gonna make it. How are you going to continually improve and does it work and worse in larger organizations? We've actually encountered where they were two different solutions for that from two different departments.
I'll bet yeah, and they have to now you get into competing who's really going to use who's do you trust and if you ask you this so so we're trying to create experiences all of us devops World being one and in Cloud bees being you know, the sponsors putting on which by the way is not just a cloud Visa event, right customer conference. This is a devops world. Well one of the biggest ones You know we've had for a long time it's great conference.
If you're we're trying to create experiences where we are talking about the things we need to be talking about right sharing things working on these kind of problems. So if you're a compliance person, you're a security person governance or somewhere in that kind of dimension of okay. I got to figure out how to the better way right?
Where do I go to find this? Well, let's go where the people who are working on this are what a great idea. Let's go to devops world if you if you easy for you to do because you talk with so many people so many customers in the industry.
What's a great way kind of mental mindset or approach? Go to devops world and have this conversation. Where do you look for it to happen?
What do you go to intend for? We really kind of people to seek out. What would advice would you have you?
Well, they I'm glad you ask that great question the the thing about devops world. and and the thing it ties into the dynamic all these companies we talked to that are trying to do it themselves is There if you're trying to do it yourself, you probably thinking in a vacuum. Like this is our unique problem.
Well, no. When you go to devops world you get you get to talk to people who solved. Or are in the process of solving the problem you're trying to solve.
and So getting back here, there's got to be a better way. There's a whole bunch of people that are working on a better way and no your situation isn't unique. You might have unique little bits here and there but if you step back and look at what are you trying to accomplish you're trying to deliver better software faster and get an Roi on the digital transformation promise, right?
Everybody. That's what everybody's trying to do. and why users use an old phrase why reinvent the wheel go talk to other people that are really smart people that are there that are working on things.
They may have a solution. That is absolutely perfect for you. You might there might be an open source thing that you didn't know about.
That's that'll drop right in you may find a commercial product that that acts, you know walks right in with what you want to do and you get to talk to other people and share War Stories and oh, yeah, I did this and what do you do and so forth everybody brings something to the table? It's not just going take Because there would be people that want to talk to you about your experiences and what you did. I think it's really good point.
I'm gonna badly butcher it but you know the Einstein quote about the the thinking that created the problem is not the thinking that will get you out of the problem. Right something to that effect. You can't solve it yourself you can't affect because it isn't just with an effect you either and you also don't know it, you know what the other people in that software chain and the architecture and the platform engineering and the devops team and the automation all of that are part of the solution and you're not going to solve it without bringing it together getting it together at least getting us perspectives and talking with people about how they think they can be part of helping finding a better way, right?
And that's the great thing I think about Our kinds of conferences about devops world. It isn't just go listen to a bunch of speakers. It isn't just go to the vendor booths.
And those are all things there. Those are all great things there. It's the hallway track right?
It's yeah, that's the track that really wears sort of the magic plus happens. The magic happened in those other areas and now the magic plus happens there and that's where Tim and I bump into each other you say, you know, I had just really amazing conversation with this bank yet Etc and all sitting we're on to okay. There's an idea there.
Yeah, right something I can take back, right? Yeah. So one of the questions that there may be people who are a little reticence about Trying to kick off a conversation with a complete stranger at the lunch table or whatever, but it it's there's some some good opening lines.
It's okay. So what problems are you trying to solve in your job? Mm-hmm or another one is so what have you seen that was really interesting or caught your eye or gave you an aha moments or something like that and you know, you'll be off.
rather than you know what you do, that's So what are you trying to solve? Here's some thing that I'm trying to solve if you've done anything like that or exactly. So new invariably even just asking like so what do you do that'll lead to okay.
Here's what it is. I'm working on and yeah, we're or the thing you can do and I love what you're saying. Now you can do is you know, here's a problem.
I'm thinking about is anybody thinking about this too or have any ideas suggestions and just kind of put it out there. I bet you you're not the only one gonna be thinking. Oh, yeah, maybe you're thinking about it differently or not, but that's a great starter too of You know don't know what all you do, but here's a starting place.
What do you think and they'll jump in right? Yeah, whatever perspective they're bringing. Yeah, and that's a good thing and you know, there's there's that, you know several years of Kent up.
Interpersonal social deficit. Yeah, be careful what you ask for. Yeah, actually get out and talk to people and and you know, the the people's horizontal and vertical aspect ratios are actually going to be different than what you expect from two years on zoom.
And yeah. com. That's where you can sign up and register.
It's in Orlando 27th through the 29th. Hopefully hopefully we'll see a good mix of some security compliance regulatory folks there. I look for it.
I look forward to seeing you there and me too. And and we'll have we have a number of sessions that are being presented by. Company people from companies from heavily regulated industry.
So there's there'll be a lot of content for folks not just product b****** not just now they're not product Bishops this thing there too. But yeah and one things I would suggest to folks to unite United knowing each other for a while. Now Tim Tim is a great wealth of information and whether you're thinking about Cloud bees as a product now, we're in the future or maybe not yet Etc.
I would encourage folks to reach out to you just have those conversations because like I said you talk to so many folks, you know, giving out a way of how people can get a hold of you. Um, well I'll be there on the I'll be on the main stage on the keynote for the first day. So I'm kind of then kind of easy to see there and I'll be on the the crowdy's booth for most of the rest of the time.
I've got a session on on the compliance tax. So all these fine come look me up. If you can't find me come to the Crowley's booth and ask, you know, they'll chase me down.
Perfect. Yeah. Sounds like you you should be pretty easy to find so yeah.
Well Tim, thank you. Have great talking with you Tim Johnson from cloudbees and fat. I think I always enjoying this conversation.
I was getting up front about oh compliance security. It is a really fascinating conversation. It is in a tough promise all so yeah, absolutely.
And so thanks for having me you bet. Good luck at the show. All right.
Thanks.