80
How Rugged Cultures Drive Biz & AppSec Value

How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

How Rugged Cultures Drive Biz & AppSec Value

Page 2: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Director of Security Intelligence for Akamai Technologies Former Research Director, Enterprise Security [The 451 Group] Former Principal Security Strategist [IBM ISS]

Industry: Co-Founder of “Rugged Software” www.ruggedsoftware.org Faculty: The Institute for Applied Network Security (IANS) 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: www.cognitivedissidents.com

Things I’ve been researching: DevOps Security Intelligence Chaotic Actors Espionage Security Metrics

Page 3: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 4: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

PassionatePurposefulPrincipledProtectorProvider

Page 5: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

HonestCourageous

Consequential

Page 6: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

UnreasonableA Fool

Page 7: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 8: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

No

Page 9: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Is it getting better?

Or do you feel the same?

Page 10: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Will it make it easier on you now?

You got someone to blame…

Page 11: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

How would you know?

By which criteria?

Page 12: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

EvolvingThreat

EvolvingCompliance

EvolvingTechnology

EvolvingEconomics

EvolvingBusiness

CostComplexity

Risk

12

Page 13: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 14: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 15: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

WHAT

WHY

http://www.ted.com/talks/simon_sinek_how_great_leaders_inspire_action.html

HOW

WHAT

Page 17: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Performance

Fungible Assets

IntellectualProperty & TradeSecrets

Rights & Civility

Safety & Human Life

Page 18: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Dependence

Page 19: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 20: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 21: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 22: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

s/Software/Vulnerability/

Page 23: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

s/Connected/Exposed/

Page 24: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Our challenges are not technical…but cultural

Page 25: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

OWASP Top 10

“We can eliminate SQLi in our lifetime”

Page 26: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

ActivityEffect

Page 27: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

SymptomsRoot Causes

Page 28: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

EasyImportant

Page 29: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 30: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Best Practices

aren’t

Page 31: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Good Enough

isn’t

Page 32: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Incentives

Page 33: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 34: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Pick one:Make ExcusesMake Progress

Page 35: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

GET A MAP

Page 36: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 38: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 39: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 40: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 41: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

CountermeasuresSituational AwarenessOperational ExcellenceDefensible Infrastructure

Page 42: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

CountermeasuresSituational Awareness

Operational Excellence

Defensible Infrastructure

Page 43: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 44: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Countermeasures

Situational Awareness

Operational Excellence

Defensible Infrastructure

Page 45: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

ExperimentationAn untested hypothesis is a wish

Page 46: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

RUGGED SOFTWARE

Page 47: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 48: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

FAST

Page 49: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

AGILE

Page 50: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Are You Rugged?

Page 51: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

HARSH

Page 52: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

UNFRIENDLY

Page 53: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 54: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 55: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

I recognize that my code will be used in ways I cannot anticipate, in ways it was not designed,

and for longer than it was ever intended.

Page 56: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 58: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

SECURITY

COSTINHIBITOR

Page 59: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Source: Wendy Nather (at the time, a CISO)

Page 60: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Vertical: Financial

Business: Money management firm

Implemented Rugged DevOps to quicken the change cycle and tighten the security

Results: Increased from quarterly change cycle, to daily changes,

46 average a month. Reduced failed changes from 17% to 4% Reduced IT audit exceptions to zero

Page 61: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 62: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 63: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

A declaration of intent &

recognition…

Page 64: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

The Rugged Summit

Page 65: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

We don’t all agree

Page 66: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

PICTURE OF A STRAWMAN

Dorothy, why do some AppSec guru’s hate Rugged?

Page 67: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

PICTURE OF A Campfire “story”

Page 68: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 69: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

From the Rugged Handbook StrawMan

Page 70: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Executives CIO/CTO

Security “Analysts”

Architects

Developers

Testers

Program Managers

Page 71: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

CIO Architect Developer QA

Page 72: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Buying and selling software

Understanding the entire software supply chain

Network security, physical security, database security, etc…

Other types of software projects, including legacy code, outsourced code, libraries, etc…

Enterprise level security as opposed to individual projects

Page 73: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Old Purchased

New Purchased

Old Built New Built

Page 74: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

ExperimentationAn untested hypothesis is a wish

Page 75: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 76: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 77: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps
Page 78: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Make it better

Page 79: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

THANK YOUMy Collaborators

Page 80: How Rugged Cultures Drive Biz & AppSec Value · 2020. 1. 17. · 2009 NetworkWorld Top 10 Tech People to Know Ponemon Institute Fellow BLOG: Things I’ve been researching: DevOps

Joshua Corman[Knowledge Seeker | Zombie Killer]

Twitter: @joshcormanBLOG: http://blog.cognitivedissidents.com

@RuggedSoftware @RuggedDevOpshttp://RuggedSoftware.org