Deep Dive into DevSecOps

Presented by

Victoria Geronimo, Product Manager - 2nd Watch & Cindy Blake, Sr. Product Marketing Manager - Security - GitLab

About this talk

DevSecOps is a misnomer. Smashing Security in between Dev and Ops is the wrong way to think about optimizing your DevOps + Security pipeline. Many believe security is the blocker before getting their applications out to production. Owned by some distant, unapproachable team, security can seem like the new deep divide with a 'throw it over the wall' mentality. Instead, Security must be sprinkled throughout the DevOps cycle, taught from the beginning when developing best practices and automating compliant infrastructure, and owned by both DevOps and Security, working as a team. In this webinar, we will dive deep into a sample DevSecOps culture and pipeline and show precisely how Security is not the blocker some make them out to be but an enabler to a positive customer and internal experience. Using the GitLab Secure and Defend solution, we’ll highlight where and how the protections of SAST, DAST, vulnerability scanning, license management, compliance management, and more can be a part of your development process and not a blocker. Additionally, we’ll identify where both DevOps and Security teams can knowledge share in order to best aid each other toward a more efficient, and more secure, pipeline and product. We will focus on a fictional company, specific challenges they faced, and the things they did to address those challenges from Threat Modeling and Risk Classification, Security and DevOps Education, Automated Policy Enforcement, Secrets Management, Vulnerability Scanning, SAST and DAST, monitoring, and more. We'll step through the DevOps cycle and expose exactly where Security comes into play and how many of the steps/process/requirements can be automated to eliminate toil.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (18)
Subscribers (2878)
2nd Watch is an AWS Premier Consulting Partner, Google Cloud Partner and Microsoft Azure Gold Partner providing professional and managed cloud services to enterprises. The company’s subject matter experts and software-enabled services provide companies with tested, proven, and trusted solutions with a focus on six solution areas: Enterprise Cloud Migration, Security and Compliance, Cloud Native and DevOps, Optimization, Data Engineering and Analytics, and Managed Services.