My Dev-Sec-Ops MindMap
Sangram Dash
CISO, VP of IT Sisense (Former PayPal, Square, SVB, CDK Global, KPMG). CISSP, CISM, CDPSE, UCLA MBA.
Humans are pattern-seeking story-telling animals, and yes, I am a human, and here is my DevSecOps story.
In my role, I often need to make recommendations and decisions regarding the tools and processes that can strengthen the DevSecOps environment. With the fast-paced nature of code changes and feature deployment, it's essential to communicate with stakeholders clearly and concisely. This means presenting information in a simple, modular, and cohesive narrative that acknowledges ongoing innovation.
To help visualize this approach, I've created a mind map that outlines the key elements of my DevSecOps story. I break down the different components of the approach, including continuous integration/continuous deployment (CI/CD) pipelines, static and dynamic application security testing (SAST/DAST), vulnerability scanning, and runtime application self-protection (RASP).
By presenting this information in a clear and coherent way, I hope to demonstrate the importance of a holistic approach to security in DevSecOps. Through ongoing innovation and adaptation, we can stay ahead of emerging threats and ensure that our systems remain secure in the face of evolving risks.
Plan:
We use many tools to plan and collaborate. Following is what I like.?
Code:
For a security professional, it is essential to standardize the tech stack. Why? Because we need to secure those. Some tools may not work with the latest open source languages, which are being adopted by the developer community.?
Build:
Selecting a build platform is critical for the DevSecOps process. I observed the following tools working well in the DevSecOps paradigm.?
Test:
Continuous testing complements the Continuous Integration (CI), Continuous Deployment (CD) process. I believe there will be a new term coined as Continuous Testing (CT) to complement CI-CD. The future will be CI/CT/CD.??
领英推荐
Release:
I came to CyberSecurity from a GRC background. The transitional, waterfall-based software release controls still hold good in this Dev-Sec-Ops world. The trick is to educate the auditors and get them to understand the tools. I have worked with many smart auditors, and they have been on board with the idea of automated controls in the DevSecOps process.?
Deploy:
In a simple sense, deploy means releasing the code to production. The incremental deployment techniques supported by modern tools have helped the industry to increase the velocity of deployment.??
Operate:
As we deploy microservices-based applications with Service Mesh, we need to monitor if the service orchestration is effective.?
Monitor:
Monitoring production systems for unusual activities that may result in cyber incidents is our responsibility as cybersecurity professionals.?
Governance:
Governance is different from compliance to an industry-standard (PCI, SOC, ISO, NIST, CIS, PSD2). The Orca, Lacework, Bridgecrew, AWS Audit Manager has a compliance view. A new breed of companies is emerging, and I hope they will transform themselves into Continuous Cloud Compliance Platforms (CCCP - Gartner may coin this buzzword). In my next post, I will detail Drata, Vanta, SecureFrame, VeryGoodSecurity (VGS). I will also talk about API governance (check out traceable.ai)???
Please feel free to provide any feedback. I will be glad to make changes.
Cybersecurity Leader | AWS Certified Cloud Practitioner | CISM | ISO27001 Certified Lead Auditor
3 年Great article Sangram, I enjoyed it and found it informative.
Director, Cybersecurity, Governance, Risk, and Compliance
3 年Great insight and well written.
CISO, VP of IT Sisense (Former PayPal, Square, SVB, CDK Global, KPMG). CISSP, CISM, CDPSE, UCLA MBA.
3 年One of my dear cyber professionals asked me why did I choose the picture of Stonehenge. Two reasons. 1: This prehistoric monument's three-ring structure signifies the defense-in-depth strategy we adopt in Dev-Sec-Ops. 2: Working with engineering and product, we enable the creation of a SECURE product like this structure is a culmination of multiple stones. (FYI, I took that picture).
Very well articulated article Sangram Dash . Anshu Gupta this article answers part of the questions you were asking in today’s Purple Book Community session. Adding Charles Nwatu , Poornaprajna Udupi , Jacob Chirayath , and a few #devsecops leaders to share their wisdom.
Vice President | CRO CISO CIO CTO & VP of Vulnerability Management Liaison | Passionate about B2B SaaS Software & Exposure Management | 23K+
3 年Wonderful job of sharing your #devsecops, journey Sangram! I see a lot of familiar logos that our customers are using, a few new players, and of course love seeing ArmorCode Inc. mention!