23.12.2015 Views

DevOps

DevOps_RuggedBook_Web

DevOps_RuggedBook_Web

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

help speak in the universal language of<br />

Rugged <strong>DevOps</strong>: speed of delivery.<br />

“There should be a really big shift<br />

for security people, moving from an<br />

approver and requester relationship with<br />

<strong>DevOps</strong> guys to more of a facilitative<br />

and partnership relationship,” says<br />

Prendergast, “where developers and<br />

operations are helping with security<br />

and learning along the way, and<br />

security is able to mentor and continue<br />

to pass responsibility to the <strong>DevOps</strong><br />

guys, because automation is making it<br />

possible to remove the human element<br />

from lot of processes.”<br />

As Edwards explained in his OWASP<br />

talk last year, security would do well to<br />

learn from many QA professionals who<br />

have embraced their role as toolsmiths<br />

and mentors within the <strong>DevOps</strong> value<br />

chain. As toolsmiths, they do their best<br />

to develop a toolset that enables as<br />

much self-service help as possible. And<br />

as mentors, security should be helping<br />

to identify security champions who<br />

can lift some of the everyday security<br />

mitigation workload off the security<br />

team’s shoulders, allowing them to<br />

focus on more strategic work.<br />

Wickett related a story about how<br />

cheaply a security empire building<br />

can be won. He explained that Ken<br />

Johnson, while at Living Social, ran an<br />

internal capture-the-flag, bug-finding<br />

competition. The prize was a specially<br />

designed, very limited-edition t-shirt.The<br />

program was simple but effective.<br />

“That’s a unique way to get people<br />

interested in security,” he says. “It helps<br />

you identify people in your organization<br />

who you can tap in the future and<br />

whenever the winners wear the shirt,<br />

people see it and are more aware of<br />

security.”

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!