Top Banner
Vinay Bansal Security Architect, Cisco Systems Oct. 2016 Continuous Security Securing Clouds in a DevOps World
23

Continuous Security – Securing Clouds in a DevOps World

Feb 13, 2017

Download

Documents

dangtuyen
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Continuous Security – Securing Clouds in a DevOps World

Vinay Bansal

Security Architect, Cisco Systems

Oct. 2016

Continuous Security –Securing Clouds in a DevOps World

Page 2: Continuous Security – Securing Clouds in a DevOps World

• Cloud and Devops

• Why traditional security does not help

• Automation Demo

• Building Security with Devops• Security is visible

• Security is Automated

• Security Individuals Embedded

• Key Takeaways

Outline

Page 3: Continuous Security – Securing Clouds in a DevOps World

Nexus of Four Forces

Cloud

Agile

Devops

Stack

Page 4: Continuous Security – Securing Clouds in a DevOps World

Security: Traditional vs. New Reality

Page 5: Continuous Security – Securing Clouds in a DevOps World

• Security Slows down

• Security always says “No”

• Infosec not embracing new norms• Cloud

• Agile

• Virtualization

Devops : Security Preconception

Page 6: Continuous Security – Securing Clouds in a DevOps World

DevOps Reaction to Security

Page 7: Continuous Security – Securing Clouds in a DevOps World

Breaches and Security Threats on Rise

Page 8: Continuous Security – Securing Clouds in a DevOps World

1. Insecure Configs and Setups

2. Stack (Opensource) Vulnerabilities

3. Credential Management

4. Appcode (homegrown) Vulnerabilities

5. Lack of Active Log Analysis and Monitoring

Top Reasons for Security Incidents

Page 9: Continuous Security – Securing Clouds in a DevOps World

• 100 % Security – Right?

What is Security Goal?

Page 10: Continuous Security – Securing Clouds in a DevOps World

What is Security Goal?

Page 11: Continuous Security – Securing Clouds in a DevOps World

How ?

Page 12: Continuous Security – Securing Clouds in a DevOps World
Page 13: Continuous Security – Securing Clouds in a DevOps World
Page 14: Continuous Security – Securing Clouds in a DevOps World
Page 15: Continuous Security – Securing Clouds in a DevOps World
Page 16: Continuous Security – Securing Clouds in a DevOps World
Page 17: Continuous Security – Securing Clouds in a DevOps World

Security Automation: Demo

Page 18: Continuous Security – Securing Clouds in a DevOps World

MULTIPLE DEPLOYMENT MODELS

NORAD CLOUD(SECaaS)

• Plug and Play for users

NORAD HYBRID• User leverage Norad

Relay machine to

preform scans of

private assets

• Results still stored in

Norad Cloud

ENTERPRISE

• On-site deployment of all Norad infrastructure

Page 19: Continuous Security – Securing Clouds in a DevOps World

Demo

Page 20: Continuous Security – Securing Clouds in a DevOps World

NORAD Capabilities- Current and Planned

Platform Features

• Blackbox and Whitebox testing

• Cloud, hybrid, and on-prem operational models

• Web UI for defining assets, launching tests, and

viewing results

• Full API support for automation

• Cross-platform agent

• Cisco SSO integration

• Email notifications

• Community-based model for adding and

developing security test content

• Security containers for security tests

Security Tests Included

• Qualys vulnerability scanning

• Qualys WAS testing (OWASP top 10 testing)

• Qualys Compliance Check Scanning

• CIS Server Benchmarks

• CIS Docker Host hardening validation

• Docker Image vuln scanning

• OpenStack hardening validation

• Nmap/sslyze crypto tests

• Credentials brute-force testing

• CSDL PSB Validation (12)SEC-OPS-PUBCRYP-2, SEC-OPS-STRENGTH, SEC-DEF-CRED-2, SEC-INT-CRED-2, SEC-CRY-PRM, SEC-AUT-ACCDEF, SEC-CRY-STDCODE, SEC-509-CERTEXT, SEC-509-CHAIN, SEC-509-FQDN, SEC-509-LIFETIME, SEC-509-REVOKE

Page 21: Continuous Security – Securing Clouds in a DevOps World
Page 22: Continuous Security – Securing Clouds in a DevOps World

Questions?

Page 23: Continuous Security – Securing Clouds in a DevOps World