TechTrend Journey To DevSecOps

Download as pdf or txt
Download as pdf or txt
You are on page 1of 12

Journey

Government
to DevSecOps
International Standards
Organization Certifications
Cloud
Experts 

ISO 20000-1:2018
ISO 27001:2013
 ISO 9001: 2015
| TechTrend | info@techtrend.us | 1-855-521-9392 |
Speaker Bio

TECH

James Barr
Senior Director DevSecOps & Cloud Strategy
Innovative senior enterprise technology professional leader specializing in
cloud services, application modernization, DevSecOps, strategic planning,
organizational transformation and data analytics.

https://www.linkedin.com/in/jamesbarr7/ jbarr@techtrend.us

2
Why DevSecOps?

85 percent of all applications One in three applications were


contain at least one vulnerability vulnerable to attack through high
after the first scan.1 or very high severity flaws.2

13 percent of applications $2.08 Trillion = total cost of poor


contain at least one very high software quality.4
severity flaw.3

DevSecOps programs fix bugs almost 12x faster than average as a result of security reviews and increased code
scanning throughout the continuous delivery process.5

3
DevSecOps Evolution
Enterprise Secure Code Scanning Speed up application development Government agencies need to
and Testing for common security and deployment through achieve ATO status. Streamline and
vulnerabilities automation. automate

Agile App Source Code DevSecOps


Development Management SaaS

Code CI/CD FedRAMP


Vulnerability Controls

Pre-harden and integrate an end-to-


Central Code repository
end toolchain that enables and
Dedicated environment
empowers developers

4
This document is sensitive and intended only for the client addressed
Federal GovCloud DevSecOps

INTEGRATED LANDING ZONE RAPID INDUSTRY


TOOLCHAIN AGNOSTIC DEPLOYMENT LEADING TOOKIT

5
DevSecOps Philosophy
 Engineering and cultural approach

 Eliminates Legacy Approach

 CI/CD for Rapid Production


Deployments

 Optimize the software


development lifecycle (SDLC)

 Gateway to Cloud Adoption

This document is sensitive and intended only for the client addressed 6
Workflow
Define & Build Build & Deploy Test Security Gate Email Notification
Application Environment

Design/ Infrastructure as Code Testing Deploy to Environment


Initialize Configuration Management as Code
Database as Code

7
This document is sensitive and intended only for the client addressed
DevSecOps Security Benefits

ENABLE SECURITY DETECT VULNERNABILITIES EARLIER

UNCOVER TRENDS INCREASE VISIBILITY

8
DevSecOps Advanced Security
Compliance & Encryption Data Segmentation

FedRAMP Controls Security Enforcement

Data Protection Third-party Sign-off

Notable Security Features

This document is sensitive and intended only for the client addressed 9
DevSecOps Takeaways

10
Thank You

www.techtrend.us twitter.com/TechTrendInc

facebook.com/TechTrendInc
info@techtrend.us
Youtube.com/UCYS3Uhq3mlXTxcS_UNMCSBA

1-855-521-9392 linkedin.com/techtrendinc/

11
References
1. Veracode 2018. The State of Software Security. Retrieved from Veracode
website:https://www.veracode.com/state-of-software-security-report
2. Ibid
3. Ibid
4. Consortium for Information & Software QualityTM (CISQ) 2021. The Cost
of Poor Software Quality in the US: A 2020 Report.
Retrieved from Synopsys website: https://www.synopsys.com/software-i
ntegrity/resources/analyst-reports/cost-poor-quality-software.html
5. Veracode 2018, Ibid

You might also like