How to Secure DevOps

Published: July 29, 2020, 5 a.m.

b'

Dan \\u201cPop\\u201d Papandrea (@danpopnyc, Field CTO @Sysdig Host @PopcastPop) talks about securing DevOps, how to secure containers and runtimes, and the cultural challenges of security in an agile world.\\xa0

SHOW: 460

SHOW SPONSOR LINKS:


CLOUD NEWS OF THE WEEK - http://bit.ly/cloudcast-cnotw

PodCTL Podcast is Back (Enterprise Kubernetes) - http://podctl.com

SHOW NOTES:


Topic 1 - Welcome to the show. I first got to know you through your podcast The POPcast, but you\\u2019re been around this evolution of the cloud for quite a while. Tell us a bit about your background.\\xa0

Topic 2 - There\\u2019s a concept that\\u2019s now been around a couple years called \\u201cDevSecOps\\u201d. Originally it was \\u201cSec\\u201d being jammed in there because it had been excluded from the early days of DevOps (at least in practice). Where are we with DevSecOps today?\\xa0

Topic 3 - Let\\u2019s talk about DevSecOps in the context of containers. We now have things like Container Scanning, Container Signing, and Immutable Infrastructure and yet security still concerns people. Isn\\u2019t the \\u201csoftware supply chain\\u201d supposed to weed out the vulnerabilities before they get into the production systems?

Topic 4 - One of the challenges that companies have in adopting containers is that they were used to having root access to hosts, and containers live in the user space. How can security tools fit into a container world?\\xa0

Topic 5 - As you talk to lots of companies, how are they dealing with the cultural challenges that go along with implementing DevSecOps?\\xa0

Topic 6 - Any tips or suggestions you can share to help people avoid common DevSecOps mistakes, or accelerate best practices and wider adoption?


FEEDBACK?

'