Automate or Die: DevSecOps in the Age of Software Supply Chain Attacks

No ratings

Presented at InfoSecurityEurope 2019 by

As nimble organisations deliver new innovations, adversaries are also upping their game, something we’ve seen in recent high profile and devastating cyberattacks. Adversaries have the intent and ability to exploit security vulnerabilities in the software supply chain - and in some cases plant vulnerabilities themselves. They have increased scale through automation and improved breach success through precision targeting. If we don’t fight back by doing the same - automating security directly in the DevOps pipeline, then we’ll always be at the hackers’ mercy. This session will provide new research on the above, and how to get started.Learning Outcomes:Real-world examples of how large and small companies are implementing DevSecOps practices in their own delivery pipelines, and increasing developer awareness to risks Key insights from the 2019 DevSecOps community report - including the top investments for automated securityA walkthrough of how security principles have been automated into a CICD pipeline and what standards for implementation are beginning to follow suite Why DevSecOps is more than a buzzword, and why it’s vital to protecting your software supply chain How automating security of policies makes it harder to ignore