DevOps Classroomnotes 06/Apr/2022

DevSecOps Manifesto

  • Manifesto
  • An Example of Best Practice.
    • We have a Standard PCI DSS (Payment Card Industry Data Security Standard)
    • Lets look at one rule (11.2)
      11.2 Run internal and external network vulnerability scans at least quarterly and after any significant change in the network.
      Address vulnerabilities and perform rescans as needed, until passing scans
      are achieved.
      After passing a scan for initial PCI DSS compliance, an entity must, in subsequent years, complete four consecutive quarters of passing scans.
      Quarterly external scans must be performed by an Approved Scanning Vendor (ASV).
    • This scan is supposed to be performed quarterly.
    • DevSecOps is all about shift left i.e. what if we perform this scan after every build and deployment which happens daily.
  • When we work with DevOps, to create infrastructure we use Infra Provisioning which has a key principle IAC (Infrastructure as Code)
  • In DevSecOps we embrace the Concept of Security as Code

Including security in CI/CD Pipeline

  • Typical DevOps Pipeline
  • DevSecOps Pipeline/ Bringing Security to DevOps Pipeline
  • Shift Left
  • Roles & Responsibilities
Published
Categorized as Uncategorized Tagged

By continuous learner

devops & cloud enthusiastic learner

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please turn AdBlock off
Customized Social Media Icons from Acurax Digital Marketing Agency

Discover more from Direct DevOps from Quality Thought

Subscribe now to keep reading and get access to the full archive.

Continue reading

Exit mobile version
%%footer%%