SlideShare a Scribd company logo
Secure your Azure and
DevOps in a smart way
Mitä kuuluu?
I am Victoria
Security girl at MS
Find me at @texnokot
or victoria.almazova@microsoft.com
100:10:1
DevOps is the union of people,
process, and technology to enable
continuous delivery of value to your
end users
DevOps
Monitor
&
learn
Develop &
TestPlan &
Track
Build
&
Release
Continuous
delivery
automation
Why not to automate security then?
delivering the product
Pre-commit Commit (CI) Acceptance (CD) Production Operations
Pre-commit stage
✘ Threat modeling
✘ IDE Security plugins
✘ Pre-commit hooks
✘ Secure coding standards
✘ Peer review
Goal: fix security from the first line of a code
Commit stage
✘ Static code analysis
✘ Security unit tests
✘ Dependency management
Goal: provide fast feedback to developers
Acceptance stage
✘ Infrastructure as Code
✘ Security scanning
✘ Cloud configuration
✘ Security acceptance testing
Goal: comprehensive check of the application and infrastructure
Production stage
✘ Security smoke tests
✘ Configuration checks
✘ Penetration testing
Goal: ensure that setup follows security traditions
Operations
✘ Continuous monitoring
✘ Threat intelligence
✘ Vulnerability assessment
✘ Blameless postmortems
Goal: continuous security and lessons learned
We get DevSecOps
Pre-commit
✘ Threat modeling
✘ IDE Security plugins
✘ Pre-commit hooks
✘ Secure coding
standards
✘ Peer review
Commit (CI)
✘ Static code analysis
✘ Security unit tests
✘ Dependency
management
Acceptance (CD)
✘ IaC
✘ Security scanning
✘ Cloud configuration
✘ Security acceptance
testing
Production
✘ Security smoke tests
✘ Configuration checks
✘ Penetration testing
Operations
✘ Continuous
monitoring
✘ Threat intelligence
✘ Penetration testing
✘ Blameless
postmortems
Azure prod subsc
Azure DevOps
repository
Azure DevOps
pipelines
Azure DevOps
release
VS Studio/Code
Azure QA subsc
Azure dev subsc
develop
master
CI build
CI build
DevSkim, Puma
scan, Coverity,
Fortify
Pre-commit hooks
AzSK Secure
DevOps Kit
(AzSK),
MS Azure Policy,
Snyk,
WhiteSource Bolt,
Coverity,
Fortify
MS Azure Policy,
Azure Management,
Azure Monitor,
Microsoft Azure
Security Center
14
Resources
✘ SANS poster: https://www.sans.org/security-resources/posters/secure-devops-toolchain-swat-
checklist/60/download
✘ Azure security best practices: https://docs.microsoft.com/en-us/azure/security/security-best-practices-and-
patterns
✘ Secure DevOps Kit for Azure: https://github.com/azsk/DevOpsKit-docs
✘ Azure DevOps Services: https://azure.microsoft.com/en-us/services/devops/
✘ Azure applications design principles: https://docs.microsoft.com/en-us/azure/architecture/guide/design-
principles/
✘ WhiteSource Bolt extension for Azure DevOps Services: https://marketplace.visualstudio.com/items?
itemName=whitesource.ws-bolt
✘ The OWASP Foundation: https://www.owasp.org/index.php/Main_Page
✘ And me ☺ at github: https://github.com/texnokot/
✘ And of course twitter: https://twitter.com/texnokot
“
thanks!
Any questions?
You can find me at
@texnokot
victoria.almazova@microsoft.com

More Related Content

What's hot (20)

PPTX
DevSecOps reference architectures 2018
Sonatype
 
PDF
Azure Security Overview
David J Rosenthal
 
PDF
Scaling DevSecOps Culture for Enterprise
Opsta
 
PPTX
Explore Microsoft Power Platform Center of Excellence
Nanddeep Nachan
 
PDF
Azure DDoS Protection Standard
arnaudlh
 
PDF
Security Process in DevSecOps
Opsta
 
PDF
introduction to Azure Sentinel
Robert Crane
 
PDF
Slide DevSecOps Microservices
Hendri Karisma
 
PPTX
VVF-Customer-Presentation-Ver1.9222.pptx
blackmambaettijean
 
PDF
Azure DevOps Presentation
InCycleSoftware
 
PDF
Practical DevSecOps Course - Part 1
Mohammed A. Imran
 
PDF
Infrastructure as Code
Albert Suwandhi
 
PDF
Dos and Don'ts of DevSecOps
Priyanka Aash
 
PDF
Azure cloud migration simplified
Girlo
 
PPTX
Azure devops
Mohit Chhabra
 
PPTX
Identity management and single sign on - how much flexibility
Ryan Dawson
 
PPTX
Leveraging Azure DevOps across the Enterprise
Andrew Kelleher
 
PDF
Azure DevOps - Azure Guatemala Meetup
Guillermo Zepeda Selman
 
PDF
2019 DevSecOps Reference Architectures
Sonatype
 
PPTX
Kubernetes and container security
Volodymyr Shynkar
 
DevSecOps reference architectures 2018
Sonatype
 
Azure Security Overview
David J Rosenthal
 
Scaling DevSecOps Culture for Enterprise
Opsta
 
Explore Microsoft Power Platform Center of Excellence
Nanddeep Nachan
 
Azure DDoS Protection Standard
arnaudlh
 
Security Process in DevSecOps
Opsta
 
introduction to Azure Sentinel
Robert Crane
 
Slide DevSecOps Microservices
Hendri Karisma
 
VVF-Customer-Presentation-Ver1.9222.pptx
blackmambaettijean
 
Azure DevOps Presentation
InCycleSoftware
 
Practical DevSecOps Course - Part 1
Mohammed A. Imran
 
Infrastructure as Code
Albert Suwandhi
 
Dos and Don'ts of DevSecOps
Priyanka Aash
 
Azure cloud migration simplified
Girlo
 
Azure devops
Mohit Chhabra
 
Identity management and single sign on - how much flexibility
Ryan Dawson
 
Leveraging Azure DevOps across the Enterprise
Andrew Kelleher
 
Azure DevOps - Azure Guatemala Meetup
Guillermo Zepeda Selman
 
2019 DevSecOps Reference Architectures
Sonatype
 
Kubernetes and container security
Volodymyr Shynkar
 

Similar to Secure your Azure and DevOps in a smart way (20)

PPTX
Secure DevOPS Implementation Guidance
Tej Luthra
 
PDF
Azure Security Check List - Final.pdf
Okan YILDIZ
 
PDF
DevSecOps Basics with Azure Pipelines
Abdul_Mujeeb
 
PPTX
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
ellan12
 
PDF
DevOps or DevSecOps
Michelangelo van Dam
 
PDF
Security Scanning Solutions_ Protecting Applications in the DevOps Era.pdf
Devseccops.ai
 
PPTX
Azure DevOps työkalut - Roundtable 14.3.2019
Janne Mattila
 
PDF
Boris Devouge (Microsoft) - DevOps on Azure
Outlyer
 
PDF
1 2 dev ops - vsts overview
Okko Oulasvirta
 
PDF
2021-10-14 The Critical Role of Security in DevOps.pdf
Savinder Puri
 
PDF
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
PPTX
DevOps & Security: Here & Now
Checkmarx
 
PPTX
Azure DevSecOps Training | Azure DevOps Certification Course.pptx
TalluriRenuka
 
PDF
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
PPTX
Putting the DOT in .NET - Dev/Ops/Test
Robert MacLean
 
PDF
Zure Azure PaaS Zero to Hero - DevOps training day
Okko Oulasvirta
 
PDF
DevSecOps at Agile 2019
Elizabeth Ayer
 
PPTX
DevSecOps Introduction Tushar Joshi - Owasp Nagpur Meetup 12 May 2019
OWASP Nagpur
 
PDF
Secure Your Code Implement DevSecOps in Azure
kloia
 
PPTX
Tour de France Azure PaaS 5/7 Accélérer avec le DevOps
Alex Danvy
 
Secure DevOPS Implementation Guidance
Tej Luthra
 
Azure Security Check List - Final.pdf
Okan YILDIZ
 
DevSecOps Basics with Azure Pipelines
Abdul_Mujeeb
 
AddingtheSecToDevOpsBSides (1).pptx for Bsides Nairobi 22 with Joylynn Kirui
ellan12
 
DevOps or DevSecOps
Michelangelo van Dam
 
Security Scanning Solutions_ Protecting Applications in the DevOps Era.pdf
Devseccops.ai
 
Azure DevOps työkalut - Roundtable 14.3.2019
Janne Mattila
 
Boris Devouge (Microsoft) - DevOps on Azure
Outlyer
 
1 2 dev ops - vsts overview
Okko Oulasvirta
 
2021-10-14 The Critical Role of Security in DevOps.pdf
Savinder Puri
 
Why Security Engineer Need Shift-Left to DevSecOps?
Najib Radzuan
 
DevOps & Security: Here & Now
Checkmarx
 
Azure DevSecOps Training | Azure DevOps Certification Course.pptx
TalluriRenuka
 
Strengthen and Scale Security for a dollar or less
Mohammed A. Imran
 
Putting the DOT in .NET - Dev/Ops/Test
Robert MacLean
 
Zure Azure PaaS Zero to Hero - DevOps training day
Okko Oulasvirta
 
DevSecOps at Agile 2019
Elizabeth Ayer
 
DevSecOps Introduction Tushar Joshi - Owasp Nagpur Meetup 12 May 2019
OWASP Nagpur
 
Secure Your Code Implement DevSecOps in Azure
kloia
 
Tour de France Azure PaaS 5/7 Accélérer avec le DevOps
Alex Danvy
 
Ad

More from Eficode (20)

PPTX
Saving money with Consolidations
Eficode
 
PDF
DevOps Automation with Puppet Bolt & Puppet Enterprise
Eficode
 
PDF
Scaling DevOps: Pitfalls to avoid
Eficode
 
PDF
Microservices, IoT, DevOps: A Case Study
Eficode
 
PPTX
Building a Knowledge Graph at Zalando
Eficode
 
PPTX
How to build the Cloud Native applications the way you want – not the way the...
Eficode
 
PPTX
The Future of Enterprise Applications is Serverless
Eficode
 
PPTX
Why Serverless is scary without DevSecOps and Observability
Eficode
 
PPTX
Securing Modern Applications: The Data Behind DevSecOps
Eficode
 
PDF
Can I Contain This?
Eficode
 
PDF
The Mono-repo – a contradiction with Microservices
Eficode
 
PDF
Using Go in DevOps
Eficode
 
PDF
Why Should You Be Thinking About DesignOps?
Eficode
 
PDF
A beginners guide to scaling DevOps
Eficode
 
PPTX
From Zero to SAFe
Eficode
 
PPTX
Bringing value to the business and for your customer through DevOps
Eficode
 
PPTX
Disconnected Pipelines: The Missing Link
Eficode
 
PDF
The Best & Worst Uses of AI in Software Testing
Eficode
 
PDF
Model-based programming and AI-assisted software development
Eficode
 
PDF
2018 State Of DevOps Report Key Findings
Eficode
 
Saving money with Consolidations
Eficode
 
DevOps Automation with Puppet Bolt & Puppet Enterprise
Eficode
 
Scaling DevOps: Pitfalls to avoid
Eficode
 
Microservices, IoT, DevOps: A Case Study
Eficode
 
Building a Knowledge Graph at Zalando
Eficode
 
How to build the Cloud Native applications the way you want – not the way the...
Eficode
 
The Future of Enterprise Applications is Serverless
Eficode
 
Why Serverless is scary without DevSecOps and Observability
Eficode
 
Securing Modern Applications: The Data Behind DevSecOps
Eficode
 
Can I Contain This?
Eficode
 
The Mono-repo – a contradiction with Microservices
Eficode
 
Using Go in DevOps
Eficode
 
Why Should You Be Thinking About DesignOps?
Eficode
 
A beginners guide to scaling DevOps
Eficode
 
From Zero to SAFe
Eficode
 
Bringing value to the business and for your customer through DevOps
Eficode
 
Disconnected Pipelines: The Missing Link
Eficode
 
The Best & Worst Uses of AI in Software Testing
Eficode
 
Model-based programming and AI-assisted software development
Eficode
 
2018 State Of DevOps Report Key Findings
Eficode
 
Ad

Recently uploaded (20)

PDF
Why aren't you using FME Flow's CPU Time?
Safe Software
 
PDF
“MPU+: A Transformative Solution for Next-Gen AI at the Edge,” a Presentation...
Edge AI and Vision Alliance
 
PDF
UiPath Agentic AI ile Akıllı Otomasyonun Yeni Çağı
UiPathCommunity
 
PPTX
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Poster...
Michele Kryston
 
PDF
Salesforce Summer '25 Release Frenchgathering.pptx.pdf
yosra Saidani
 
PDF
From Chatbot to Destroyer of Endpoints - Can ChatGPT Automate EDR Bypasses (1...
Priyanka Aash
 
PDF
Automating the Geo-Referencing of Historic Aerial Photography in Flanders
Safe Software
 
PDF
FME as an Orchestration Tool with Principles From Data Gravity
Safe Software
 
PDF
My Journey from CAD to BIM: A True Underdog Story
Safe Software
 
PDF
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
 
PPTX
Paycifi - Programmable Trust_Breakfast_PPTXT
FinTech Belgium
 
PDF
Redefining Work in the Age of AI - What to expect? How to prepare? Why it mat...
Malinda Kapuruge
 
PDF
How to Visualize the ​Spatio-Temporal Data Using CesiumJS​
SANGHEE SHIN
 
PDF
Open Source Milvus Vector Database v 2.6
Zilliz
 
PDF
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 
PDF
EIS-Webinar-Engineering-Retail-Infrastructure-06-16-2025.pdf
Earley Information Science
 
PPTX
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Pitch ...
Michele Kryston
 
PPTX
Smarter Governance with AI: What Every Board Needs to Know
OnBoard
 
PPTX
reInforce 2025 Lightning Talk - Scott Francis.pptx
ScottFrancis51
 
PPTX
Practical Applications of AI in Local Government
OnBoard
 
Why aren't you using FME Flow's CPU Time?
Safe Software
 
“MPU+: A Transformative Solution for Next-Gen AI at the Edge,” a Presentation...
Edge AI and Vision Alliance
 
UiPath Agentic AI ile Akıllı Otomasyonun Yeni Çağı
UiPathCommunity
 
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Poster...
Michele Kryston
 
Salesforce Summer '25 Release Frenchgathering.pptx.pdf
yosra Saidani
 
From Chatbot to Destroyer of Endpoints - Can ChatGPT Automate EDR Bypasses (1...
Priyanka Aash
 
Automating the Geo-Referencing of Historic Aerial Photography in Flanders
Safe Software
 
FME as an Orchestration Tool with Principles From Data Gravity
Safe Software
 
My Journey from CAD to BIM: A True Underdog Story
Safe Software
 
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
 
Paycifi - Programmable Trust_Breakfast_PPTXT
FinTech Belgium
 
Redefining Work in the Age of AI - What to expect? How to prepare? Why it mat...
Malinda Kapuruge
 
How to Visualize the ​Spatio-Temporal Data Using CesiumJS​
SANGHEE SHIN
 
Open Source Milvus Vector Database v 2.6
Zilliz
 
Hello I'm "AI" Your New _________________
Dr. Tathagat Varma
 
EIS-Webinar-Engineering-Retail-Infrastructure-06-16-2025.pdf
Earley Information Science
 
MARTSIA: A Tool for Confidential Data Exchange via Public Blockchain - Pitch ...
Michele Kryston
 
Smarter Governance with AI: What Every Board Needs to Know
OnBoard
 
reInforce 2025 Lightning Talk - Scott Francis.pptx
ScottFrancis51
 
Practical Applications of AI in Local Government
OnBoard
 

Secure your Azure and DevOps in a smart way

  • 1. Secure your Azure and DevOps in a smart way
  • 2. Mitä kuuluu? I am Victoria Security girl at MS Find me at @texnokot or [email protected]
  • 4. DevOps is the union of people, process, and technology to enable continuous delivery of value to your end users DevOps Monitor & learn Develop & TestPlan & Track Build & Release Continuous delivery
  • 5. automation Why not to automate security then?
  • 6. delivering the product Pre-commit Commit (CI) Acceptance (CD) Production Operations
  • 7. Pre-commit stage ✘ Threat modeling ✘ IDE Security plugins ✘ Pre-commit hooks ✘ Secure coding standards ✘ Peer review Goal: fix security from the first line of a code
  • 8. Commit stage ✘ Static code analysis ✘ Security unit tests ✘ Dependency management Goal: provide fast feedback to developers
  • 9. Acceptance stage ✘ Infrastructure as Code ✘ Security scanning ✘ Cloud configuration ✘ Security acceptance testing Goal: comprehensive check of the application and infrastructure
  • 10. Production stage ✘ Security smoke tests ✘ Configuration checks ✘ Penetration testing Goal: ensure that setup follows security traditions
  • 11. Operations ✘ Continuous monitoring ✘ Threat intelligence ✘ Vulnerability assessment ✘ Blameless postmortems Goal: continuous security and lessons learned
  • 12. We get DevSecOps Pre-commit ✘ Threat modeling ✘ IDE Security plugins ✘ Pre-commit hooks ✘ Secure coding standards ✘ Peer review Commit (CI) ✘ Static code analysis ✘ Security unit tests ✘ Dependency management Acceptance (CD) ✘ IaC ✘ Security scanning ✘ Cloud configuration ✘ Security acceptance testing Production ✘ Security smoke tests ✘ Configuration checks ✘ Penetration testing Operations ✘ Continuous monitoring ✘ Threat intelligence ✘ Penetration testing ✘ Blameless postmortems
  • 13. Azure prod subsc Azure DevOps repository Azure DevOps pipelines Azure DevOps release VS Studio/Code Azure QA subsc Azure dev subsc develop master CI build CI build DevSkim, Puma scan, Coverity, Fortify Pre-commit hooks AzSK Secure DevOps Kit (AzSK), MS Azure Policy, Snyk, WhiteSource Bolt, Coverity, Fortify MS Azure Policy, Azure Management, Azure Monitor, Microsoft Azure Security Center
  • 14. 14
  • 15. Resources ✘ SANS poster: https://www.sans.org/security-resources/posters/secure-devops-toolchain-swat- checklist/60/download ✘ Azure security best practices: https://docs.microsoft.com/en-us/azure/security/security-best-practices-and- patterns ✘ Secure DevOps Kit for Azure: https://github.com/azsk/DevOpsKit-docs ✘ Azure DevOps Services: https://azure.microsoft.com/en-us/services/devops/ ✘ Azure applications design principles: https://docs.microsoft.com/en-us/azure/architecture/guide/design- principles/ ✘ WhiteSource Bolt extension for Azure DevOps Services: https://marketplace.visualstudio.com/items? itemName=whitesource.ws-bolt ✘ The OWASP Foundation: https://www.owasp.org/index.php/Main_Page ✘ And me ☺ at github: https://github.com/texnokot/ ✘ And of course twitter: https://twitter.com/texnokot
  • 16.