The Ugly Truth About Your DevSecOps Guidelines and Security Policies

A presentation at IDC IT Security Finland 2022 in September 2022 in Helsinki, Finland by Bruno Amaro Almeida

Slide 1

Slide 1

The Ugly Truth About Your DevSecOps Guidelines and Security Policies Bruno Amaro Almeida September 2022 Photo by charlesdeluvio on Unsplash

Slide 2

Slide 2

Hello! About me • Head of Technology & Architecture at Fortum • Independent Advisor / Architect Consultant Bruno Amaro Almeida brunoamaro.com Reach out on: @bruno_amaro @brunoamaroalmeida

Slide 3

Slide 3

Fortum Digital Development: Energy Optimization, Sustainability, Electric Mobility Generation, Trading and Asset Optimization District Heating, Recycling & Waste Consumer Solutions Enterprise 3 … … Startups

Slide 4

Slide 4

Policies Cloud Guardrails IAM Hardened Images … Guidelines Cloud Security Privacy Open Source Vulnerability Management Incident Management Quality & Testing Enterprise Architecture … 4 Photo by Sixteen Miles Out on Unsplash

Slide 5

Slide 5

Security vs Developers 5 Photo by Jeremy Bezanger on Unsplash

Slide 6

Slide 6

Security Threat Modeling “Threat modelling works to identify, communicate, and understand threats and mitigations within the context of protecting something of value.” source: owasp.org 6

Slide 7

Slide 7

AWS and Azure Well-Architected Framework & Review • Consistent, Repeatable Assessment • Identify Risks & Opportunities • Outside perspective new Sustainability 7

Slide 8

Slide 8

Fortum Digital Development Handbook Inspired by 💚 https://s-group-dev.github.io/development-guidelines/ 8 (…)

Slide 9

Slide 9

Guidelines Digital Development Handbook Assessments 9 HOW WHY WHAT Builders Library HOW

Slide 10

Slide 10

Connecting the dots with Backstage • Tech Radar • Digital Development Handbook • Core IT Handbook • Builders Library and Templates • Metrics (e.g. DORA, SLAs, SLOs) • … 10 source: backstage.io

Slide 11

Slide 11

Culture > Processes > Technologies 11

Slide 12

Slide 12

Thanks! Questions? Feedback? Bruno Amaro Almeida brunoamaro.com Reach out on: @bruno_amaro @brunoamaroalmeida