The Ugly Truth About Your DevSecOps Guidelines and Security Policies Bruno Amaro Almeida September 2022
Photo by charlesdeluvio on Unsplash
Slide 2
Hello! About me • Head of Technology & Architecture at Fortum • Independent Advisor / Architect Consultant
Bruno Amaro Almeida brunoamaro.com
Reach out on: @bruno_amaro @brunoamaroalmeida
Slide 3
Fortum Digital Development: Energy Optimization, Sustainability, Electric Mobility Generation, Trading and Asset Optimization District Heating, Recycling & Waste Consumer Solutions
Enterprise 3
…
… Startups
Slide 4
Policies
Cloud Guardrails IAM Hardened Images …
Guidelines
Cloud Security Privacy Open Source Vulnerability Management Incident Management Quality & Testing Enterprise Architecture … 4
Photo by Sixteen Miles Out on Unsplash
Slide 5
Security
vs
Developers
5
Photo by Jeremy Bezanger on Unsplash
Slide 6
Security Threat Modeling “Threat modelling works to identify, communicate, and understand threats and mitigations within the context of protecting something of value.” source: owasp.org
6