Introduction
How DevOps creates more security risk for organizations
The price of agility, speed and de-centralized control
Inadequacies of traditional security tools
Security policies
Firewall rules
Lack of APIs for integration
Lack of visualization tools
Implementing a DevOps-ready security program
Aligning security with business goals
Removing the security bottleneck
Implementing detailed visibility
Standardizing security configurations
Adding sensors into the application
Interactive Application Security Testing
Runtime Application Self-Protection
Providing security data to DevOps tools through RESTful APIs
On-demand scaling, micro-perimeterization of security controls
Per-resource granular security policies
Automating attacks against pre-production code
Continually testing the production environment
Protecting web applications from an Agile/DevOps perspective
Securing containers and clouds
Embracing next generation automated security tools
The future of DevOps and its strategic role in security
Closing remarks
|