Fully Automating Security Early in the Delivery Pipeline


Details
Link to virtual meetup https://us04web.zoom.us/j/410989891
This meetup group is going to be an ONLINE WEBINAR. Link will be shared prior to the event. The event will start at 630 and content will be shared at 7PM.
Integrating security within the standard DevOps CI/CD Pipeline providing full protections while continuing to accelerate solution delivery. Join us at Presidio in Woburn on April 1st for a discussion with our SMEs on “Shifting security to the Left” earlier in the development stage instead of close to the production at the end.
Discussion topics include:
• Review typical challenges development team have with integrating security into the current development practice, particularly for infrastructure as code (IaC) and container development environments
• Common security risks associated with container deployments
• Assessing security risks associated with the new serverless computing development model
• Ongoing challenges protecting running instances and containers after initial image scanning prior to deployment
• Shortcomings of legacy security tools
• Advantages and shortcomings of leveraging public cloud native security tools
• What is "shift left security" and why it is relevant for both on premise and public cloud deployments environments
• How a "shift left" security approach fits into the existing CI environment (Jenkins, CircleCI, TravisCI, etc.)
• Shift left reference architecture
• Demonstration
• Multi Cloud visibility and asset management
• Compliance reporting
• Audit history including JSON code changes over specific points in time
• Detection and auto-remediation
• Image scanning (IaC templates: hosts, containers, serverless) within CI/CD pipeline environment on premise and/or public cloud
• Ongoing runtime protections for deployed workloads (hosts/containers/serverless), auto learning whitelists, firewall protections
• Q&A

Fully Automating Security Early in the Delivery Pipeline