Shannon Lietz on Building DevSecOps at Intuit

434 views
•
February 22, 2017
by
RSAC Cybersecurity
YouTube video player
Shannon Lietz on Building DevSecOps at Intuit

TL;DR

DevSecOps integrates development, security, and operations so security decisions and checks occur throughout the software development life cycle, not only at runtime. At Intuit, this includes rapid attack mapping, CI/CD-compatible tooling, compliance as code, and feedback from security operations, helping developers prioritize important vulnerabilities and shorten the time from detecting a software defect to remediating it.

Transcript

Hello and welcome back to RSAC TV. We're here in the Moscone West in downtown San Francisco, and I'm your host, Paul Roberts, the editor-in-chief at the Security Ledger. We've been coming to you all week long from San Francisco during this year's RSA Security Conference, talking to some of the luminaries and security leaders, thought leaders who ar... Read More

Key Insights

  • DevSecOps is the integration of development, security, and operations within the software development life cycle. Its purpose is to make security part of early design and implementation decisions while connecting those decisions with operational detection, response, and remediation activities.
  • Intuit's DevSecOps journey grew from moving products from desktop environments to the cloud. The transition exposed demanding security requirements and showed that coding, application security, DevOps, and security operations needed to function as a connected organizational and technical process.
  • The key to reducing remediation time is linking early security ideation with security operations. Attack knowledge developed while software is being designed can inform operational rules, while operational findings can return to developers and DevOps teams responsible for correcting defects.
  • Rain Dance is an Intuit capability that uses attack maps to support secure software development. Lietz says a team can create an attack map in 15 minutes and hand it to security operations, which can then use that information to build relevant rules.
  • DevSecOps does not depend on one specific tool. Lietz identifies existing DevOps tools such as Chef and Puppet, emerging compliance-as-code practices, cloud-enabled security incident event monitoring, open-source capabilities, APIs, and CI/CD integration as parts of the broader toolkit.
  • Sensitive data workloads make software security essential for Intuit products such as QuickBooks, Mint, and TurboTax. Developers and DevOps teams make early security decisions and later resolve discovered issues, so security checks and guidance must exist inside their normal development pipeline.
  • Modern software complexity increases security risk because developers increasingly integrate packages, partner capabilities, and services instead of writing every component themselves. Trusting reputable companies or actively maintained open-source libraries does not ensure that their code has been fully vetted or secured.
  • Developer-focused security tooling should run throughout development, be easy to use, integrate with CI/CD pipelines, expose APIs, reduce false positives, and prioritize important vulnerabilities. Addressing severe, easily exploited weaknesses first can make security work more manageable before teams tackle nuanced problems.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is DevSecOps and how does it work?

DevSecOps brings coding, security, and operations into one connected software development process. Security is considered during early ideation and continues through implementation, deployment, monitoring, and remediation. Application security and security operations are joined so early threat information can inform operational rules, while discovered defects can return quickly to the developers or DevOps teams able to correct them.

Q: How did Intuit develop its DevSecOps approach?

Intuit's approach developed as the company moved products from desktop environments to the cloud. According to Shannon Lietz, the organization initially lacked a complete understanding of how to combine the required capabilities. Because cloud environments were demanding from a security perspective, Intuit brought coding, security, and operations personnel together and eventually formed a DevSecOps team that culminated in the red team.

Q: How can security be shifted earlier in software development?

Security can move earlier by making it part of ideation, design, and the development pipeline instead of relying mainly on runtime testing. Developers need tools that let them check their work as it progresses. Those tools should be easy to use, API-driven, integrated with CI/CD pipelines, and capable of filtering false positives so teams can concentrate on important defects.

Q: What is Rain Dance in Intuit's DevSecOps process?

Rain Dance is a capability used by Intuit to help teams envision how software can be built securely at speed and scale. It includes attack maps that can be produced in 15 minutes while software is being built. The resulting map can be handed to security operations, which can use the information to create rules and connect development decisions with operational security.

Q: What tools are needed for DevSecOps?

There is no single tool that provides DevSecOps. Lietz describes a collection of capabilities, including DevOps tools such as Chef and Puppet, compliance as code, cloud-enabled security incident event monitoring, attack mapping, APIs, and CI/CD-compatible security checks. Intuit has also open-sourced capabilities and worked across companies, making community involvement part of the broader toolkit and operating model.

Q: Why do companies still struggle with OWASP Top 10 vulnerabilities?

Companies struggle because software development has become more complex and increasingly depends on integrated packages, partnerships, services, and open-source libraries. Security assumptions can travel through this chain without enough tooling to verify them. In addition, many security products test applications end to end at runtime, even though the decisions that create defects were made much earlier in development.

Q: Why should security tools prioritize the most important vulnerabilities?

Security tools that report every possible issue can overwhelm developers with false positives and findings that are not equally important. Lietz argues that teams should first focus on serious weaknesses that are easy for a script kiddie to attack, including prominent web application problems. Removing those issues first makes it easier for developers to participate before addressing more nuanced, fine-grained security problems.

Q: Who is responsible for software security in a DevSecOps model?

Developers and DevOps teams hold central responsibility because they make early decisions that affect security and are also the people who resolve many discovered defects. Security professionals support them by providing tools, feedback, and an assessment of whether practices are working. Security operations contributes detection and response capabilities, including help when an attacker must be chased away.

Summary & Key Takeaways

  • Shannon Lietz describes DevSecOps as the integration of coding, security, and operations across the software development life cycle. Intuit developed this approach while moving products from desktop environments to the cloud, where security demands required developers, DevOps teams, security professionals, and security operations personnel to work within a connected process.

  • Intuit uses tools and practices that move security earlier into software development. Rain Dance enables teams to produce an attack map in 15 minutes and pass it to security operations for rule creation. Other useful capabilities include DevOps tools, compliance as code, cloud-aware monitoring, open-source resources, APIs, and CI/CD integration.

  • Common vulnerabilities remain difficult because modern applications increasingly integrate external packages, partnerships, and services whose security may be implicitly trusted. Many security tools also operate at runtime, after important design decisions have been made. Developer-friendly checks should run throughout development, reduce false positives, and prioritize serious, easily exploited weaknesses before subtler issues.

  • Key Insights Included

  • Security Operations Integration

  • Shift Left Security Practices

  • Cloud Migration and Sensitive Data Protection

  • Developer-Friendly Security Tooling

  • OWASP Top 10 Challenges

  • Third-Party Package and Dependency Risk

  • Rain Dance Attack Mapping

  • CI/CD and Compliance as Code


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚