How Can DevSecOps Improve Complex System Safety?

314 views
β€’
February 26, 2020
by
RSAC Cybersecurity
YouTube video player
How Can DevSecOps Improve Complex System Safety?

TL;DR

DevSecOps improves security by making it an inclusive part of development and operations, rather than a separate team that mainly inhibits change. Because distributed systems are too complex for humans to model completely, teams must interact with them, share responsibility, and apply security chaos engineering to understand behavior while continuing to deliver customer value quickly.

Transcript

All right. Hey, good afternoon, everybody. How's it going here at RSA? Good? You kinda-- Hopefully you had lunch. I don't know. Like, this is, this is that weird up against lunch spot. Um, hey, we're really, really excited to be here today, and let me just start off by saying I, I work at Verica, and Aaron works at Verica, but we're not gonna reall... Read More

Key Insights

  • DevSecOps is an inclusive role and organizational movement that integrates security into DevOps practices. It is not a product, a tool, or merely a CI/CD pipeline that an organization can purchase and install.
  • A worldview is the mental map through which a person understands daily reality. Developers, operations professionals, and security practitioners bring different worldviews into their work, which helps explain persistent disconnects and silos among these groups.
  • Traditional security teams may operate with the goal of inhibiting change as much as possible. This worldview conflicts with engineering teams that use leading-edge technologies and deliver value quickly, creating friction between security controls and organizational productivity.
  • Security risk assessment can become a substitute for adequately funded engineering work. The talk cites criticism that structured inadequacy and underfunded security combined with risk management should not be treated as equivalent to properly funded security efforts.
  • DevOps became inevitable because efficient operations in distributed computing and cloud environments require practices that scale beyond separate development and operations silos. Environments containing thousands of servers demand people and processes capable of working across traditional boundaries.
  • Unequal labor distribution naturally creates organizational silos. The talk describes ratios of ten developers to one operations person and, when security is included, one security person for every hundred developers, making isolated security work difficult to scale.
  • Complex systems are nonlinear systems whose behavior humans cannot fully model. Examples given include the human body, nation-state political interactions, financial markets, weather patterns, and distributed computer systems, all of which can exhibit cascading failures.
  • Understanding a complex system requires interacting with it because mental models alone cannot capture its behavior. As modern computing systems continually gain components and complexity, outages and breaches are expected to worsen without more effective approaches to security and system safety.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is DevSecOps in modern software organizations?

DevSecOps is an inclusive organizational movement that brings security into the shared work of development and operations. It is treated as interchangeable with DevOps because security should participate directly in how modern systems are built and operated. It is not a commercial tool, an artificial intelligence product, or simply a CI/CD pipeline that can be purchased from a vendor.

Q: Why has DevSecOps become necessary for distributed systems?

DevSecOps has become necessary because distributed computing and cloud environments operate at a scale that traditional silos cannot support efficiently. Separate development and operations teams may function with tens or hundreds of servers, but environments involving thousands of servers require people and practices that cross boundaries. Security must join that scalable operating model rather than remain on the sidelines.

Q: How do different worldviews create conflict between security and engineering?

A worldview is a person's mental map of daily reality, and no two people have exactly the same one. Developers, operations teams, and security practitioners therefore approach systems, change, and risk from different perspectives. When security seeks to inhibit change while engineering seeks to deploy leading-edge technologies and deliver value quickly, those differing priorities create disconnects, silos, and operational friction.

Q: Why can traditional security practices hurt productivity?

Traditional security efforts can hurt productivity when they protect the wrong things or focus primarily on preventing change. The talk argues that companies continue to spend heavily on security while major computer-related attacks still occur, indicating that something is wrong. If controls slow productive work without addressing the systems and assets that matter, spending more does not resolve the underlying problem.

Q: How does unequal staffing contribute to security silos?

Unequal staffing makes collaboration and scalable security difficult. The talk describes an early DevOps pattern of roughly ten developers for every operations person, then extends it to about one security person for every hundred developers. These ratios concentrate responsibilities in small specialist groups, naturally separating them from development work and creating communication, capacity, and ownership gaps across the organization.

Q: What is a complex system in the context of DevSecOps?

A complex system is not merely something complicated. It is a term from applied physics describing systems that are nonlinear, can experience cascading failures, and cannot be fully modeled by humans. The talk identifies the human body, nation-state political interactions, financial markets, weather patterns, and distributed computer systems as examples that share these difficult behavioral characteristics.

Q: Why are mental models insufficient for understanding distributed systems?

Mental models are insufficient because humans cannot completely predict the behavior of a complex system. Distributed systems are nonlinear, can produce cascading failures, and continually become harder to navigate as components are added. According to the talk, understanding such a system requires interacting with it, because observation and reasoning alone cannot represent every relationship or possible behavior within it.

Q: How does chaos engineering relate to cybersecurity?

Chaos engineering relates to cybersecurity by providing a way to interact with complex systems and investigate how they behave under difficult conditions. Aaron Rinehart describes leading work that created the first tool applying Netflix's chaos engineering approach to cybersecurity. This supports a broader security playbook focused on experimentation, complex-system behavior, and system safety within DevSecOps organizations.

Summary & Key Takeaways

  • Security, development, and operations often approach work through different worldviews, creating silos and conflicting priorities. Traditional security practices may inhibit change, protect the wrong things, or reduce productivity. DevSecOps responds by bringing security into the shared practices and responsibilities of modern development and operations teams.

  • DevSecOps is presented as an inevitable response to distributed computing, cloud environments, and unequal staffing. A traditional organization might have one operations person for every ten developers, then only one security person for every hundred developers. Shared responsibility is therefore necessary to make security practices scale with modern systems.

  • Distributed computing environments are complex systems characterized by nonlinear behavior and cascading failures. Humans cannot completely model how such systems will behave, especially as more components are added. Teams must interact with these systems to understand them, using ideas from chaos engineering and system safety to investigate weaknesses and improve resilience.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š