How to Build a Secure Development Environment

338 views
β€’
February 21, 2017
by
RSAC Cybersecurity
YouTube video player
How to Build a Secure Development Environment

TL;DR

Protect source code by placing development work in a segmented network with strong endpoint controls, restricted internet access, and careful handling of removable media. Rockwell Automation’s experience shows that successful deployment also requires identifying critical assets and high-risk users, securing leadership support, involving business representatives, addressing regional concerns tactfully, and planning the rollout carefully instead of treating it as an informal technical pilot.

Transcript

Good morning. Thank you all for being here eight AM. We really appreciate that. So let's start with why is Rockwell Automation going to all this trouble to build a secure development environment? How many of you have heard about Stuxnet? Okay. That's what we expected. Um, so you know what Stuxnet is, and you know what it did, but how did it get int... Read More

Key Insights

  • Source code is one of Rockwell Automation’s crown jewels, so protecting it from ransomware, theft, and unauthorized transfer is a central purpose of the secure development environment. Concentrating critical development assets inside the environment also helps the company define what deserves its strongest protection.
  • A secure development environment is fundamentally a segmented network that separates development assets from the enterprise network. Rockwell combines this segmentation with strong endpoint controls, restricted internet access, and careful control of removable media used by developers.
  • Phishing can compromise protected operational environments indirectly through trusted engineering organizations. The Stuxnet example shows how attackers entered contractors’ networks and relied on engineering work being transferred by USB drives into an air-gapped customer facility.
  • Enterprise compromise must be treated as an expected event, not merely a remote possibility. Rockwell designed the secure development environment so that a successful phishing attack on its enterprise network would not automatically give attackers access to its most critical development assets.
  • Insider risk programs become more focused when critical assets and privileged users are clearly identified. Rockwell treats information inside the secure development environment as highly critical and considers people with access to that information its highest-risk users for monitoring priorities.
  • Existing secure development practices are necessary but were not sufficient for Rockwell’s risk profile. The company already used penetration testing, static code analysis, security competency development, awareness training, defense-in-depth measures, and leadership support before investing in a separately controlled development environment.
  • Regional security controls can create trust concerns if they appear to single out employees. Rockwell addressed this issue tactfully, and managers at its first selected site viewed the secure environment as a way to demonstrate trustworthiness, obtain better engineering assignments, and create stronger career paths.
  • Careful planning is essential when deploying a secure development environment across global product teams. Rockwell initially tried to avoid formal IT bureaucracy by calling the effort a pilot, while the presentation’s boating analogy emphasized preparation, mechanical readiness, and contingencies instead of simply improvising.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why should a company build a secure development environment?

A company should build a secure development environment to protect source code and other critical development assets from phishing, ransomware, external attackers, and malicious insiders. It can also prevent compromised engineers or products from becoming attack routes into customer environments. For Rockwell Automation, this protection is particularly important because its customers operate factories and other critical infrastructure across large parts of the economy.

Q: What is a secure development environment?

A secure development environment, as described by Rockwell Automation, is fundamentally a segmented network in which developers perform their work. It applies strong controls to developer endpoints, carefully limits the use of removable media, and restricts internet access. Its purpose is to isolate source code and other critical assets so that a compromise of the ordinary enterprise network does not automatically reach development systems.

Q: How does network segmentation protect source code?

Network segmentation places development systems and source code in an environment separated from the broader enterprise network. If phishing or another attack compromises the enterprise, the attacker does not automatically gain access to the protected development assets. Rockwell treats the contents of this segmented environment as crown jewels and supplements the separation with endpoint, internet, and removable-media controls.

Q: Why are removable media controls important for developers?

Removable media can carry malicious software from a compromised engineering network into a protected or air-gapped customer environment. In the Stuxnet example discussed, attackers targeted engineering contractors and waited for engineering work to be placed on USB drives and taken to the customer. Controlling removable media therefore helps protect both the developer’s organization and customers receiving engineering work or products.

Q: How does a secure development environment reduce insider risk?

A secure development environment makes insider-risk priorities clearer by defining which assets are most critical and which users have access to them. Rockwell concluded that anything inside its environment should receive crown-jewel protection, while anyone authorized to access that information should be treated as a highest-risk user. This focus helps a formal insider-risk program concentrate attention where potential damage is greatest.

Q: What security practices should support a secure development environment?

Rockwell’s secure development environment builds upon an existing defense-in-depth program rather than replacing it. Supporting practices include penetration testing, static code analysis, security competency development, security awareness training, and leadership commitment. The segmented environment adds stronger isolation and access controls after those foundational measures are already operating, providing another layer of protection for valuable development assets.

Q: How can companies introduce stronger controls in higher-risk locations?

Companies can explain the business and security reasons for stronger controls tactfully while recognizing that regional risk classifications may affect employee trust. Rockwell’s first selected site actively welcomed the secure environment because its managers believed it could demonstrate that their capable engineers were trustworthy. They expected that increased confidence could bring better assignments and create career opportunities that were previously limited by regional distrust.

Q: What organizational roles help a secure development environment succeed?

A secure development environment benefits from cooperation between cybersecurity leadership and business representatives. At Rockwell, the CISO brought cybersecurity and insider-risk expertise, while a business unit liaison represented operational concerns and debated controls that would affect developers. The liaison also explained and justified security requirements to development teams, using business credibility to support adoption when stronger measures needed to be implemented.

Summary & Key Takeaways

  • Rockwell Automation created a secure development environment because compromised engineers, phishing attacks, ransomware, and malicious insiders can expose source code or provide a route into customer systems. Its industrial automation customers operate factories and critical infrastructure, making protection of development assets important to both the company and the organizations using its products.

  • The secure development environment is fundamentally a segmented network for developers. It combines strong endpoint controls with tight restrictions on removable media and internet access. Rockwell positioned this environment as an additional investment beyond existing measures such as penetration testing, static code analysis, security training, competency development, and leadership engagement.

  • The initial rollout targeted a higher-risk location, but local managers welcomed becoming the first site. They believed stronger controls could increase trust in their engineers and lead to better assignments and career opportunities. Rockwell then began the effort as a pilot, later emphasizing that complex security projects require deliberate preparation, contingencies, and organizational coordination.


Read in Other Languages (beta)

Share This Summary πŸ“š

Explore More Summaries from RSAC Cybersecurity πŸ“š