Artwork

Indhold leveret af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

Modeling DevSecOps to Reduce the Time-to-Deploy and Increase Resiliency

59:45
 
Del
 

Manage episode 287128865 series 1264075
Indhold leveret af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Many organizations struggle in applying DevSecOps practices and principles in a cybersecurity-constrained environment because programs lack a consistent basis for managing software intensive development, cybersecurity, and operations in a high-speed lifecycle. We will discuss how an authoritative reference, or Platform Independent Model (PIM), is needed to fully design and execute an integrated DevSecOps strategy in which all stakeholder needs are addressed, such as engineering security into all aspects of the DevSecOps pipeline to include both the pipeline and the deployed system.

We will discuss how a PIM of a DevSecOps system can be used to 1) Specify the DevSecOps requirements to the lead system integrators who need to develop a platform-specific solution that includes the system and CI/CD pipeline.

2) Assess and analyze alternative pipeline functionality and feature changes as the system evolves.

3) Apply DevSecOps methods to complex systems that do not follow well-established software architectural patterns used in industry.

4) Provide a basis for threat and attack surface analysis to build a cyber assurance case in order to demonstrate that the software system and DevSecOps pipeline are sufficiently free from vulnerabilities and function only as intended

  continue reading

174 episoder

Artwork
iconDel
 
Manage episode 287128865 series 1264075
Indhold leveret af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Carnegie Mellon University Software Engineering Institute and SEI Members of Technical Staff eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Many organizations struggle in applying DevSecOps practices and principles in a cybersecurity-constrained environment because programs lack a consistent basis for managing software intensive development, cybersecurity, and operations in a high-speed lifecycle. We will discuss how an authoritative reference, or Platform Independent Model (PIM), is needed to fully design and execute an integrated DevSecOps strategy in which all stakeholder needs are addressed, such as engineering security into all aspects of the DevSecOps pipeline to include both the pipeline and the deployed system.

We will discuss how a PIM of a DevSecOps system can be used to 1) Specify the DevSecOps requirements to the lead system integrators who need to develop a platform-specific solution that includes the system and CI/CD pipeline.

2) Assess and analyze alternative pipeline functionality and feature changes as the system evolves.

3) Apply DevSecOps methods to complex systems that do not follow well-established software architectural patterns used in industry.

4) Provide a basis for threat and attack surface analysis to build a cyber assurance case in order to demonstrate that the software system and DevSecOps pipeline are sufficiently free from vulnerabilities and function only as intended

  continue reading

174 episoder

Alle episoder

×
 
Loading …

Velkommen til Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Hurtig referencevejledning

Lyt til dette show, mens du udforsker
Afspil