csa colorado 2016 presentation cloudpassage

29
The New Best Practices: Cloud Computing, Hybrid Architecture and Agile IT Delivery Sami Laine Principal Technologist CloudPassage

Upload: trish-mcginity

Post on 23-Jan-2017

36 views

Category:

Technology


2 download

TRANSCRIPT

Page 1: CSA colorado 2016 presentation CloudPassage

TheNewBestPractices:CloudComputing,HybridArchitectureandAgileITDelivery

SamiLainePrincipalTechnologistCloudPassage

Page 2: CSA colorado 2016 presentation CloudPassage

IntroducingCloudPassage

On-demand,automatedsecurityplatformthatworksanywhere,at anyscale

Maturestartup– $91MfundingfromleadingVCs

100+enterprisecustomers

7X growthinprotected workloads inlast2years

Page 3: CSA colorado 2016 presentation CloudPassage

3 |©2016CloudPassageConfidential

Howlongdoyourmosttransientworkloadslive?

Page 4: CSA colorado 2016 presentation CloudPassage

4 |©2016CloudPassageConfidential

Weeks MinutesHours

Page 5: CSA colorado 2016 presentation CloudPassage

TransformationofInfrastructureDelivery

DrivenbybusinessAgility,Speed,Efficiency

Software-definedDC IT-as-a-Service Public,Hybrid&Multicloud

Page 6: CSA colorado 2016 presentation CloudPassage

TransformationofInfrastructureDelivery

Traditional(Mode1) Modern(Mode2)

DataCenter

DataCenter,SDDCorPrivateCloud

Public,HybridorMulti-Cloud

• Datacenter&perimeteroriented• Applicationsondedicatedhardware• Totalownership,visibility&control• Lowrateofchange

• Cloudoriented,degradedperimeter• Sharedresources,distributedworkloads• Sharedownership,lowvisibility&control• Highrateofchange

Page 7: CSA colorado 2016 presentation CloudPassage

7 |©2016CloudPassageConfidential

Howmanymoreserverswillyouhave?

Page 8: CSA colorado 2016 presentation CloudPassage

PerformanceDataSource:Geekbench (PrimateLabs)

AWSEC2c4.largeScore:3,911

36nodes

AzureStandardA3Score:3,594

39nodes

DellPowerEdgeR930Score:141,129

1node

InfrastructureScale

Page 9: CSA colorado 2016 presentation CloudPassage

PerformanceDataSource:Geekbench (PrimateLabs)

AWSEC2c4.largeScore:3,911

36nodes

AzureStandardA3Score:3,594

39nodes

DellPowerEdgeR930Score:141,129

1node

30-40xmoresystemstosecure

InfrastructureScale

Page 10: CSA colorado 2016 presentation CloudPassage

10 |©2016CloudPassageConfidential

Howoftenwillyour

serverschange?

Page 11: CSA colorado 2016 presentation CloudPassage

TransformationofApplicationDelivery

Jan DecFeb Mar Apr May Jun Jul Aug Sep Oct Nov

Q1 Q2 Q3 Q4

Mon Tue Wed Thu Fri Sat Sun

November

Plan Code DeployTest/QA

Waterfall(Mode1) DevOps(Mode2)

• 9-12monthcycletime• Verylargereleasesize• Manualdeployment

• 1-daycycletime• Frequent,smallchanges• Automateddeployment

Page 12: CSA colorado 2016 presentation CloudPassage

TransformationofApplicationDelivery

Source:PuppetLabs2016StateofDevOpsReport

Speed

200x

200xmorefrequent

deployments

Resilience

24x

24xfasterrecoveryfrom

failures

Quality

3x

3xlowerchangefailure

rate

Efficiency

2,555x

2,555xshorterleadtimes

Security

2xlesstimeonsecurityremediation

2x

Page 13: CSA colorado 2016 presentation CloudPassage

Source:PuppetLabs2016StateofDevOpsReport

Speed Resilience Quality Efficiency

200x 24x 3x 2,555x

200xmorefrequent

deployments

24xfasterrecoveryfrom

failures

3xlowerchangefailure

rate

2,555xshorterleadtimes

Security

2xlesstimeonsecurityremediation

2x

TransformationofApplicationDelivery

200xmorefrequentdeployments

Page 14: CSA colorado 2016 presentation CloudPassage

14 |©2016CloudPassageConfidential

Sowhat?

Page 15: CSA colorado 2016 presentation CloudPassage

SpeedandAutomationBreaksTraditionalSecurity

Sorryaboutthat.

DataCenter,SDDCorPrivateCloud

Public,HybridorMulti-Cloud

Page 16: CSA colorado 2016 presentation CloudPassage

SpeedandAutomationBreaksTraditionalSecurity

• Perimeterandnetworkfocused• Heavyfootprintsonsystems• BuiltforstaticIPaddresses• Notdesignedforautomation• LackscomprehensiveAPIs• Reliesondedicatedappliances

Page 17: CSA colorado 2016 presentation CloudPassage

17 |©2016CloudPassageConfidential

AgileITrequires

agilesecurity!

Page 18: CSA colorado 2016 presentation CloudPassage

ReleaseProcess

Plan Code Build Test Release Deploy Operate

Agile Development

Continuous Integration

Continuous Delivery

DevOps

Value

Continuous Deployment

OpsDev

Collaboration

Page 19: CSA colorado 2016 presentation CloudPassage

TraditionalSecurity

Plan Code Build Test Release Deploy Operate

Achtung!Security

Gate!

Page 20: CSA colorado 2016 presentation CloudPassage

Yay! Security Guardrails!

Re-alignSecurityToModernITDelivery

Plan Code Build Test Release Deploy Operate

Page 21: CSA colorado 2016 presentation CloudPassage

Yay! Security Guardrails!

Re-alignSecurityToModernITDelivery

Plan Code Build Test Release Deploy Operate

• Plan– Definesecuritypolicyandbenchmarksforeachtypeofworkload

• Build&Test– Catchvulnerability&configurationissues,generatebaselines• Deploy– Applyproductionpoliciestosystemsautomatically

• Operate– ContinuouslyfeedSecOps andAudit&Compliancesystems

Page 22: CSA colorado 2016 presentation CloudPassage

Re-alignSecurityToModernITDelivery

• On-demand,self-service• Automated,rapidexpansion• Measuredormeteredservice• Ubiquitous,convenientaccess• Resourcepooledgrid• Highlyscalable• Design-patternbased

• On-demand,Security-as-a-Service• Automated,rapidexpansion• Meteredlicensing• Ubiquitous,convenientaccess• Resourcepooledgrid• Highlyscalable• Design-patternbased

AgileITDelivery AgileSecurityDelivery

Page 23: CSA colorado 2016 presentation CloudPassage

23 |©2016CloudPassageConfidential

Whatisthenewroleofsecurity?

Page 24: CSA colorado 2016 presentation CloudPassage

NewRoleofSecurity

vs.

Culture• collaboration

• education

Automation• integrationtotoolchain

• policydevelopment

Measurement• outcomes

• feedback

Page 25: CSA colorado 2016 presentation CloudPassage

The Eight Imperatives for Agile & Scalable Cloud Security

1. Deeply automated & API-driven

2. Ready for orchestration

3. Built into workloads

4. Runs anywhere

5. Context-aware & policy-based

6. Broad set of controls

7. Instant & long-term scalability

8. Aligned with DevOps principles

Page 26: CSA colorado 2016 presentation CloudPassage

26 |©2016CloudPassageConfidential

OK,so…whatdoyouguys

doaboutit?

Page 27: CSA colorado 2016 presentation CloudPassage

CloudPassageHalo

ReduceSoftwareAttackSurface

• Vulnerabilities

• Configuration

• Accounts

MonitorforCompromise

• Integrity

• Intrusion

ReduceNetworkAttackSurface

• Connections

• Firewall

• Authentication

Page 28: CSA colorado 2016 presentation CloudPassage

VMs

Servers

VMs

PublicClouds DataCenters&PrivateClouds

VMs

InfrastructureOrchestration

SOC&GRCSystems

Page 29: CSA colorado 2016 presentation CloudPassage