2015 06-12 devopsdc 2015 - consumer to collaborator

41
Consumer to Collaborator Re-Imagining the Government’s role in Open Source

Upload: shawn-wells

Post on 21-Feb-2017

12 views

Category:

Software


1 download

TRANSCRIPT

Page 1: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Consumer to Collaborator

Re-Imagining the Government’s rolein Open Source

Page 2: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

EXPLAIN YOUR FISMA PROCESS

Page 3: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 4: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

OR, EMBED INTO KICKSTART:

$ oscap xccdf eval \--remediate \--profile stig-rhel6-server-upstream \--report /root/scan-report.html \/usr/share/xml/scap/content.xml

Page 5: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 6: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 7: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 8: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 9: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 10: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Miracle at Willow Run

Page 11: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 12: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 13: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

FIRST USE OF CONTAINERS?

Page 14: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Mode 1 Mode 2

Page 15: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Mode 1 Mode 2

TRADITIONAL

Page 16: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Mode 1 Mode 2

TRADITIONAL EXPLORATORY

Page 17: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

YOU ARE NOT ANIT CRAFTSMAN

YOU ARE ABI-MODAL IT

MANUFACTURER

Page 18: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 19: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

Page 20: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

SELECT CONTROLS(FIPS 200 / SP 800-53)

Page 21: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

SELECT CONTROLS(FIPS 200 / SP 800-53)

IMPLEMENT CONTROLS(SP 800-70)

Page 22: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

SELECT CONTROLS(FIPS 200 / SP 800-53)

IMPLEMENT CONTROLS(SP 800-70)

ACCESS CONTROLS(SP 800-53A)

Page 23: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

SELECT CONTROLS(FIPS 200 / SP 800-53)

IMPLEMENT CONTROLS(SP 800-70)

ACCESS CONTROLS(SP 800-53A)

AUTHORIZE(SP 800-37)

Page 24: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

CATEGORIZE(FIPS 199 / SP 800-60)

SELECT CONTROLS(FIPS 200 / SP 800-53)

IMPLEMENT CONTROLS(SP 800-70)

ACCESS CONTROLS(SP 800-53A)

MONITOR(SP 800-37 / SP 800-53A)

AUTHORIZE(SP 800-37)

Page 25: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

… and DevOps g

oes...

Page 26: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 27: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Everyone knows thatSCAP is a suite of XML standards for creating automated checklists for configuration and vulnerability scans!

Page 28: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 29: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Features

Risk?

Risk?

Risk?

Units of ___________

Growth

Page 30: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Community created portfolioof tools and content to make

attestations about known vulnerabilities

https://github.com/OpenSCAP

Page 31: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 32: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 33: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 34: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 35: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 36: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 37: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

$ govready scan

Page 38: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 39: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator
Page 40: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

HOW TO ENGAGEOpenSCAP GitHub:https://github.com/OpenSCAP

OpenSCAP References & Docs:https://github.com/OpenSCAP/scap-security-guide/wiki/Collateral-and-References

SCAP Content Mailing List:https://fedorahosted.org/mailman/listinfo/scap-security-guide

GovReady user-friendly front-end:https://github.com/GovReady/govready

Ansible-SCAP (+ Vagrant) demo. See how it all works - painlessly:https://github.com/openprivacy/ansible-scap

NIST SCAP Website:https://scap.nist.gov

Page 41: 2015 06-12 DevOpsDC 2015 - Consumer to Collaborator

Shawn [email protected]

443-534-0130

CONTACT INFO

Greg [email protected]

m917-304-3488

Fen [email protected]

om412-996-4113