Henry Been on Security with DevOps - Episode 012

Henry Been on Security with DevOps - Episode 012

In this episode, Jeffrey is discussing security in DevOps with his guest, Henry Been. Henry is an independent DevOps and Azure architect from the Netherlands. He enjoys working with development teams to create and deliver great software — and for him, this includes the full DevOps cycle; starting with discovering and planning new features and ending only when end users are satisfied. Henry's interests include the Azure cloud, Agile, DevOps, software architecture and the design and implementation of testable and maintainable software. Next to his work, Henry is one of the Microsoft ALM DevOps Rangers — which is a group of 130 engineers worldwide who share professional guidance and create gap-filling solutions surrounding Azure.

Henry and Jeffrey discuss, in-depth, everything you want to know when it comes to security with DevOps. Henry offers advice on how to implement security into your DevOps practice, makes recommendations on how to be more secure at each stage of the software development application lifecycle, highlights possible vulnerabilities that you might want to watch out for, and offers tools you can utilize to combat this and up your security in your DevOps environment.

Topics of Discussion:

[:40] About today's episode and featured guest expert.

[1:35] Jeffrey welcomes Henry to the podcast.

[1:41] What Henry has been up to of late.

[2:21] How Henry has found himself in the DevOps space.

[3:08] Henry shares some information about the ALM DevOps Rangers he is a part of.

[4:16] About the half-marathon Henry recently finished!

[5:50] How did the term DevSecOps come about? And what do people need to know about it?

[7:22] Henry offers advice on how to implement security into your DevOps practice.

[8:26] Henry's recommendations for being more secure at each stage of the software development application lifecycle.

[12:47] The vulnerabilities of copying your database offsite.

[13:44] Is keeping your database offline more secure than having it online?

[14:04] A word from Azure DevOps sponsor: Clear Measure.

[14:29] Henry outlines ways to limit the surface area of personal access to environments.

[16:29] A vulnerability in the FCKeditor WYSIWYG HTML editor and how to avoid it.

[17:53] Henry and Jeffrey's take on why many are fearful of a scheduled, automated deployment or redeployment.

[20:45] The work Henry has done with Azure Policy and how can help.

[24:04] One of the most vulnerable attack surfaces: any area that a human's account has access to.

[24:41] What's on the roadmap for Henry!

[26:32] How to keep up with Henry and everything he's doing.

[27:02] Henry's recommendations to those who want to learn more about security in their DevOps environment.

Mentioned in this Episode:

Azure DevOps

Azure DevOps User Group on Meetup

Microsoft ALM DevOps Rangers

DevSecOps

SQL Clone from Redgate

Redgate

Clear Measure (Sponsor)

Infrastructure as code

FCKeditor WYSIWYG HTML

Azure Policy

Henry's Blog (HenryBeen.nl)

Henry's Twitter @Henry_Been

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Follow Up with Our Guest:

Henry Been's LinkedIn

Henry's Blog

Henry's Twitter

Jaksot(393)

Craig Loewen on the Windows Subsystem for Linux DevOps Story - Episode 57

Craig Loewen on the Windows Subsystem for Linux DevOps Story - Episode 57

On this week's episode, Jeffrey is joined by Craig Loewen to discuss the Windows Subsystem for Linux! Craig is a Program Manager on the Windows Subsystem for Linux team. He started his journey in Univ...

7 Loka 201932min

Oren Eini on DevOps Success at RavenDB (Part 2) - Episode 56

Oren Eini on DevOps Success at RavenDB (Part 2) - Episode 56

This is the second part to the two-episode series with Oren Eini! If you haven't listened to the first part already be sure to tune into that one first! Oren Eini, pseudonym Ayende Rahien, is a freq...

30 Syys 201941min

Oren Eini on DevOps Success at RavenDB (Part 1) - Episode 55

Oren Eini on DevOps Success at RavenDB (Part 1) - Episode 55

Today's guest is Oren Eini, pseudonym Ayende Rahien. Oren is a frequent blogger at Ayende.com and has over 20 years of experience in the development world, with strong focuses on the Microsoft and .NE...

23 Syys 201936min

Kayla Cinnamon and Rich Turner on DevOps on the Windows Terminal Team - Episode 54

Kayla Cinnamon and Rich Turner on DevOps on the Windows Terminal Team - Episode 54

On this week's podcast, Kayla Cinnamon and Rich Turner are joining the show! Kayla is a Program Manager on the Windows Terminal Team and has been working for Microsoft for the last 8 years, and Rich i...

16 Syys 201956min

Jared Parsons on DevOps on the C# Compiler Team - Episode 53

Jared Parsons on DevOps on the C# Compiler Team - Episode 53

Today, your host, Jeffrey Palermo is speaking with Jared Parsons, the Principal Developer Lead on the C# Compiler Team. Everybody tuning in probably uses his code on a day-to-day basis! Jared started ...

9 Syys 201935min

Patrick Smacchia on Static Code Analysis - Episode 52

Patrick Smacchia on Static Code Analysis - Episode 52

Patrick Smacchia is the founder and CEO of NDepend — a tool for .NET static analysis — and has been in the software world for over 20 years. He's one of the world's top tier experts in static code ana...

2 Syys 201940min

James Avery on Scaling to 3 Billion Requests Per Day - Episode 51

James Avery on Scaling to 3 Billion Requests Per Day - Episode 51

James Avery is the founder and CEO of Adzerk. Adzerk is the next generation of publisher ad serving. It's built to be faster, easier to use, and comprehensive than anything on the market today. Adzerk...

26 Elo 201937min

Richard Lander on .NET Core Runtime - Episode 50

Richard Lander on .NET Core Runtime - Episode 50

Today's guest, Richard Lander, is a Principal Program Manager on the .NET Core Team at Microsoft. He's been with Microsoft for a total of 19 years, 16 of which have been with the .NET team. Richard is...

19 Elo 201955min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
ootsa-kuullut-tasta-2
politiikan-puskaradio
rss-ootsa-kuullut-tasta
tervo-halme
rss-vaalirankkurit-podcast
viisupodi
et-sa-noin-voi-sanoo-esittaa
rss-podme-livebox
rss-asiastudio
otetaan-yhdet
rss-girls-finish-f1rst
rikosmyytit
the-ulkopolitist
rss-raha-talous-ja-politiikka
rss-kaikki-uusiksi
rss-polikulaari-pitka-kiekko-ja-muut-ts-podcastit
rss-vain-talouselamaa
rss-tekkipodi