Henry Been on Security with DevOps - Episode 012

Henry Been on Security with DevOps - Episode 012

In this episode, Jeffrey is discussing security in DevOps with his guest, Henry Been. Henry is an independent DevOps and Azure architect from the Netherlands. He enjoys working with development teams to create and deliver great software — and for him, this includes the full DevOps cycle; starting with discovering and planning new features and ending only when end users are satisfied. Henry's interests include the Azure cloud, Agile, DevOps, software architecture and the design and implementation of testable and maintainable software. Next to his work, Henry is one of the Microsoft ALM DevOps Rangers — which is a group of 130 engineers worldwide who share professional guidance and create gap-filling solutions surrounding Azure.

Henry and Jeffrey discuss, in-depth, everything you want to know when it comes to security with DevOps. Henry offers advice on how to implement security into your DevOps practice, makes recommendations on how to be more secure at each stage of the software development application lifecycle, highlights possible vulnerabilities that you might want to watch out for, and offers tools you can utilize to combat this and up your security in your DevOps environment.

Topics of Discussion:

[:40] About today's episode and featured guest expert.

[1:35] Jeffrey welcomes Henry to the podcast.

[1:41] What Henry has been up to of late.

[2:21] How Henry has found himself in the DevOps space.

[3:08] Henry shares some information about the ALM DevOps Rangers he is a part of.

[4:16] About the half-marathon Henry recently finished!

[5:50] How did the term DevSecOps come about? And what do people need to know about it?

[7:22] Henry offers advice on how to implement security into your DevOps practice.

[8:26] Henry's recommendations for being more secure at each stage of the software development application lifecycle.

[12:47] The vulnerabilities of copying your database offsite.

[13:44] Is keeping your database offline more secure than having it online?

[14:04] A word from Azure DevOps sponsor: Clear Measure.

[14:29] Henry outlines ways to limit the surface area of personal access to environments.

[16:29] A vulnerability in the FCKeditor WYSIWYG HTML editor and how to avoid it.

[17:53] Henry and Jeffrey's take on why many are fearful of a scheduled, automated deployment or redeployment.

[20:45] The work Henry has done with Azure Policy and how can help.

[24:04] One of the most vulnerable attack surfaces: any area that a human's account has access to.

[24:41] What's on the roadmap for Henry!

[26:32] How to keep up with Henry and everything he's doing.

[27:02] Henry's recommendations to those who want to learn more about security in their DevOps environment.

Mentioned in this Episode:

Azure DevOps

Azure DevOps User Group on Meetup

Microsoft ALM DevOps Rangers

DevSecOps

SQL Clone from Redgate

Redgate

Clear Measure (Sponsor)

Infrastructure as code

FCKeditor WYSIWYG HTML

Azure Policy

Henry's Blog (HenryBeen.nl)

Henry's Twitter @Henry_Been

Want to Learn More?

Visit AzureDevOps.Show for show notes and additional episodes.

Follow Up with Our Guest:

Henry Been's LinkedIn

Henry's Blog

Henry's Twitter

Jaksot(386)

Kyle Nunery on Azure DevOps in the Real World - Episode 42

Kyle Nunery on Azure DevOps in the Real World - Episode 42

Today's guest is Kyle Nunery, a Principal Software Architect at Clear Measure as well as the business owner of Burnout Studios (where he has developed mobile games for the iOS platform and created art...

25 Kesä 201927min

Eric Fleming on Middle-of-the-Day Deployments - Episode 41

Eric Fleming on Middle-of-the-Day Deployments - Episode 41

Today's episode is all about recognizing middle-of-the-day deployments; how teams such as Netflix, Facebook, and even the Azure DevOps Product Team are doing them; and taking a look at how other teams...

17 Kesä 201943min

Dr. Neil Roodyn on the Social Impact of Technology - Episode 40

Dr. Neil Roodyn on the Social Impact of Technology - Episode 40

Today's guest is Dr. Neil Roodyn — an entrepreneur, founder, consultant, trainer, and author! Neil travels the world, working with technology companies and helps software development teams become more...

10 Kesä 201939min

Atley Hunter on the Business of App Development - Episode 39

Atley Hunter on the Business of App Development - Episode 39

Jeffrey Palermo's guest today is none other than Atley Hunter! Atley has been a developer for more than 20 years and has developed over 1200 publically released apps across many Microsoft platforms. I...

3 Kesä 201937min

Greg Duncan on Putting the Ops in DevOps - Episode 38

Greg Duncan on Putting the Ops in DevOps - Episode 38

On today's episode, Greg Duncan is joining the podcast! Greg has been developing eDiscovery software applications since his days at the now-defunct, Arthur Andersen. And he continued to develop eDisco...

27 Touko 201940min

Mark Miller on Developer Productivity - Episode 37

Mark Miller on Developer Productivity - Episode 37

Today's guest is Mark Miller, a five-year C# MVP alumnus with strong expertise in decoupled design, plug-in architectures, and great user interfaces. He is the Chief Architect of the IDE Tools divisio...

20 Touko 201947min

Jeff Fritz on .Net Core 3 and Blazor - Episode 36

Jeff Fritz on .Net Core 3 and Blazor - Episode 36

Joining Jeffrey Palermo today is Jeff Fritz! Jeff is the Senior Program Manager in Microsoft's Developer Division working on the .Net Community Team. He's a long-time web developer and survivor of the...

13 Touko 201940min

Jeffrey Palermo on .NET DevOps for Azure - Episode 35

Jeffrey Palermo on .NET DevOps for Azure - Episode 35

This week is a special solo-edition episode with your host, Jeffrey Palermo! Recently, Jeffrey published his fourth book, .NET DevOps for Azure, on April 26th, 2019. This book has been a long-time com...

6 Touko 201929min

Suosittua kategoriassa Politiikka ja uutiset

aikalisa
rss-ootsa-kuullut-tasta
tervo-halme
ootsa-kuullut-tasta-2
politiikan-puskaradio
rss-vaalirankkurit-podcast
viisupodi
rss-podme-livebox
otetaan-yhdet
et-sa-noin-voi-sanoo-esittaa
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
rss-asiastudio
the-ulkopolitist
mtv-uutiset-polloraati
rss-kaikki-uusiksi
rss-hyvaa-huomenta-bryssel
rss-merja-mahkan-rahat
rss-kuka-mina-olen
rss-raha-talous-ja-politiikka
rss-sanna-ukkola-show-verkkouutiset