DevSecOps: What, Why and How?
Black Hat USA
Las Vegas, NV, USA
Abstract
Security is often added towards the end, in a typical DevOps cycle. This talk covers how to integrate security into each phase of DevOps — from code commit to deployment — using freely available open-source tools.
We walk through a practical pipeline that includes SAST, DAST, dependency scanning, container security, and infrastructure-as-code auditing, all orchestrated via CI/CD. The goal: make security a first-class citizen in every sprint, not an afterthought bolted on at release time.
Video
Conference Recording
Resources
Social chatter
Twitter/X
@anantshri talking about #DevSecOps @BlackHatEvents pic.twitter.com/UySZf1cH3p
— Vandana Verma (@InfosecVandana) August 8, 2019







