Tackling RMF W/Devsecops: Jennifer Rekas March 2019
Tackling RMF W/Devsecops: Jennifer Rekas March 2019
Tackling RMF W/Devsecops: Jennifer Rekas March 2019
w/DevSecOps
Jennifer Rekas
jrekas@mitre.org
March 2019
The author's affiliation with The MITRE Corporation is provided for identification purposes only, and is
not intended to convey or imply MITRE's concurrence with, or support for, the positions, opinions, or
viewpoints expressed by the author. ©2019 The MITRE Corporation. ALL RIGHTS RESERVED.
Approved for Public Release; Distribution Unlimited. Public Release Case Number 19-0841
Agenda
Enabled by
Automation
Culture / Mindset Technology
Development, Security, and and
Operations are one team
Processes
Image sources: https://www.peakgrantmaking.org/blog/process-automation-new-black/
https://martinfowler.com/bliki/DevOpsCulture.html
What Is the “Enabling”?
How Can We Use Automation Output to Meet the Requirements? How can we
maximize inheritance of controls?
Tailored security rigor and body of evidence requirements based on risk level
• Basic Criteria:
• Leverage the provided PaaS Microservice Architecture
• Build and deliver using the provided enterprise DevSecOps
Pipeline
• Utilize APIs only for data calls
Security
inspec ZAP
+ + + + + + +
16