Overview
Syllabus
Exit Stage Left: Replacing Theater with Chaos Kelly Shortridge, Capsules
Act 1: Welcome to Security Theater
Security Theater optimizes for drama
Cumbersome change management will hinder speedy patch deployments, too
How do we spot Security Theater's red flags? And is there a better way ahead?
Act II: Theater & Chaos in Fisticuffs
Security Chaos Engineering: Let's harness failure to build knowledge
SCE: Failure is a natural part of systems ST: Bad humans cause failures
SCE: Adapt to minimize incident impact ST: Prevent failure from happening
SCE: Security is collaborative & open ST: Security teams operate in a silo
SCE Culture: Learning & experimenting ST Culture: Fear and mistrust
Act II, Scene II: Judgment
Security Theatre shuns fair judgment
Compare security code review coverage vs. lead time or deploy frequency
The Grande Finale
Security Theater prioritizes gatekeeping more than security outcomes
Strive for continuous improvement through Security Chaos Engineering
Attackers behaviors constantly evolve. Defender behaviors must evolve, too.
Treat security teams as advisors & hold P&E teams accountable for changes
Taught by
CNCF [Cloud Native Computing Foundation]