275x Filetype PPTX File size 2.21 MB Source: www.releaseteam.com
Previous Landscape and
Opportunities
• Continual requests from all business units for more work to be done,
with fewer resources and budget.
• Legislation around elections and business passed which our office
does not control.
• Requests coming to IT from all directions including e-mail, phone calls,
hallway conversations, counties, and other sources with little ability
for our teams to control the work in process and prioritization.
• Multiple ticketing systems, spreadsheets, and manual processes in
place to track work. E-mail was a significant method to track and
facilitate work.
• Various groups contending for IT resources with no clear view of
impact.
Pressure…what
pressure?
Remote Work Dependencies on State Pandemics
Culture New Legislation Friends
Technology Old Legislation Family
Budget Admin Changes Finances
Procurement Cyber Attacks Always remember Health
System Crashes to care about Culture
Hiring people first!
Media Social Media
Politics Workload
Assumptions Expectations
We all have multiple hats to
wear to meet the demands of
our jobs. If you look at the
typical job posting out there
today, we all must know
everything about everything.
• Linux & Windows Systems Engineer
• Software Defined Networking
• Virtualization
• Python, Java, .NET Programmer
• Cloud Architect
• Master Chef….
So, how can we succeed?
“Operations teams may know Leaning in over Always Saying “No”
development as “the people who Data & Security Science over Fear, Uncertainty and Doubt
always break things.” At the same
time, it can be scary for Open Contribution & Collaboration over Security-Only
development to involve operations Requirements
in the development process because
they may know operations as “the Consumable Security Services with APIs over Mandated
team that always says ‘No.’” Security Controls & Paperwork
“Successfully merging the priorities Business Driven Security Scores over Rubber Stamp Security
and goals of development and
operations teams to create one Red & Blue Team Exploit Testing over Relying on Scans &
cohesive DevOps effort can fail due Theoretical Vulnerabilities
to cultural misunderstandings and,
oftentimes, a fundamental lack of 24x7 Proactive Security Monitoring Over-Reacting After Being
https://devops.com/strategies-to-build-trust-in-devops/ Informed of an Incident
trust.”
Shared Threat Intelligence over Keeping Info to Ourselves
Trust is a continual Compliance Operations over Clipboards & Checklists
process that takes time.
https://www.devsecops.org/
Define the Problem as a Team
• Worked with our Business, Elections, Administration, and Information
Systems teams to determine where our agency could improve.
• Everyone was involved and had input.
• Staff from every division even attended DevSecOps training onsite. It was
critical to have everyone's buy-in.
• We felt it was critical to have the business units on board to have success.
• We found three areas that needed improvement in the organization's
relationship with IT. We also realized our organization was IT.
no reviews yet
Please Login to review.