{"id":39783,"date":"2019-10-15T10:28:28","date_gmt":"2019-10-15T10:28:28","guid":{"rendered":"https:\/\/www.cloudcomputing-news.net\/news\/2019\/oct\/15\/moving-devops-modern-ops-why-there-no-room-silos-when-it-comes-cloud-security\/"},"modified":"2019-10-15T10:28:28","modified_gmt":"2019-10-15T10:28:28","slug":"moving-from-devops-to-modern-ops-why-there-is-no-room-for-silos-when-it-comes-to-cloud-security","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/moving-from-devops-to-modern-ops-why-there-is-no-room-for-silos-when-it-comes-to-cloud-security\/","title":{"rendered":"Moving from DevOps to modern ops: Why there is no room for silos when it comes to cloud security"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.cloudcomputing-news.net\/media\/img\/news\/silos-towers-picture-id516261852.jpg\"><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">It started with DevOps. Then there was NetOps. Now SecOps. Or is it DevSecOps? Or maybe SecDevOps?<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Whatever you decide to call it, too often the end result is little more than the same old siloes with shiny new names. We&#39;ve become so focused on &quot;what do we call these folks&quot; that we sometimes forget &quot;what is it we&#39;re trying to accomplish&quot;.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Shakespeare said that a rose would smell as sweet by any other name. Let&#39;s apply that today to the number of factions rising in the operations game. Changing your name does nothing if you don&#39;t change your core behaviours and practices.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Back when cloud first rose &#8211; pun intended &#8211; there were plenty of pundits who dismissed enterprise efforts to build private (on-premises) cloud. Because it didn&#39;t fit the precise definition they wanted to associate with cloud. They ignored that the&nbsp;<em>outcome&nbsp;<\/em>was the measure of success, not measuring up to someone else&#39;s pedantic definition. They sought agility and efficiency and speed by changing the way infrastructure was provisioned, configured, and managed. They changed&nbsp;<em>behaviours&nbsp;<\/em>and <em>practices&nbsp;<\/em>through the use of technology.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Today the terminology wars are focused on X-Ops and what we should call the latest arrival, security.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">I know I&#39;ve used the terms, and sometimes I use them all at the same time. But perhaps what we need is&nbsp;<em>fewer<\/em>&nbsp;distinctions. Perhaps I should just say you&#39;re either adopting &quot;modern ops&quot; in terms of behaviours and practices or you&#39;re remaining &quot;traditional ops&quot; and that&#39;s all there is to it.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Modern ops&nbsp;employ technology like cloud and automation to build pipelines that codify processes to speed delivery and deployment of applications.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">And they do it by changing behaviours and practices. They are collaborative and communicative. They use technology to modernise and optimise decades old processes that are impeding delivery and deployment. They work together, not in siloed X-Ops teams, to achieve their goal of faster, more frequent releases that deliver value to the business and delight consumers.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Focusing on what to call &quot;security&quot; as they get onboard with modern ops can be detrimental to the basic premise that delivery and deployment can only succeed at speed with a collaborative approach. Slapping new labels on a new focused team just builds differenter siloes; it doesn&#39;t smash them and open up the lines of communication that are required to operate at speed and scale.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">It also unintentionally gives permission to other, non-security ops to abdicate security responsibilities to the &lt;SecDevOps | DevSecOps&gt; team. Because it&#39;s in their name, right?<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">That&#39;s an increasingly bad idea given that application security is a stack and thus requires a full stack to implement the right protections.&nbsp; You need network security and transport security and you definitely need application security. The attack surface for an app includes all seven layers and, increasingly, the stack comprising its operational environment. There is no room for silos when it comes to security.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">The focus of IT as its moving through its digital transformation should be to modernise ops &#8211; from the technology to the teams that use it to innovate and deliver value to the business. Modern ops are not consumed by concern for titles, they are passionate about producing results. Modern ops work together, communicate freely, and collaborate across concerns to build out an efficient, adaptive delivery and deployment pipeline.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">That will take network, security, infrastructure, storage, and development expertise working together.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">In the network, we use labels to tag traffic and apply policies that control what devices can talk to which infrastructure and applications. In container clusters we use labels to isolate and restrict, to constrain and to disallow.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">Labels in organisations can have the same affect.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><span style=\"background-color:white\"><span style=\"color:#343434\">So maybe it would be better if we just said you are either modern ops or traditional ops. And that some are in a transitional state between the two. Let&#39;s stop spending so many cycles on what to call each other that we miss the opportunity to create a collaborative environment in which to deliver and deploy apps faster, more frequently, and most of all, securely.<\/span><\/span><\/p>\n<p style=\"margin-left:0cm; margin-right:0cm\"><a href=\"https:\/\/www.cybersecuritycloudexpo.com\/\" style=\"color:#0563c1; text-decoration:underline\"><span style=\"color:blue\"><img decoding=\"async\" alt=\"https:\/\/www.cybersecuritycloudexpo.com\/wp-content\/uploads\/2018\/09\/cyber-security-world-series-1.png\" src=\"https:\/\/www.cybersecuritycloudexpo.com\/wp-content\/uploads\/2018\/09\/cyber-security-world-series-1.png\" style=\"height:59px; width:272px\" \/><\/span><\/a><strong>Interested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases<\/strong>? Attend the <a href=\"https:\/\/www.cybersecuritycloudexpo.com\/\" style=\"color:#0563c1; text-decoration:underline\">Cyber Security &amp; Cloud Expo World Series<\/a> with upcoming events in Silicon Valley, London and Amsterdam to learn more.<\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/www.cloudcomputing-news.net\/media\/img\/news\/silos-towers-picture-id516261852.jpg\"><\/p>\n<p><span><span>It started with DevOps. Then there was NetOps. Now SecOps. Or is it DevSecOps? Or maybe SecDevOps?<\/span><\/span><\/p>\n<p><span><span>Whatever you decide to call it, too often the end result is little more than the same old siloes with shiny new names. We&#8217;ve become so focused on &#8220;what do we call these folks&#8221; that we sometimes forget &#8220;what is it we&#8217;re trying to accomplish&#8221;.<\/span><\/span><\/p>\n<p><span><span>Shakespeare said that a rose would smell as sweet by any other name. Let&#8217;s apply that today to the number of factions rising in the operations game. Changing your name does nothing if you don&#8217;t change your core behaviours and practices.<\/span><\/span><\/p>\n<p><span><span>Back when cloud first rose &#8211; pun intended &#8211; there were plenty of pundits who dismissed enterprise efforts to build private (on-premises) cloud. Because it didn&#8217;t fit the precise definition they wanted to associate with cloud. They ignored that the&nbsp;<em>outcome&nbsp;<\/em>was the measure of success, not measuring up to someone else&#8217;s pedantic definition. They sought agility and efficiency and speed by changing the way infrastructure was provisioned, configured, and managed. They changed&nbsp;<em>behaviours&nbsp;<\/em>and <em>practices&nbsp;<\/em>through the use of technology.<\/span><\/span><\/p>\n<p><span><span>Today the terminology wars are focused on X-Ops and what we should call the latest arrival, security.<\/span><\/span><\/p>\n<p><span><span>I know I&#8217;ve used the terms, and sometimes I use them all at the same time. But perhaps what we need is&nbsp;<em>fewer<\/em>&nbsp;distinctions. Perhaps I should just say you&#8217;re either adopting &#8220;modern ops&#8221; in terms of behaviours and practices or you&#8217;re remaining &#8220;traditional ops&#8221; and that&#8217;s all there is to it.<\/span><\/span><\/p>\n<p><span><span>Modern ops&nbsp;employ technology like cloud and automation to build pipelines that codify processes to speed delivery and deployment of applications.<\/span><\/span><\/p>\n<p><span><span>And they do it by changing behaviours and practices. They are collaborative and communicative. They use technology to modernise and optimise decades old processes that are impeding delivery and deployment. They work together, not in siloed X-Ops teams, to achieve their goal of faster, more frequent releases that deliver value to the business and delight consumers.<\/span><\/span><\/p>\n<p><span><span>Focusing on what to call &#8220;security&#8221; as they get onboard with modern ops can be detrimental to the basic premise that delivery and deployment can only succeed at speed with a collaborative approach. Slapping new labels on a new focused team just builds differenter siloes; it doesn&#8217;t smash them and open up the lines of communication that are required to operate at speed and scale.<\/span><\/span><\/p>\n<p><span><span>It also unintentionally gives permission to other, non-security ops to abdicate security responsibilities to the &lt;SecDevOps | DevSecOps&gt; team. Because it&#8217;s in their name, right?<\/span><\/span><\/p>\n<p><span><span>That&#8217;s an increasingly bad idea given that application security is a stack and thus requires a full stack to implement the right protections.&nbsp; You need network security and transport security and you definitely need application security. The attack surface for an app includes all seven layers and, increasingly, the stack comprising its operational environment. There is no room for silos when it comes to security.<\/span><\/span><\/p>\n<p><span><span>The focus of IT as its moving through its digital transformation should be to modernise ops &#8211; from the technology to the teams that use it to innovate and deliver value to the business. Modern ops are not consumed by concern for titles, they are passionate about producing results. Modern ops work together, communicate freely, and collaborate across concerns to build out an efficient, adaptive delivery and deployment pipeline.<\/span><\/span><\/p>\n<p><span><span>That will take network, security, infrastructure, storage, and development expertise working together.<\/span><\/span><\/p>\n<p><span><span>In the network, we use labels to tag traffic and apply policies that control what devices can talk to which infrastructure and applications. In container clusters we use labels to isolate and restrict, to constrain and to disallow.<\/span><\/span><\/p>\n<p><span><span>Labels in organisations can have the same affect.<\/span><\/span><\/p>\n<p><span><span>So maybe it would be better if we just said you are either modern ops or traditional ops. And that some are in a transitional state between the two. Let&#8217;s stop spending so many cycles on what to call each other that we miss the opportunity to create a collaborative environment in which to deliver and deploy apps faster, more frequently, and most of all, securely.<\/span><\/span><\/p>\n<p><a href=\"https:\/\/www.cybersecuritycloudexpo.com\/\"><span><img decoding=\"async\" alt=\"https:\/\/www.cybersecuritycloudexpo.com\/wp-content\/uploads\/2018\/09\/cyber-security-world-series-1.png\" src=\"https:\/\/www.cybersecuritycloudexpo.com\/wp-content\/uploads\/2018\/09\/cyber-security-world-series-1.png\"><\/span><\/a><strong>Interested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases<\/strong>? Attend the <a href=\"https:\/\/www.cybersecuritycloudexpo.com\/\">Cyber Security &amp; Cloud Expo World Series<\/a> with upcoming events in Silicon Valley, London and Amsterdam to learn more.<\/p>\n","protected":false},"author":550,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-39783","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39783","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/550"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=39783"}],"version-history":[{"count":2,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39783\/revisions"}],"predecessor-version":[{"id":40035,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39783\/revisions\/40035"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=39783"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=39783"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=39783"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}