At SAP NS2, our business is focused on delivering a full suite of applications, analytics, database, cybersecurity, and cloud software solutions. with specialized levels of security and support for our U.S. national security and critical infrastructure customers. We have the same needs for development velocity as many other organizations but we must operate under stringent compliance and security protocols that present barriers to collaboration and fast, small batch releases. Our presentation will examine how you can balance velocity and compliance in regulated environments, and will take what we’ve learned from working with the government and show you how to apply those lessons to a range of industries with their own security and compliance considerations. A few topics we will cover: -How do you apply DevOps to enterprise software? -Compliance and security at speed and scale -Continuous monitoring is continuous delivery -How do I ensure auditability of my infrastructure -Chef Delivery and its vital role with compliance -Chef provisioning and our ability to adapt to customer needs quickly and reliably. -Auto scaling powered by slapchop Attendees will learn how we: -Leveraged Chef to enforce compliance -Leveraged Delivery for Change Control -Enabled auditing powered by Chef data.
next question is was that not only at best so that in a lot of things and specialist compliance space the 1st thing we looked at were building on was how users for structures like there's no as you know with on the structure we want ensure that people something action taken in transport environment by 1 of the key factors we have those we actually have to work there yet but we cannot see again environmental being we had something to say and say here you take it you have to talk to you take the nature of things codified standardized reading with the recent ones as to how the action approach that uses the universe as a whole that's all fine saying that all the word for offered on tour infrastructure 5 of all so you can save up from 1 . 2 that means that the that was the the lost it assumes you actually are responsible for ingesting all the people all the we have from our has has a key and bringing it in making it work and find out what the commercial off-the-shelf whatsoever designed along entire where it's area where you don't have can any agreement 16 others here you can deploy from 1 cell cultures can sometimes because employment and that that works hi and take all of these things and packed together and the that's what were the questions and so a lot of people here compliancy and the lost in space you're because most of you know that that doesn't make sense has a guarantee that government and the public sector and in fact there there's so so only 1 useless even make process factor there has to be there let's bring some of that out martial science and the only source world and bring them into the public sector and say let's take for so long and cover a little bit of how the world works I was the oldest being as a herself was huge security change is subjects huge harvest huge thinking all these things and with the environment where 1 you have access to is sometimes it's usable billions of data somewhere sometimes tensile up not words actually happens the next time you that environments are passed and the value of of insurance financing build correctly throughout by at most next covered is how rationalization and he mentioned in Section yes yes the lossy how was how and hold on to all of you will be so the 1st thing will covers some of the challenges we have with our resource it's it's it's on you there's hundreds of servers or applications that all that is about 100 so a variant of solid for assessing assassination that's a lot of a lot conveying engine what has to be there just for the application of the things is because we ourselves were so that the party search for a possible essay he has no worry about all this things coming in our ingesting all this from taking this happened in the of that that was a means to prevent the model was and what developers needed to on knowledge but they don't want see what the machine is because we're finds effect on the work you may not have access to all the time build something that we can always uses that say you know deploy is confined students scale so the 1st time that over there good job in this internet invariance of was that the following fare was 114 dashed to was a fan of the form that I the present how this all of these things never get the actually build environment for all users OK when I said that we only have forestry our how and when that is OK well this obligation as a living that the having actually worked forces and put them in the font so they were having to do with the back end of this is a learning build knowledge that security and when the guy that really really helps build things much bigger that of looking at it really is researcher there hasn't pessimistic 1 if you do that then you see a lot when the cross annexing 160 and the philosophy it's how to all this stuff and the across so you have the generations future fire on the shoulders machines talk and then the next thing we have is these key has a new area of our so called boundaries may not necessarily see and you have things systems themselves inside of me isn't enough of talking to other except for maybe 1 or 2 words from a specific around presented fire not allowed to say I want you meaningful merits further than what you see is what does the wheel that is that we can actually take this by putting together a file and say let's move all this together so states and that's what states but if the and and that no 1 say perhaps you missed it right with this is that priority I went to the particle is not that 3rd original things Latin all columns a bowl readers that's what the designed to do so high contain all the days and applied environment that works and and standardize all that say however in last thing all this stuff and students will you know always applications and appliances they will vary their numbers is fixed for those you unfamiliar this is sort of looks like
right so this is is not something you're which is very much of this year actually put together a great website saying here's my goal of our at say here's what they're in for example this is known as the last years or had no co-channel scientists have just done this wonderful standard things but as we look at the sum of all reliable as they file on a server shut him do that why not just make all this shit which then brings us to hunting all these things and again the next
day you probably have more about we have our environment the physically and what was this breaks the law of the having to try something that means package part of putting it on CD and saying so there's a hassle or walk across because there you can just sort of cross which a lot of cases it was something that have about what you'll see what goes on there is you want to see how the process the something that's horrible not both from the next big thing especially as a lot of balls that and we'll get high tionally area veteran and with the words is we were not propulsive you won't get access to watching it to a variant of the deviation and access to just a bit of yours the just made this year or last year's we'll have access to online and that's not necessarily the application on half so they cannot be overlooked for which the application also although it may have the answers is so that in the west you have a lot of cost functions vested in privileges we move that chat was that the instrument cost and on a lot of these tools assays involved in that case is only worry about just that they were able to solve is inferior this you will want helps also so that came so 1st column contours home things that look at this plant work so as to the structures of developing all the time how we think that we're across so the 1st is on the last of all of and processes so this has documentation design not all together before 1 recent orders as part of the package and what we actually some knowledge of the relationship geological into all the action of the 2 so in Europe and and I've worked on this for and 1 of the things that we do with the user change from process of
were talking about system libraries offer of life cycle in use everything that we urgently from changes it could be made from changes systems and you may always you you'll provisioning and how it's changed the provision chains the loss the cycle of the other part is things like the article books from a because of our our so we have to basically for clues mainly put them through rule or compliancy in and running through our change control any changes that we've been told them and going to also have the same process of allows us to easily and users creation however or the cormorants are not easy they are the so basically this is the reason for all of those of you who are of the view from delivery and mean you're running some the based on so basically you start to pull request for a different shapes name that goes through delivery the way is it for you to answer basic syntax chest in is a key test once approved by reviewer in on his words you use it you want to live recall far for most of you of the liver and this is where you get a lot of the this where you do most of your acceptance testing the could all into a union birdsong production which are slightly different but also we want to present a little 1 is there much so as long as you test as it will go through right and production however as part of a little bit we have disconnected production environments in nothing this is the last week of some of them had drug indicated we can even see of we have to basically in off and say here you go get employed in the contact with the problems they act on redacted problems that the requirements are we also has from the get stage to the way to a state environment to what each of those has to the people who have to sign off on it did you say you know of any guests can improve from there to the way that we show up after that it's something totally different and different in its state in different and production and actually that last part of the production side and also requires or customer to say yes we accept the codes stage in your allready production so very hot we also minimal delay of each in each stage enhanced by contract and also the regulations we can have once this at that stage 4 we have so that's slow this down a bit whereas we're trying to move very quickly so part of what we do here we modify the life cycle of took part of the delivery truck cookbook which is deliver users to you through each of stages and we basically had to take apart put it back together to your so you know the environment the poor was of course we'd passes through the normal delivery pump a line in the den environment is where it is delivery so that's basically where the rest stops we have a set of core which is a promotional west on certified gets ready to go we trained professional west which also wants to deliver a bold using modifying the delivery cookbook teaching the versions of certified dead to actually create the promoter they promotes it increased the environment Final then it has all the version numbers increase power of all codebooks and then has the sign on that because we need to the environment so it crosses the boundaries we have to say it was going out is what's happening it's all very complicated but delivery was flexible enough to allow us to do this with some modifications to the delivery truck of outside of that once all others have that ready when put in the change from what's the question as to whoever proves to the onto the stage name provided in the use of into the environment there was passing off the CDU somebody was physically whether that's in essence he transfer however is to go to prosperity once crosses their death taking all the shares your before that was included in this Act and they basically of lose all codebooks just all the body versions of his for each of the environments on each in each servers that or in that production or its a little bit complicated but we had to have worked in what part of the of the has very good very flexible allowing us to this the only part of the annual of what used to be offered Chester of book 1 since it all is delivered and all that it's very easy of motion was with the previous 1st cookbooks and you were all that forces of the so that has shown so those of you have a little room for our application of its and our action on a on the financing for so so next to her early experience was going through our terrible process was all over God has to be put into the baseline that it submitted to the orders they wanna is sort of body his heart lost his life and how did they put together and all racists is accused the PC's appliances thing the kitchen sink in it if you see that the documentation is can you get into the building always down to the bits officer it's a real pseudoknots facility the whole thing so how we put this all together how we standardized and stuff of there's a real also fluids that and
and With this could shuffle is there shall on this includes building machines how we actually put together a lot however this is I going was to say OK that at this is a little and the lack of knowledge so that actually writes show the people that Major Sheppard actually doing all the work that you standardized fire at which point you can say this is not 1 of the standout package of sending were other environment in the so it all together just to see how complex this environment blocks this is actually an
architecture diagram for just 1 of our of its reduce the complex on Monday to try something that's probably another 3 days not all but is usually just everything every box that you see the the color ones that's a different security not the difference in the question will will use you're actually services of web service after databases and all hostages ends up being a hundred services just for a minimum high-availability step so putting them all together the way that the trees or shape is the next year growing face and where we actually start looking at how we can fix that or how to tackle this problem was shot provision schools
that will be all over the world to actually start with you where the cost of the Ireland and Euratom's analyst to you about how you reasoning with this of of work that I want to explain why is it that you watch it the following is a
fairly new organization that of and was I would pass through socially grab the suite of Fatah location and women about it especially because of up so all we need to find out how to do with how we deploy these large numbers of how is it that all these special Annals of servers prior is usually transferred and essentially just as can assume that is 1 of our chat with you as he was rich enough to give us cookbooks through poisonous applications which was a great has for us and we will do so we also need to figure out a way to is so many you work with in the US said something very were worried areas of stone showing myself so working by point server 1 by 1 by 1 is fast especially when we start of something the work of the actual vote for it go for it to actually put work so that about so hadn't had this problem of mold serving or yeah shellfish which channeling give us the ability of insulin the requirements that were new for us which were had to be flexible enough To the extent that they had to be solution of transpire between a local area markers and so 2nd there was managing all these as we heard always cats right beginning all these applications give them all the work you know essentially smoothly together which was news they pay and lastly but correlated security a being as a as a the national security services that is the number 1 priority nature there are quite a was 1 of our applications are structure is fully in place insecure so I should original we have to figure out a way to essentially get all these recipes to work together for each 1 of applications so we had this letter is to you want to communicate with other of work you know we to talk and utilize the years in which is great you these these years spines pretty highly doing a lot of ice we talked a lot of time to extend that soldier visioning give us that because that's isn't has from the genes but to to you as a 4 hour news we had used it has like and resources and so that's the house that the size of the US is are massive reasoning contains everything that we use only everything location every single tree everything we see we utilize and so has given us essentially the is the backbone of the entire structure in a lot the 1st thing is this was the same as in general here it's true we have moved all about so we have you do me a code portable enough to to move from place to place to place what's right and so we start off in a loss of returning to that right it is the ability to increase on the cost of things you can do right we can that the she's going to sort of right have a way to deploy false that about each of the entire spectrum and be all of the edge is going to be a part of right so that was the score values and that's what we look at the data points for us at the time was figuring out a way to make these household writing that the challenge you know as as a songwriter earlier we have hundreds of apps hundreds of things working together in these things usually it's hard to use so so we reduce variance that you know we do have have great now how we use these are the things we started doing this it goes up to a week you know all possible over to you to run the rediscovery the color cation so we have to figure out a way to bring that should be allowed us to do that in In particular the least you to essentially bring them and that we call on time don't about it right and by 1 of our last feature right in roughly 100 and what is your rate that comes from the you the part of the evacuation Web right how many have a mission
vision most because we were able to put a machine that they essentially you orchestrate the weight of these applications we employ right to bring in the of that hundreds of Israeli go it's vital reuse with just after that we that occasionally result of that research of pressure has also was that we are so all those little things that we need to utilize generation it was lost any was going to bring down the it's actually to the point is she occasion down decisions with with the right espressos good it was good and bad were ready that we're all we make sure that all of our actions are at the point is very distinct so I have to say that with our cycle of the provisioning and delivery instrument because once we have a book once we have the code or actually should have a higher because originally was that by being the time in the hope that we can go through it has every single time in quantum service and we saw that he was going to do so so delivery was construal that work so to me and I and chew out on together to make sure that that was happening everything time at all so how is for us because they arise is everything you everything up occasionally do employ we know it is exactly to everything and so we build it happens when a new you again with the more you work work with has helped us to velocity to specialize in research field lean on a fusion of customers into more where so we found to our security model had to make that happen easily and smoothly as shown images we have to understand throughout the body right and there is evidence that not for its so and so we have is you move you ask all these questions have been a all you have to just kind of your actual or secure you've checked all we have various because part of the article reflects is exactly how would how we we so liking to that shown in the code penal to I'll give them those ones has helped us tremendously maintenance easier and so that led to our security right after you've also seen that the bill of sale at all languages and so that's a problem but with vision we have been able to essentially you want school when they can use to maintain enabled to also ensure that remediation and ensure that everything that we have said we're going to do it there so in calling for example and the rules that we currently use we used to using that out through the rest of right so every now and then if the test it so I have so sentences in a lot of the sports off but what you wanted to volunteers at the also that's great but the problem is of course castles of light that falls out of a large spectrum of the world so by the into for example grab 1 of these recipes put in a provision no we are able to that in in words and things right so she change the whole number 2 major revision included back so we will have to worry about how we know what happens when removes all land the sports should be that's the the student so it is a shame because of their age so we could to has so we're taking the that into our taking provisioning as a cookbook at it's a couple that's delivered alignment over everything else which is of course so working through the actually of this really accelerate properly we need to work there don't get through we take a process that was really necessary for us to take up to 3 years 2 years of here you're dreaded here all that into years not use so we definitely move faster next our interesting with policy inspect finds the entire that directly to the platform built because they're actually built the delivery and shattered much so we have defined so as on the going in the input in all of the United instead also in compliance programs the pipeline and had flown directly in so that the venue coming out of this time were things I wish I had a student and I will go to the
questions of so the search of meaning has the diversity of learning the and of which can be so much junk in this is are you aware anybody who is sort of put out of collections of books that help you with the energy and they I want Tomcat but this time don't work just for well I had the if not always in the line this much possible just like this so that's not the point process well as you look at the map on out there on I will say there is a quote from US yes around 6 that will actually get these the basal as on these was actually of reaction that for us but that's sort of start by the end of our applications that almost always a little difference so we're looking at ways that happens in lot of community were sold on so that was on I think and as in all the matches start getting back with some out the same a age that users about element the based you mentioned was when he shows you have security you could then they actually went through a lot of aligned with the solvent was doing security is supposed to be prudent to all the problems with the nest and that's actually case the intelligent but so actually this that's part of our our back so long we lot with the waters where they came in the offices that down on a lot of problems here Table there is use of sentiment through actually cause some something else will be wrong said here what we just do and we cannot have problems that you will be working in the material Stewart we're on track and here's vigilance and that actually was pretty sufficient that use that we also will always analytics which things it's all these injuries for cost always saying things like I think I can have a small questions so I'm especially when dealing with Ortiz or security learning things a lot of times when I try to bring chef and an organization there's a lot of just you need fear about NATO dealing with code for anything I'm so sorry you guess that any of resistance you with the external auditors were your internal teams I up but in their face in a way the assistance the secured on in matching the jury and the answer that of he was actually there's a help because that was what yeah so very often you know quite a bit of a sense of of people understand what it means to actually put my infrastructure that understand what you mean by using a single that means the security so small fear of the unknown wants to start execution 1 thing we did was is about 7 of which are comes in and actually shows that the security as this is what we have here is the standardization the star and in a state of and that during and in the same group you can search and you can build a signed bill standardization and you don't change for all this time interval so much better than it does in fact building individual systems so you can actually show right there to security and from about 1 hour in of how their life just from the good to this right we also show your it management how you can sell consolidating teams consolidates inside value from Bell the documentation the around security but so see someone with this on Friday to that or they can save you a but in the start so that you now wish you need you wish to you now they didn't know that this fall and hot that that was 1 of the major things that is a big on what because a lot of a grouping works and we were developed with humans on the environment special bestseller out of nowhere now we did it we we we sort of look for that where reporting things to get things working and how would we try not to everything fell out so I will not alter the and so the logic is just going to get as well so that was the ones of keeping in mind that you want to buy and 1 of the states it was the design and just because that's how the set of his security Cantonese xyz gene that have that put together that radiation here's what we did here's how protect against any other also known as a result of having that would that that will be on the should only knowledge brought in or security so and to the sound without affecting it provides a expect greenery here is definitely 1 of this data starting out inspect how things are the the same so long as the age after we culture of several times I began to be people to win so as to the guys who isn't in the in and out of or away from the the 1st question now I'm keen time last year the US the class that's in your organization and how auditors respond to that so when we do that we actually do it open so you can report on new or a sentence or interrogator pairs so using anyway it was available in the there's something wrong with the course of our also change you're probably will mean that the women in control from production of words are moving in on that is working poor West Coast produced and delivery process so we have a Byzantine inside cordon off and attaches fossils call the book and all that all that is anybody organs actually you make a change in the wind that is the actions in the world were being processed approval for it was not so these 2 sets of items because of course means that so many of them are so it's important to know the different environments so that require you to use the American south but you don't have a handout situation the dead QA and production the and so when you do that you the service access but is is a kind of a high medium low you from reduction backwards so you can provide more access to the voters of new teams and then you don't process this is the last cycle as to how you actually do that code and how security does it's just balances the those aren't there something that we in using mentioning the attitude currently and we will see to what extent confidence and actually user to the delivery lexical ahead of where we had to go across the that's of 1 thing I would add to the things we wish him so I originally were about delivery started this because the automated testing users say it's a whole lot and his all that they will not questions or sorry zones on the accuracy of solution use this as the different kind of his view