Putting the “Sec” in DevSecOps… Quantified

March, 2021

The March 2021 tech talk was presented by Larry Maccherone

Abstract:

A guiding principle of Comcast Cybersecurity is that we are no longer gatekeepers, but rather coaches and toolsmiths. Another, is that we favor building security in over bolting it on. Together, what this means is that the ownership of the problem of the security of the products shifts primarily to the teams that are developing those products. Further, the role of the cybersecurity group at Comcast shifts to supporting those engineering teams by developing and providing self-service tools that prevent problems or give automated feedback. We then provide coaching to help teams understand how best to use those tools and whatever other DevSecOps practices they need to adopt.

This talk dives deeper into what the above paragraph means and then presents original research quantifying the impact that various DevSecOps practices have on security risk outcomes so you can make an informed decision what to focus on first.

About the Presenter 

Larry Maccherone is an industry-recognized thought leader on Lean/Agile, Analytics, and DevSecOps. He currently leads the DevSecOps transformation at Comcast as a Distinguished Engineer. Previously, Larry led the Insights product line at Rally Software where he published the largest ever study correlating development team practices with performance. Before Rally, Larry worked at Carnegie Mellon with the Software Engineering Institute (SEI) and CyLab for seven years conducting research on cybersecurity and software engineering.

Contact Larry on his LinkedIn page: https://www.linkedin.com/in/LarryMaccherone

Past Presentations

Personal Reviews: How Fencing Helped Me Write Better Software

The May 2023 tech talk was presented by Dr. Bradley HodginsAbstractNAVAIR has hundreds of engineers/professionals using Team Software Process (TSP) and Team Process Integration (TPI) methodologies to plan and track their projects. One especially valuable activity in...

Application of Statistical and Other Quantitative Techniques in Software

The February 2023 tech talk was presented by Stephen ShookAbstractThe CMMI has long emphasized use of “statistical and other quantitative techniques” as a best practice for software work. Many organizations struggle with how to apply those techniques. (The ISHPI AIS...

Implementing a Strategy for Excellence

The January 2023 tech talk was presented by Seemin SuleriAbstractIn our pursuit of excellence, we built a strategy that matched the ambition of a competitive e-commerce business. The problem was, where do we start the work: A struggling software department with high...

NAVAIR Process Dashboard Introduction Workshop

Abstract: NAVAIR has hundreds of engineers/professionals using Team Software Process (TSP) or Team Integration Process (TPI) methodologies to plan and track their projects. NAVAIR teams following TSP/TPI use the Process Dashboard tool to implement the methodologies....

Why Can’t Johnny Program Securely?

The October 2022 tech talk was presented by Robert SeacordAbstractSecure coding (unsurprisingly) is hard. Our educational systems have failed to properly prepare students, and our assessments have overestimated their abilities. Analysis and testing is useful but...

Team Process Integration: Half-Day Course

Abstract: This half-day course covers all aspects of the Team Process Integration (TPI) framework. The TPI methodology integrates disciplined project practices that can be applied by many product teams (e.g., software, systems, and test). It is a framework that...

How to Increase Team Performance : A Tale of Two Teams

The June 2022 tech talk was presented by Seemin SuleriAbstract:This is a story of two software teams: one in a large blue-chip corporate environment and another in a small company. This is a tale of how people came together to face challenges and show incredible...

Rules and Submissions for the Watts Humphrey Process Achievement Award

The August 2022 tech talk was presented by Isabel Margarido.AbstractWatts Humphrey was a practitioner and advocate of Software Engineering good practices, also known as the “Father of Software Quality”. His work “laid ground for” CMM, CMMI and he proved the entire...

SEA 2022 Virtual Summit

Software Excellence Alliance professionals from around the world met to celebrate our accomplishments from 2021 and to set the Alliance's 2022 direction for changing the world of software engineering.Jim Over delivered the keynote presentation, sharing his personal...

The Digital Transformation Spiral Model

The March 2022 tech talk was presented by Dr. Barry DwolatzkyAbstract:Digital transformation has become an imperative for organisations in the 21st Century irrespective of size, sector, or geographic location. Studies have shown that a very high percentage of digital...

Changing the Engines without Landing the Plane

The January 2022 tech talk was presented by Robert BentallAbstract:Technical debt is like adding useless ballast to a speeding jet. It just slows everything down. Yet, in most environments, technical debt reduction, infrastructure upgrades, and process improvement...

Being a Leader and Coder – A Survival Guide

The December 2021 tech talk was presented by Dylan GreinerAbstract:Being both a technical leader and an active software engineer at the same time raises many challenges. I present the various techniques and approaches I have both learned and gathered from various...

High-Maturity Scrum with the Process Dashboard

The October 2021 tech talk was presented by David TumaAbstract:Scrum is a popular Agile development method that enables rapid customer feedback and continuous delivery of value. Earned value is a high-maturity planning technique that helps teams to create realistic...

Training Coco – Agile Lessons with a Puppy

The September 2021 tech talk was presented by Jeff PulciniAbstract:Does training a 10-week-old puppy have any relation to Agile and Agile teams? Can training basic commands like sit, stay, and down be useful to Agile teams? What about potty training? Join us as we...

Making SAFe Better from the Bottom Up: Mixing Methods and Tools

The August 2021 Tech Talk was presented by Kimberly WadeAbstract:The Scaled Agile Framework (SAFe) is the leading method for scaling lean and agile practices to large solution delivery. Using SAFe allows large organizations with multiple programs and projects to...

Share This