×÷Ϊ¹ú¼ÊÉÏ×î¶¥¼¶µÄÍøÂçÇå¾²¾Û»á£¬RSA¾Û»áͨ¹ýÖ÷ÌâÑݽ²¡¢É³ºÐ¡¢Êý×ÖÕ¹ÀÀ»á¡¢×êÑлáµÈ¶àÖÖ·½·¨ÏòÈ«ÇòÍøÂçÇå¾²Ïà¹ØÖ°Ô±×ª´ï×îÐÂÉú³¤Ç÷ÊÆ¡¢ÈÈÃÅÊÖÒÕÒÔ¼°ÐÐÒµÈËʿרҵ¿´·¨µÈÄÚÈÝ£¬ÌìÌìµÄ¾Û»áÄÚÈݶ¼°²ÅŵÄÒì³£¸»ºñ¡£ÔÚµÚ¶þÌìµÄRSA¾Û»áÉÏ£¬Õë¶Ô»ù´¡ÉèÊ©Çå¾²¡¢Èí¼þ¿ª·¢Çå¾²¡¢NIST±ê×¼¡¢DevSecOpsµÈ¶à¸öÖ÷ÌâÆ«Ïò£¬Õö¿ªÁ˾«²Ê·×³ÊµÄÑݽ²¡£
01 Ñݽ²Ö÷Ì⣺¡¶Î´À´¼«ÏÞÅÌËãµÄÍøÂçÇå¾²¡·
Ñݽ²ÕߣºDr. Anne Fitzpatrick£¨ÍøÂç¹ú¼ÒÇå¾²¾Ö¸±ÃÜÂëѧ¹ú¼Ò¹ÙÔ±£©
Dr. Anne FitzpatrickÔÚÕâ´ÎÑݽ²ÖÐÏÈÈÝÁËHPC¸ßÐÔÄÜÅÌËãµÄÉú³¤ÏÖ×´ºÍδÀ´µÄÍøÂçÇå¾²ÎÊÌ⣬ͬʱ¶ÔHPCµÄδÀ´Éú³¤¾ÙÐÐÕ¹Íû¡£
HPC£¬¼´ÎªHigh Performance Computing£¬¾ßÓиßÐÔÄÜÓÅ»¯¡¢°üÀ¨Ìض¨Ó²¼þ¼°Èí¼þ¡¢¹æÄ£ºÍÅÌËãËÙÂÊÒª³öÀà°ÎÝ͵ÈÌØµã¡£ÏÖÔÚHPCÁìÓòÊÇÒ»¸öÓÐÊýµ«ÈÔºÜÖ÷ÒªµÄÁìÓò£¬Ë¼Á¿µ½Õþ¸®Í¶×Êȱ·¦µÈ¶à·½ÃæÔµ¹ÊÔÓÉ£¬HPCÔÚÒÑÍù25ÄêÖкÜÉÙÓÐÁ¢Òì¡£

ÔÚ̸µ½ÍøÂçÇå¾²ÎÊÌâʱ£¬ÒÔExascaleÏîĿΪÀý£¬Dr. Anne FitzpatrickÏÈÈÝ£¬ËäÈ»ÏîĿϣÍû˳Ë죬µ«HPCµÄ¿É¿¿ÐÔËæ×ŹæÄ£µÄÔöÌí¶ø½µµÍ£¬Í¬Ê±ÊÖÒÕ¡¢Éç»á¡¢ÕþÖÎʵÁ¦µÈÒòËØÒ²»á¶ÔHPCµÄÇå¾²ÎÊÌⱬ·¢Ó°Ï죬´Ó¹ú¼ÒÇå¾²½Ç¶È˼Á¿£¬È·±£¹©Ó¦Á´Ç徲ʮ·ÖÒªº¦¡£
ÔÚ̸µ½HPCµÄÉú³¤Ç÷ÊÆÊ±£¬Dr. Anne FitzpatrickÒÔΪÐèÒªÓÃÈ«¾ÖºÍÉú̬ϵͳͷÄÔÈ¥¿´´ýHPCµÄδÀ´£¬HPC½«´ÓÆ¾Ö¤Ô¤ÖÆÖ¸ÁîÖ´ÐеĻúÐµ×ªÒÆµ½»ùÓÚº£Á¿Êý¾Ý²¢ÇÒ¿ÉÒÔ¡°Ñ§Ï°¡±µÄÈÏ֪ϵͳ£¬ÕâÆäÖУ¬Í¨Óô¦Öóͷ£Æ÷½«Ô½À´Ô½ÉÙ£¬¸ü¶àµÄÊÇתÏòרҵ»¯ºÍ¡°design your own¡±µÄģʽ£¬Ò²ÐíÔÙ¹ý40Ä꣬ÎÒÃǽ«²»ÔÙÏñÏÖÔÚÕâÑùÊìϤHPC¡£
פ×㵱ϣ¬Dr. Anne FitzpatrickÒÔΪHPCµÄ¼¸¸öÉú³¤Æ«Ïò°üÀ¨¡°·ºÔÚÅÌË㡱ºÍˢпçѧ¿ÆµÄÍøÂçÇå¾²Ñо¿Óë½â¾ö¼Æ»®ÒÔ¼°ÖØÐÂ˼Á¿HPCÀͶ¯Á¦µÄÉú³¤µÈ¡£
02 Ñݽ²Ö÷Ì⣺¡¶ DevSecOpsͬÃ˵ÄÉú³¤ÏÖ×´¡·
Ñݽ²ÕߣºShannon Lietz£¨Intuit¹«Ë¾DevSecOps×ܼࣩ
ʲôÊÇDevSecOpsÄØ£¿DevSecOpsÊÇDevOpsµÄÀ©Õ¹£¬Ëü±»ÒÔΪÊÇÒ»ÖÖÏ໥½»Ö¯µÄ·½·¨¿ª·¢¡¢ÔËÓª¡¢Çå¾²¡£DevOpsÆðÔ´ÓÚѸËÙÎÄ»¯£¬ÌØÊâÇ¿µ÷¿ìËÙ¿ª·¢ºÍ°²ÅÅ£¬µ«ÔÚʵÏÖ¿ìËÙ¼ÛÖµ½»¸¶µÄͬʱ£¬Çå¾²ÐÔÈí¼þ¿ª·¢Àú³ÌÖÐÒ²´øÀ´ÁËΣº¦¡£Òò´Ë£¬Ò»Ð©ÓÐÇå¾²ÎÊÌâµÄ¹«Ë¾×îÏÈ˼Á¿Çå¾²µÄDevOpsÓ¦Óã¬Õâ¾ÍÊÇDevSecOps¡£¡°Éú³¤¡¢ÔËÓª¡¢Çå¾²ÊÇ»ù´¡£¬Çå¾²ºÍDevOps±ØÐèÑÝÄð³ÉÒ»¸öеÄÔ¸¾°¡±£¬Shannon LietzÒýÓûÒÉ«ÎÄÏ××ÛÊö(GLR)ËùÑ¡µÄÎÄÕ¡£

Shannon LietzÔÚÑݽ²Öн²µ½£ºDevSecOpsÊÇÅãͬ×ÅÈí¼þÖÊÁ¿ºÍÇå¾²µÄÉú³¤¶ø·ºÆðµÄ£¬×î³õÊÇΪÁËÖ§³ÖÌåÀý×î¡°½áʵ¡±µÄÈí¼þÊֲᣬ½â¾öDevOpsÓ¦ÓÃÖеÄÇå¾²ÎÊÌ⣬ÒÔÊÇDevSecOpsµÄµÚÒ»¸öÀÖ³ÉÂÄÀúÊDZØÐèÓëÈí¼þ¿´Æë£¬°ÑÈí¼þÖÊÁ¿ÓÉÔÀ´µÄ´´Á¢¼ÛÖµºÍ¿ÉÓÃÍÆÏò´´Á¢ÐÅÍкͱã½ÝÉú³¤¡£DevSecOpsÁíÒ»¸öÀÖ³ÉÂÄÀúÊÇ£¬Ç徲רҵÈËʿԽÀ´Ô½Òâʶµ½ÐèÒªÔÚÁ÷³ÌµÄÔçÆÚ×óÒÆ£¬ÔöÇ¿Çå¾²Ó뿪·¢Ö°Ô±µÄ»¥¶¯ºÍѸËÙÐû²¼£¬ÕâÑùÄܹ»´ó´óïÔÌÈí¼þºóÆÚ·µ¹¤´øÀ´±¾Ç®¡£Ëæ×Å DevSecOps µÄ½¨É裬¸ü¶àѧÊõ×éÖ¯ºÍÆóÒµ¶Ô DevSecOps±¬·¢ÁËѧÊõÐËȤºÍÀͶ¯Á¦Í¶È룬 Gartner ÔÚ2020ÄêÐû²¼µÄÓ¦ÓÃÇå¾²Óйر¨¸æÖмÓÈëÁËDevSecOps ²úÆ·Öֱ𣬽øÒ»²½×ª»¯ÁËDevSecOpsͬÃ˵ÄÊг¡Ð§Ò棬¼ÓËÙÍêÉÆÁ˲úÆ·¹©Ó¦Á´¡£
ËäÈ»£¬DevSecOpsÒ²ÓÐʧ°ÜµÄÂÄÀú£¬ÐèÒªÕÆÎÕÈí¼þ¿ª·¢ÔËӪȫÉúÃüÖÜÆÚµÄÊÖÒÕ£¬ÒÔ¼°Àú³ÌÖеIJ»¿É¿ØÐÔ¡¢¼ÙÑôÐÔ¡¢Éó¼ÆÒªÇóµÈ£¬ÕâЩ¶¼»á¶ÔDevSecOpsµÄÓ¦ÓÃʵ¼ùÔì³É¹¥»÷¡£ÐÒÔ˵ÄÊÇ£¬¾ÓÉÊ·Ê«°ãµÄ¶·Õù£¬DevSecOpsͬÃËսʤÁËÕâЩÄÑÌ⣬ÐγÉÁËDevSecOpsÉú³¤µÄÄÜÁ¦¡¢ÎÄ»¯ºÍÊÖÒÕ£¬Í¬Ê±£¬Çå¾²ÔËÓÃÄ¿µÄÔ½´´ÔìÈ·£¬Á÷³Ì¡¢»ù´¡½á¹¹ºÍÐ×÷Ò²Ô½·¢ÍêÉÆµÈ¡£Òò´Ë£¬ÎÒÃǸüÓ¦¸Ã¹Ø×¢DevSecOps½ÓÏÂÀ´»á±¬·¢Ê²Ã´£¬¾ÍÏñGartner2020ÄêÕ¹ÍûµÄÒ»Ñù£¬DevSecOps±»½ç˵ΪÔÚÓ¦ÓóÌÐò¿ª·¢Àú³ÌÖÐÓ¦ÓÃÇå¾²µÄÀú³ÌÒѳÉΪ¹²Ê¶£¬DevSecOpsÊг¡ÔÚ2021-2028Äêʱ´ú½«ÊµÏÖ¸ßËÙÔöÌí£¬ÎÒÃÇÖ÷ҪʹÃü¾ÍÊÇʹÓÃÐÂÊÖÒÕʵÏÖÓ¦ÓóÌÐòËùÐèµÄÇå¾²ÐæÅºÍÀú³ÌµÄ×Ô¶¯»¯¡£
03 Ñݽ²Ö÷Ì⣺¡¶CISAÈç×÷ÉõÍýÏë»ù´¡ÉèÊ©·À»¤Ïß·¡·
Ñݽ²ÕߣºJoshua Corman£¨CISAÒ½ÁƲ¿·ÖÊ×ϯսÂÔʦ£©¡¢Sounil Yu (JupiterOne CISOºÍÑо¿²¿Ö÷¹Ü)
ÔÚ¡¶CISAÈç×÷ÉõÍýÏë»ù´¡ÉèÊ©·À»¤Ïß·¡·Ñݽ²ÖУ¬Ñݽ²ÕßÌåÏÖÏàʶCISAÔÚÍýÏë»ù´¡ÉèÊ©·À»¤Ïß·ʱËùʹÓõÄÒªÁ죬ÒÔ¼°ÔõÑùʹÓøÃÒªÁìÀ´Öƶ©ÊÖÒÕÕ½ÂÔÊǺÜÊÇÖ÷ÒªµÄ¡£ÓÉÓÚÏÖÔÚÎÒÃÇÐí¶à»ù´¡ÉèÊ©µÄÇå¾²·ÀÓù¶¼ÊDz»·óµÄ¡£

CISAµÄÄ¿µÄÊǺ´ÎÀ½ñÌ죬°ü¹ÜÃ÷Ìì¡£ÈçÉÏͼÖÐÁ½¸öÏ໥µ¹ÖõĽð×ÖËþ£¬º´ÎÀ½ñÌìÓÉÉÏÖÁϰüÀ¨¶Ô²ß¡¢Ç龳ȱʧ¡¢²Ù×÷ÔÓÂÒ¡¢ÎÞ·¨·ÀÓùµÄ»ù´¡ÉèÊ©£»¶ø°ü¹ÜÃ÷ÌìÓÉÏÂÖÁÉÏÔò°üÀ¨¿É¿¿¡¢²Ù×÷¹æ·¶¡¢Çé¾°Ã÷È·¡¢¶Ô²ßÒ»ÖµĻù´¡ÉèÊ©¡£
ÍøÂç·ÀÓù¾ØÕóÊÇCISAµÄ»ù´¡£¬ËüÄÜ×ÊÖú»ú¹¹¿ìËÙÏàʶĿ½ñµÄÇå¾²Ì¬ÊÆÒÔ¼°ÔõÑùˢС£»ù´¡ÉèÊ©·ÀÓùµÄÖÊÁ¿ÔòÌåÏÖÓÚDIEÈýÔÔò£¬¼´ÂþÑÜÐÔ¡¢²»¿É±äÐԺͶÌÔÝÐÔ¡£½«DIEÓ¦ÓÃÓÚ¿É·À»¤»ù´¡ÉèÊ©ÖиüÈÝÒ×·¢Ã÷²î±ðºÍʱ»ú¡£
04 Ñݽ²Ö÷Ì⣺¡¶ÈýºÏÒ»£ºÈý¸öNIST¿ò¼ÜµÄÆÊÎöºÍÖØ×é¡·
Ñݽ²ÕߣºDave Weitzel£¨MITREÕþ²ßºÍ±ê×¼ÈÏÕæÈË£©¡¢Julie Snyder£¨MITREÊ×Ï¯ÍøÂçÇå¾²ÓëÒþ˽¹¤³Ìʦ/NCFÒþ˽ÁìÓòÈÏÕæÈË)¡¢Christina Sames£¨MITREÊ×Ï¯ÍøÂçÇå¾²¹¤³Ìʦ)
NISTµÄΣº¦ÖÎÀí¡¢ÍøÂçÇå¾²ºÍÒþ˽±£»¤¿ò¼Ü¶¼ÊÇÓÃÓÚË¢ÐÂÆóÒµµÄΣº¦ÖÎÀí£¬ËäÈ»¿ò¼Ü¸÷×Ô²î±ð£¬µ«ËüÃÇÒÔijÖÖ·½·¨ÓÅÊÆ»¥²¹£¬Ê¹ËüÃdzÉΪÈκÎ×éÖ¯ÖÐÓмÛÖµµÄΣº¦ÖÎÀí¹¤¾ß¡£

ÍøÂçÇå¾²ºÍÒþ˽Á½¸ö¿ò¼Ü¶¼°üÀ¨½¹µã²ã(Core)¡¢ÌáÒª²ã£¨Profiles£©ºÍʵÏֲ㣨Implementation Tiers£©¼¸¸ö×é³É²¿·Ö¡£½¹µã²ãÀï°üÀ¨×éÖ¯ÓÃÓÚ¿ªÕ¹Î£º¦ÖÎÀíµÄһϵÁÐÔ˶¯ºÍЧ¹ûÎÌáÒª²ãÊǽ¹µã²ãÀï½¹µãµÄ×Ó¼¯£¬ÓÃÓÚ½â¾ö¸æ¿¢×é֯ĿµÄʱÓöµ½µÄΣº¦£»ÊµÏÖ²ã×ÊÖú×é֯ȷ¶¨ÊÇ·ñÓÐ×ã¹»µÄΣº¦ÖÎÀíʵ¼ùºÍ×ÊÔ´ÒÔµÖ´ïÆäÄ¿µÄ¡£Î£º¦ÖÎÀí¿ò¼ÜÓÉ×¼±¸¡¢·ÖÀࡢѡÔñ¡¢ÊµÑé¡¢ÆÀ¹À¡¢ÊÚȨ¡¢¼à¿ØµÈһϵÁа취×é³É¡£Ñݽ²ÕßÏÈÈÝÁËÍøÂçÇå¾²ºÍÒþ˽¿ò¼ÜÔõÑùÔö½øÎ£º¦ÖÎÀíÔ˶¯µÄ£¬ºÃ±ÈÔÚΣº¦ÖÎÀíÀú³ÌºÍÔ˶¯ÖУ¬½¹µã²ãºÍʵÏÖ²ãÉÏ¿ÉÒÔÌṩ¸üϸÃܵÄÁªÏµºÍÏàͬ£¬ÌáÒª²ãÉÏ¿ÉÒÔÔÚ×é֯ʹÃü/ÉÌҵĿµÄºÍÍøÂçÇå¾²¡¢Òþ×ß˽¶¯Ö®¼ä½¨ÉèÁªÏµ£¬Í¬Ê±¿ÉÒÔ×èֹһЩÐèÇóÉϵijåÍ»¡£Ñݽ²Õß½¨Ò飬ҪÃ÷È·Èý¸ö¿ò¼ÜÒÔ¼°ËüÃÇÖ®¼äµÄ¹ØÏµ£¬½¨Éè¿ò¼ÜÌáÒªÊֲᣬÃ÷ȷΣº¦ÖÎÀíʵÑé°ì·¨£¬½«ÌáÒªÉè¼ÆºÍΣº¦ÖÎÀí¿ò¼ÜÓ¦ÓÃÆðÀ´£¬ÊµÏÖÈý¸ö¿ò¼ÜµÄÈںϡ£
05 Ñݽ²Ö÷Ì⣺¡¶¹¤¾ßʱ¿Ì:¹¹½¨ÄúµÄÍøÂçÇå¾²¼Ü¹¹ÍýÏ빤¾ßÏä¡·
Ñݽ²ÕߣºDiana Kelley£¨Founder & Partner SecurityCurve£©
Diana KelleyºÍEd MoyleΪÎÒÃÇÏÈÈÝÁËÔÚ¹¹½¨ÍøÂçÇå¾²¼Ü¹¹ÍýÏëʱËùÓõ½µÄÆÊÎö¹¤¾ß¡¢ÐÅÏ¢¹¤¾ßºÍÉè¼Æ¹¤¾ß£¬Õë¶ÔÔõÑù¹¹½¨¼Ü¹¹¹¤¾ß£¬ÒÔ¼°ÔÚºÎʱÄÇÀïʹÓÃÕâЩ¹¤¾ßÀ´ÀÖ³ÉÇÒÇå¾²µØÊµÑé¼Ü¹¹¾ÙÐÐÁËÏêϸڹÊÍ¡£
Ò»¸öÀֳɵÄÇå¾²¼Ü¹¹Ó¦¸ÃÊÇͳһµÄ¡¢¹æ·¶»¯µÄ¡¢²¢ÇÒÊÇ¿ÉÖØ¸´µÄ£¬Ôڼܹ¹Éè¼ÆÊ±Ó¦µ±×ñÕÕ˳Ӧµ±ÏÂÇéÐΡ¢×èֹ̫¹ýͶ×ÊÒÔ¼°Ë¼Á¿ÖÜÈ«¼¸¸ö½¹µãÔÔò£¬Ò»¸ö¼Ü¹¹Éè¼ÆÍ¨³£ÐèÒªÏàʶĿ½ñ״̬¡¢Í¨¹ýÕÉÁ¿ºÍÑéÖ¤¡¢±ê¼ÇδÀ´×´Ì¬Èý¸öÀú³Ì£¬¶ø¹¤¾ßÖ§³Ö×Åÿ¸öÀú³Ì¡£
̫ͨ¹ýÎö¹¤¾ß£¬¿ÉÒÔʵÏÖÄ¿½ñ״̬£¬Î£º¦ºÍÍþвµÄÊáÀí£¬²¢Í¨¹ýÓÐÓÃÐÔ¡¢³ÉÊì¶ÈºÍЧÂÊÈýÖá¾ÙÐн¨Ä£ÆÊÎö£¬À´×ÊÖúÄúÏàʶÔõÑù×öÒ»¸öÇ徲ʹÃü¡£ÆäÖУ¬³ÉÊì¶È¹Ø×¢µÄÊÇÇå¾²Á÷³ÌÊÇ·ñ¿É¿¿ÇÒ¾ßÓе¯ÐÔ£¬¿ÉÒԲο¼ CMMIµÄ³ÉÊì¶È»òÄÜÁ¦¡¢Á÷³ÌʵÑéºÍ CMMCµÄÊÖÒÕ¡¢³ÉÊì¶ÈÆÀ¹ÀµÈ£»Ð§ÂʹØ×¢µÄÊÇÇå¾²×ÊÔ´±»ºÏÀíÓÅ»¯µØÊ¹Óã¬Í¨¹ý¾¼Ã½¨Ä£¹¤¾ßÏàʶÁ˸÷¸ö¿ØÖƲ½·¥µÄ±¾Ç®¡£

ͨ¹ýÐÅÏ¢¹¤¾ß¾ÙÐÐÍøÂç¡¢¸ú×ÙºÍÆÊÎöÆóÒµËùÔÚÇéÐÎÐÅÏ¢£¬È»ºóͨ¹ý¿ÉÊÓ»¯µÄÖ¸±ê¾ÙÐÐչʾ¡£
ͨ¹ýÉè¼Æ¹¤¾ß¾ÙÐн¨Ä££¬¿É×ÊÖú±à¼ºÍºÏ²¢¼Ü¹¹ÍýÏ룬ʹÓÃArchiMate»òUMLµÈ±ê¼ÇÓïÑÔ¾ÙÐиüºÃµØÉè¼Æ¡£
×îÖÕ£¬½«ÆÊÎö¹¤¾ß¡¢ÐÅÏ¢¹¤¾ßºÍÉè¼Æ¹¤¾ß¾ÙÐÐÓÐÓõÄÍŽᣬ½ø¶ø³ä·ÖÕ¹ÏÖ¿ÉÊÓ»¯¡¢Í·ÄÔÓ³ÉäºÍÁ÷³ÌÐͬµÄ×÷Óã¬ÒÔ´ËÀ´Éè¼Æ×îÊÊºÏÆóÒµµÄÍøÂçÇå¾²¼Ü¹¹¡£
06 Ñݽ²Ö÷Ì⣺¡¶¿ÆÑ§ÒªÁ죺Çå¾²»ìãçʵÑé&¹¥»÷Êýѧ¡·
Ñݽ²ÕߣºKelly Shortridg£¨¸±×ܲÃ, Capsule8£©
Çå¾²»ìã繤³ÌÌá³öÁËÒ»ÖÖеÄÒªÁ죬ʹÓÿÆÑ§µÄÒªÁìºÍ¹¥»÷ÕßÊýѧÀ´ÐγÉÓÐÓõķÀÓùÕ½ÂÔ¡£Kelly Shortridgͨ¹ýÓþöÒéÊ÷À´¼ÙÉè¹¥»÷ÕßÕ½ÂÔ£¬È»ºó̽Ë÷ʹÓÃÕâЩ¶¯Ì¬Íþвģ×ÓÀ´ÖÆ×÷ÏÖʵʵÑ飬ÒÔ»ñµÃ¶Ôϵͳ»Ø¸´Á¦µÄÐÅÐÄ£¬²¢×öºÃÓ¦¶ÔÊÂÎñµÄ×¼±¸¡£
Ò»¸ö¿ÆÑ§µÄÒªÁì°üÀ¨ÒÔϰ취£ºÌá³öÒ»¸öÕæÊµÎÊÌâ¡¢Ìá³ö¼ÙÉè¡¢¾ÙÐÐʵÑé¡¢½«ÊÓ²ìЧ¹ûÓëÕ¹ÍûÏà½ÏÁ¿£¬²¢Êä³ö±¨¸æÐ§¹û£¬»ùÓÚЧ¹ûÖØ¸´¡¢Ò»Ö±ÐÞÕýÄã¶ÔÏÖʵµÄÊìϤµÈ¡£ÄÇôʲôÊǾöÒéÊ÷ºÍÇå¾²»ìã繤³ÌÄØ£¿Çå¾²»ìã繤³Ì£¨SCE£©Ò»Ñùƽ³£Ê¹ÓÃinfosecµÄ¿ÆÑ§ÊµÑéÒªÁ죬ÏàʶϵͳÊÇÔõÑùÔËÐеģ¬Í¨¹ýÓÐÍýÏëµÄÂÄÀúʵÑé¡¢ÓÐÒâÒýÈëʧ°ÜµÈ£¬´´Á¢Ñ§Ï°ÎÄ»¯£¬·¢Ã÷ϵͳµÄÕæÊµÐÔ£¬Ìá¸ßϵͳµÄÇå¾²ÐÔ¡£¿ÉÊÇʵÑéÊÇÔÚ¼ÙÉèÖ®ºó¾ÙÐеģ¬ÄÇôÔõÑùÌá³ö¼ÙÉèÄØ£¿ÎÒÃDZØÐè¶ÔÏÖʵ×÷³ö¼ÙÉ裬ΪÎÒÃǵÄʵÑéÌṩÐÅÏ¢£¬ÔÚ³åÍ»µÄÇéÐÎÏ£¬»¹±ØÐè¶ÔµÐÊÖ×÷³ö¼ÙÉ裬¶ø¾öÒéÊ÷ÊÇ×îºÃµÄÒªÁ죬Ëüͨ¹ý¡°ÐÅÐļ¤Àø¡±×ÊÖúÈËÀàˢмÙÉ裬ÏàÊ¶ÌØ¶¨¹¥»÷Õß¡£Õâ¾ÍÊǾöÒéÊ÷ÓëÇå¾²»ìã繤³Ì¡£
ÔõÑùʹÓþöÒéÊ÷ÓëÇå¾²»ìã繤³Ì£¿Kelly Shortridg½â˵ÁËÒ»¸öÏêϸµÄ°¸Àý£¬Ê¹ÓþöÒéÊ÷ÓëÇå¾²»ìã繤³Ì£¬ÓÃÍêÕûµÄ¾öÒéÊ÷Ó³Éä³ö¹¥»÷Õß¿ÉÄܽÓÄɵÄÐж¯¹æÄ££¬ÆÊÎö¹¥»÷·¾¶£¬ÔÚÈÝÆ÷Öй¹½¨¹¥»÷Ê÷Òþ¿ó¹¤£¬ÇÀÕ¼¹¥»÷·¾¶µÄÏÈ»ú£¬¼Ó´ó¹¥»÷Ͷ×ʺÍÖØÆ¯ºó£¬´Ó¶øÈù¥»÷ÕßÖªÄѶøÍË¡£¾öÒéÊ÷¹¥»÷·¾¶Ó³ÉäÆÊÎöÂ߼ͼÈçÏ£º

×ܵÄÀ´½²£¬¾öÒéÊ÷ºÍÇå¾²»ìã繤³ÌÌṩһÖÖÑо¿¹¥»÷¼ÛÖµºÍÄ¿µÄ¼ÛÖµµÄ¿ÆÑ§ÒªÁìÂÛ£¬Í¨¹ýÃ÷È·×é֯ĿµÄ£¬¹¹½¨¹¥»÷Ä¿µÄÓÅÏȼ¶¾ØÕ󣬽ṹY-ÏìÓ¦=X-¼ÙÉèµÄ¹¥»÷º¯Êý£¬½¨ÉèSCEʵÑ飬ÐγÉеļ¡ÈâÓ°ÏóÀ´Ó¦¶ÔÍ»·¢ÊÂÎñ£¬Ê¹¹¥»÷ÊÂÎñ±äµÃÎÞÁÄ£¬Í¬Ê±ÈÃÎÒÃǵÄÄ¿µÄ×ʲú¸üÇå¾²¡£
07 Ñݽ²Ö÷Ì⣺¡¶¿ª·¢Ö°Ô±²»Ï²»¶Çå¾²µÄÊ®´óÔµ¹ÊÔÓÉÓë½â¾ö¼Æ»® ¡·
Ñݽ²ÕߣºChristopher J. Romeo£¨Çå¾²Ö®ÂÃCEO£©
DevSecOpsÊǹ¹½¨µ¯ÐÔÍøÂçÌṩÇå¾²ÄÜÁ¦µÄÖ÷ÒªÊÖÒÕÊÖ¶ÎÖ®Ò»£¬Christopher J. RomeoÒÔΪDevºÍSecµÄÅþÁ¬ÊǶϿªµÄ¡£¾¿ÆäÔµ¹ÊÔÓÉÔÚDevSecOpsÌìÏÂÖУ¬¿ª·¢Ö°Ô±³ÉΪÁËÇå¾²Ö°Ô±£¬µ«¿ª·¢Ö°Ô±²»ÏàʶÇå¾²£¬È´¾³£ÊµÑéÇ¿ÖÆÖ´ÐÐÁ÷³ÌºÍ¹¤¾ß¼¯£¬µ¼Ö¿ª·¢Ö°Ô±²»Ï²»¶Çå¾²Ïà¹ØÊÂÇ飬ÒÔÊÇDevºÍSecµÄÅþÁ¬ÊǶϿªµÄ¡£Christopher J. Romeo×ܽáÁË¿ª·¢Ö°Ô±²»Ï²»¶Çå¾²µÄÊ®¸öÔµ¹ÊÔÓÉÓë½â¾ö¼Æ»®£¬Ìá³öͨ¹ýÐ×÷ÎÄ»¯½â¾ö¿ª·¢Ö°Ô±²»Ï²»¶Çå¾²µÄÎÊÌ⣬ʮ¸öÔµ¹ÊÔÓÉÈçÏÂͼËùʾ£º

ÀýÈ磺ûÈ˽ÌÎÒÔõÑù¡°Çå¾²¡±µÄÎÊÌ⣬Christopher J. RomeoµÄ½â¾ö¼Æ»®ÊÇͨ¹ý׫д¡°ÔõÑù×ö¡±µÄÇå¾²Ö¸µ¼¡¢ÊÚȨÍŶӡ¢Íƹã½ÌÓýÈý²½½¨ÉèÇ徲ʵ¼ùÊÖ²áºÍÅàѵÍýÏë¡£×÷ÓýÐ×÷ÎÄ»¯¡¢ÌáÉýͬÀíÐÄ¡¢Ó뿪·¢Ö°Ô±Í¬ÔÚ¡¢ËæÊ±ÌýÈ¡¿ª·¢Ö°Ô±µÄÒâ¼û¡¢Ñ¯ÎÊËûÃÇÐèҪʲô×ÊÖúµÄ·´Ï죬²¢Öƶ©½ÌѧºÍÖ¸µ¼µÄ½â¾ö¼Æ»®£¬Óɴ˽â¾ö¿ª·¢Ö°Ô±µÄÄÑÌ⣬ÆäËû9¸öÔµ¹ÊÔÓÉChristopher J. Romeo¾ùÌṩÁËÀàËÆµÄ½â¾ö¼Æ»®¡£
×îºóChristopher J. RomeoÌá³öÐèÒªÕ¾ÔÚ¿ª·¢Ö°Ô±µÄ̬¶È¡¢Ó뿪·¢Ö°Ô±ÅäºÏÊÂÇéÒ»¶Îʱ¼ä£¬ÓëÖ®¹²Ê¶£¬½¨Ïë³ÌÐò»¯µÄÒªÁ죬ʵÑé½â¾ö¼Æ»®½â¾ö¿ª·¢Ö°Ô±ÓëÇå¾²µÄÖ÷Òª¹ØÏµ£¬Ê¹DevºÍSec½¨Éè׼ȷµÄÅþÁ¬¡£
- Òªº¦´Ê±êÇ©£º
- ×ðÁú¿Ê± RSA 2021 ÍøÂçÇå¾²¾Û»á