SlideShare a Scribd company logo
1 of 31
Download to read offline
Singapore | 28 Feb - 01 Mar 2019
The journey of Digital
Transformation through
Devsecops in Banking Industry
NADIRA
Singapore | 28 Feb - 01 Mar 2019
Nadira Bajrei
IT Continuous Improvement and Knowledge Management
at Bank MandiriTbk
MIT from University of Indonesia,
IT Governance Specialist.
⁻ 9 years experience as a IT process and governance
⁻ 6 years experience in Banking Industry
⁻ Develop All IT process.
⁻ Integrated whole SDLC process through automation.
⁻ Built up internal community and become community
leader for agile and devops.
⁻ Bank Mandiri ChangeAgent for Devops Adoption
⁻ Built up Devsecops IndonesiaCommunity.
Email : bajrei.nadira@gmail.com
Linkedin: nadirabajrei
Singapore | 28 Feb - 01 Mar 2019
1
2
3
4
Background
Transformation Roadmap
DevSecOps Journey
Challenges
AGENDA :
Singapore | 28 Feb - 01 Mar 2019
Background1
Singapore | 28 Feb - 01 Mar 2019
What is digital transformation?
Integration of digital technology into all areas of a business,
fundamentally changing how you operate and deliver value to
customers. It’s also a cultural change that requires organizations to
continually challenge the status quo, experiment and
get comfortable with failure.
Singapore | 28 Feb - 01 Mar 2019
Engage customers through multiple channels
EnterThe Digitalization Era and Competition with Disruptor
Achieve OurVision 2020 ”Become Indonesia’s Best, ASEAN’s prominent”
Quickly respond to changing customer needs
WhyWe Need to doTheTransformation?
1
2
3
4
Digital BankingTransformation
Improve internal capabilities in many areas such as :
• IT Security, Availability & Reliability
• Digital and Infrastructure
• People, Process, Governance
Singapore | 28 Feb - 01 Mar 2019
Digital BankingTransformation – Business Function
Define the “Digital Banking Roadmap” to become customer – centric organization
2017
Mobile banking launched
2018- Improved Digital
Services
2020 - Be no.1 Digital
Banking Application
• Provide personalized and targeted offers to
specifics customer
• Drive digital onboarding process
• Offer Innovative services / features through
external collaboration
• Increasing service transaction
• Build Cashless ecosystem
• Fintech Collaboration
• Improve Internal Capabilities to
enable digital banking initiatives
• Build strong foundation in digital
capabilities
Singapore | 28 Feb - 01 Mar 2019
Transformation
Roadmap
2
Singapore | 28 Feb - 01 Mar 2019
Infuse agile devops culture and mindset in business and IT Leadership
and seek strong buy in and sponsorship to change.
Adopt right organizational structure to quickly incubate agile skills and
start piloting agile project
Start practicing agile with collaborative workspaces, business co-
ownership (Product Owner) and right sized governance
Start defining policies and procedures for Agile Methodology
Start build Devsecops architecture and automate everything
1
2
3
4
5
ProcessPeople Technology
Roadmap Plan( 2017-2020)
Singapore | 28 Feb - 01 Mar 2019
DevSecOps
Journey
3
Singapore | 28 Feb - 01 Mar 2019
DevOps will complementAgile Methodology to break the “silos” and achieve better Business-ITAlignment,
increased delivery certainty and faster speed to market and deliver more secure application.
WANTING
FLEXIBILITY
WANTING
CHANGE
WANTING
STABILITY
WANTING
SECURITY
Wall
Wall
Wall
Customers
Development
IT Operations
IT Security
 Create Flexibility
 Improve time to market
 Create effective change
 Add/Modify Features
 Create Stability
 Enhance services
 Create Security
 Enhance security
services
 Security as a code
Agile
DevOps
DevSecOps
Better Business - IT
alignment
Increased Delivery
Certainty
Faster Speed to
Market
Deliver more
Secure Application
1
2
3
4
Singapore | 28 Feb - 01 Mar 2019
BuildCode Integrate Test Deploy Release Operate
Agile Development
Continous Integration
Continous Delivery
Continous Deployment
Devops
Business
decision to
go live
Security as a code
Shift left security testing
DevSecOps
Singapore | 28 Feb - 01 Mar 2019
DevOps
Values
Culture
Automation
LeanMeasure
Sharing
Singapore | 28 Feb - 01 Mar 2019
C
Organizational culture is one of the strongest predictors of both
IT performance and overall performance of organization
We are to do shifting thought and Behaviors, Culture of Safe Failure and
also culture of Continous Improvement
FROM TO
1) IT Focus (Inside out)
2) Silos
3) Command & Control
4) Task Oriented
5) Blame
6) Reactive
7) Resistant
8) LowTrust
1) Customer Focus (Outside in)
2) Cross Functional
3) Self Organized & Collaboration
4) Outcome Oriented
5) Take Responsibility
6) Proactive
7) Flexible
8) HighTrust
Singapore | 28 Feb - 01 Mar 2019
Organization Structure
CIO
B
B1
C
C1
D
D1
SM PO
Dev
Team
SM PO
Dev
Team
SM PO
Dev
Team
UI/UX EA
Devops
Engineer
Other
SME
Stakeholder
Stream / Product A
Stream / Product B
Stream / Product C
Dedicated Team
Shared Team
 From Structural to Matrix
Structure
 Divided by stream/product
 Provide organic growth
Singapore | 28 Feb - 01 Mar 2019
AAdopting automation we avoid tools that enforce silos
What We Do? 1. Architect before automating
2. Assess our existing tools and
automation capabilities
3. Identify critical gaps
4. Seek vendor for POC
5. Automate high value and repetitive
work
6. Optimize workflow bottleneck
“Do not underestimate the effort and cost building toolchain from open source applications,
open source is not necessarily free, you need to modify the source fit to your needs”
Singapore | 28 Feb - 01 Mar 2019
Singapore | 28 Feb - 01 Mar 2019
Plan Operate
ObjectiveTools
DeployTestBuildDevelop
Agile - CI
Devsecops
Backlog
grooming,
define user
story,
burnt down
charts,
security
Requirement
Develop apps
and services
using version
control,
traceability,
and CI
Manage,
track and
document all
changes to
application
and
configuration
management
Automate test
script execution
including
regression, user
acceptance and
security
Deploy apps
and provision
environments
using
automation &
standardized
configurations
Measure
performance of
environment
and application
Singapore | 28 Feb - 01 Mar 2019
Continuous Integration – Continuous Delivery (CI/CD) Life Cycle
Singapore | 28 Feb - 01 Mar 2019
L
Muda -Waste
Simple statement to identify waste
“If you are not adding value , then you are adding waste”
How we eliminating waste?
 Start finishing stop starting or limit WIP (work in progress)
 Avoid hand-overs.
Mura - Reduce inconsistency
 Make everything as simple as possible
Muri – Overburden
Its represents the activities where processes, people, or
machines are pushed beyond a reasonable limit.
 Remove bottlenecks
Singapore | 28 Feb - 01 Mar 2019
 No Changes while development
2-speed IT / Bimodal IT
21
Initiation
Planning
Analysis & Design
Development
Implementation
Closure
Waterfall
 Evolving requirements and incremental
delivery
 Frequent changes and faster time to market
 Customer oriented products and get early
feedback
 Accommodate changes during development
Agile
 Clear expectation and fix requirement
 Minimal rate of changes
 Focus on application that required highest
stability
L
Singapore | 28 Feb - 01 Mar 2019
Discovery Workshop (2 Days)
 Agile Charter
PO-SM-DT-SME-BP-RR
2
1
Sprint Planning (4 hours)
 Sprint Goal
 Prioritize User Story
 Definition of Done
 Release Plan
PO-SM-DT
Sprint Execution (2 weeks)
 Specification Document
 Test Script & Unit Test Result
 Training Material
 PTO
 Nota Migrasi
SM-DT
4
Sprint Review (2 hours)
 Demo Result & Acceptance
PO-SM-DT-SME-BP-RR
5
Sprint Retrospective (2 hours)
 Minutes of Retrospective
PO-SM-DT
6
RCB
 Migration Approval
PO-SM-RCB Member
7
Migration
 Deploy to Prod
SM-Release Team
8
3
PO - Product Owner
SM - Scrum Master
DT – Development Team
SME – Subject Matter Expert
BP – Business Partner
RR – Risk Reviewer
Our Agile Approach
Daily Standup (15 minutes)
3 question :
• What you do yesterday
• What you do today
• What is impediment
SM-DT
3
L
Singapore | 28 Feb - 01 Mar 2019
Discovery
Workshop
Sprint Planning
Sprint
Execution
Daily Stand Up
Description Duration Who Involved
Defining user stories details, Plan to prepare
the supporting infrastructure, acceptance criteria
and also definition of done.
Sprint Review
Retrospective
2 Days
Product Owner, Scrum
Master, Development
Team, SME, Risk Reviewer
Determine the stories that match the definition of
ready to be prioritized and delivered in the next
sprint.
4 Hours
Product Owner, Scrum
Master, Development
Team, SME
Development Team,2 Weeks
Demo product increment, getting more feedback 2 Hours
Start developing and create product
increment
Development Team,
SM (opt)
15 Minutes
Align on three key questions within the team: what
did you do yesterday, what will you do today, and/or
are there any impediments?
Product Owner, Scrum
Master, Development
Team, SME
• Review the process from the last sprint: what went
well, what didn’t go well, what can we improve
• Identify action to improve collaboration
2 Hours
Scrum Master,
Development Team
Singapore | 28 Feb - 01 Mar 2019
Security within software lifecycle
VA/Pentest
Operate
Source code
review
Security Req. SIEM
Plan Develop Test Deploy
Security Hardening
Antivirus
Patch Management
Security Awareness
Security guy as SME
to build on the
mindset that
‘everyone
is responsible
for security’
with the goal of safely distributing security decisions at
speed and scale to those who hold the highest level of
context without sacrificing the safety required.
Singapore | 28 Feb - 01 Mar 2019
M
If you can’t measure, then you don’t know if you’re improving!
The essence of measure in DevOps, namely capture and review
your metrics / measurements and then take action.
Measure methods
Logging and Monitoring Strategy
There are a number of useful reliability KPIs that can be captured:
 MTTR (Mean Time To Recover/Restore)
 Change Fail rate
 % of Failed / Successful deployments
 Time in cycle
Singapore | 28 Feb - 01 Mar 2019
S
Community of Practices to provide sharing values in Devops
Agile
DevOps
Community
Infosec
Community
Cloud
Community
Data
Sciences
Community
Whatsapp or
Telegram Group
Formal or Informal
Meeting
SharedWeb Space 
I share / e-KMS
Benefits to
Members
Build professional network of similar interests
Access to expertise to seek help with work challenges
Nurture personal development and professional identity
Help to achieve meaningful work
Benefits to
Organization
Foster capability building
Enable knowledge sharing, retention, and reuse
Support synergy across units
Retention of talents
Singapore | 28 Feb - 01 Mar 2019
Our Community of Practices Activities - Sharing
Singapore | 28 Feb - 01 Mar 2019
Challenges4
Singapore | 28 Feb - 01 Mar 2019
Our Challenges
 Cultural Change – resistance to change
 Regulatory aspect (Internal audit, Risk and Compliance and also OJK)
Devops Benefits
 People disconnect between delivery and
application support
 Collaborations between delivery and
application support
 Work in silos  Drive integration, repetability & realibility
through automation
 Handover is slow and complex limiting
time to market
 Continous evaluation of practices and
tools
 People disconnect between delivery and
application support
 Collaborations between delivery and
application support
 Work in silos  Drive integration, repetability &
realibility through automation
 Handover is slow and complex limiting
time to market
Singapore | 28 Feb - 01 Mar 2019
Thank you
Keep CALMS
and
Do DevOps
Singapore | 28 Feb - 01 Mar 2019
Q n A5

More Related Content

What's hot

CI/CD Overview
CI/CD OverviewCI/CD Overview
CI/CD OverviewAn Nguyen
 
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSourceDevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSourceDevOps Indonesia
 
DevSecOps The Evolution of DevOps
DevSecOps The Evolution of DevOpsDevSecOps The Evolution of DevOps
DevSecOps The Evolution of DevOpsMichael Man
 
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOps
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOpsWashington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOps
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOpsBig Compass
 
Platform engineering 101
Platform engineering 101Platform engineering 101
Platform engineering 101Sander Knape
 
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream Flow
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream FlowLearn from the Experts: Using DORA Metrics to Accelerate Value Stream Flow
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream FlowDevOps.com
 
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Shifting Security Left - The Innovation of DevSecOps - ValleyTechConShifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Shifting Security Left - The Innovation of DevSecOps - ValleyTechConTom Stiehm
 
Dos and Don'ts of DevSecOps
Dos and Don'ts of DevSecOpsDos and Don'ts of DevSecOps
Dos and Don'ts of DevSecOpsPriyanka Aash
 
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...Amazon Web Services
 
Shift Left Security - The What, Why and How
Shift Left Security - The What, Why and HowShift Left Security - The What, Why and How
Shift Left Security - The What, Why and HowDevOps.com
 
Introduction to CI/CD
Introduction to CI/CDIntroduction to CI/CD
Introduction to CI/CDHoang Le
 
DOES SFO 2016 - Topo Pal - DevOps at Capital One
DOES SFO 2016 - Topo Pal - DevOps at Capital OneDOES SFO 2016 - Topo Pal - DevOps at Capital One
DOES SFO 2016 - Topo Pal - DevOps at Capital OneGene Kim
 
Agile Testing Framework - The Art of Automated Testing
Agile Testing Framework - The Art of Automated TestingAgile Testing Framework - The Art of Automated Testing
Agile Testing Framework - The Art of Automated TestingDimitri Ponomareff
 
ABN AMRO DevSecOps Journey
ABN AMRO DevSecOps JourneyABN AMRO DevSecOps Journey
ABN AMRO DevSecOps JourneyDerek E. Weeks
 

What's hot (20)

CI/CD Overview
CI/CD OverviewCI/CD Overview
CI/CD Overview
 
DevSecOps 101
DevSecOps 101DevSecOps 101
DevSecOps 101
 
DevSecOps - The big picture
DevSecOps - The big pictureDevSecOps - The big picture
DevSecOps - The big picture
 
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSourceDevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
DevSecOps Beginners Guide : How to secure process in DevOps with OpenSource
 
DevSecOps The Evolution of DevOps
DevSecOps The Evolution of DevOpsDevSecOps The Evolution of DevOps
DevSecOps The Evolution of DevOps
 
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOps
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOpsWashington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOps
Washington DC MuleSoft Meetup: CI/CD Pipeline with MuleSoft and Azure DevOps
 
Platform engineering 101
Platform engineering 101Platform engineering 101
Platform engineering 101
 
Benefits of DevSecOps
Benefits of DevSecOpsBenefits of DevSecOps
Benefits of DevSecOps
 
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream Flow
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream FlowLearn from the Experts: Using DORA Metrics to Accelerate Value Stream Flow
Learn from the Experts: Using DORA Metrics to Accelerate Value Stream Flow
 
DevSecOps
DevSecOpsDevSecOps
DevSecOps
 
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Shifting Security Left - The Innovation of DevSecOps - ValleyTechConShifting Security Left - The Innovation of DevSecOps - ValleyTechCon
Shifting Security Left - The Innovation of DevSecOps - ValleyTechCon
 
Dos and Don'ts of DevSecOps
Dos and Don'ts of DevSecOpsDos and Don'ts of DevSecOps
Dos and Don'ts of DevSecOps
 
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...
Why Users Are Moving on from Docker and Leaving Its Security Risks Behind (Sp...
 
Shift Left Security - The What, Why and How
Shift Left Security - The What, Why and HowShift Left Security - The What, Why and How
Shift Left Security - The What, Why and How
 
DevOps Best Practices
DevOps Best PracticesDevOps Best Practices
DevOps Best Practices
 
Scrum
ScrumScrum
Scrum
 
Introduction to CI/CD
Introduction to CI/CDIntroduction to CI/CD
Introduction to CI/CD
 
DOES SFO 2016 - Topo Pal - DevOps at Capital One
DOES SFO 2016 - Topo Pal - DevOps at Capital OneDOES SFO 2016 - Topo Pal - DevOps at Capital One
DOES SFO 2016 - Topo Pal - DevOps at Capital One
 
Agile Testing Framework - The Art of Automated Testing
Agile Testing Framework - The Art of Automated TestingAgile Testing Framework - The Art of Automated Testing
Agile Testing Framework - The Art of Automated Testing
 
ABN AMRO DevSecOps Journey
ABN AMRO DevSecOps JourneyABN AMRO DevSecOps Journey
ABN AMRO DevSecOps Journey
 

Similar to DevSecCon Singapore 2019: The journey of digital transformation through DevSecOps in the Banking industry

What organisations are doing to nurture and grow a culture of high-performance
What organisations are doing to nurture and grow a culture of high-performanceWhat organisations are doing to nurture and grow a culture of high-performance
What organisations are doing to nurture and grow a culture of high-performanceMarcio Sete
 
CWIN17 london digital ops model and transformation - max bocchini and ishit...
CWIN17 london   digital ops model and transformation - max bocchini and ishit...CWIN17 london   digital ops model and transformation - max bocchini and ishit...
CWIN17 london digital ops model and transformation - max bocchini and ishit...Capgemini
 
Presentation by lavika upadhyay
Presentation by lavika upadhyayPresentation by lavika upadhyay
Presentation by lavika upadhyayPMI_IREP_TP
 
auto-mobile-service-station.pdf
auto-mobile-service-station.pdfauto-mobile-service-station.pdf
auto-mobile-service-station.pdfarjungupta617621
 
Project Report on Employee Management System.docx
Project Report on Employee Management System.docxProject Report on Employee Management System.docx
Project Report on Employee Management System.docxDhineshkumarPrakasam
 
ROI Driven Digital Development
ROI Driven Digital DevelopmentROI Driven Digital Development
ROI Driven Digital DevelopmentRobbie Burns
 
Methodologies 1: Managing Agile Projects
Methodologies 1: Managing Agile ProjectsMethodologies 1: Managing Agile Projects
Methodologies 1: Managing Agile ProjectsInflectra
 
Methodologies 3: Using Spira for Waterfall
Methodologies 3: Using Spira for WaterfallMethodologies 3: Using Spira for Waterfall
Methodologies 3: Using Spira for WaterfallInflectra
 
Agile project management - a deep dive 2.2
Agile project management  - a deep dive 2.2Agile project management  - a deep dive 2.2
Agile project management - a deep dive 2.2Mohammad Faiz
 
Accelerating Business Growth with Agile Software Delivery.pdf
Accelerating Business Growth with Agile Software Delivery.pdfAccelerating Business Growth with Agile Software Delivery.pdf
Accelerating Business Growth with Agile Software Delivery.pdfSeasia Infotech
 
PMI-Oslo chapter: PMI-ACP & Agile contracts
PMI-Oslo chapter: PMI-ACP & Agile contractsPMI-Oslo chapter: PMI-ACP & Agile contracts
PMI-Oslo chapter: PMI-ACP & Agile contractsDidier Soriano
 
Project Requriement Management Vs Agile software development
Project Requriement Management Vs  Agile software developmentProject Requriement Management Vs  Agile software development
Project Requriement Management Vs Agile software developmentbizpresenter
 
Successful Agile Transformation - The NCS Story
Successful Agile Transformation - The NCS StorySuccessful Agile Transformation - The NCS Story
Successful Agile Transformation - The NCS StoryNUS-ISS
 
Tech reboot Jan All staff 2015 DRAFT 4
Tech reboot Jan All staff 2015 DRAFT 4Tech reboot Jan All staff 2015 DRAFT 4
Tech reboot Jan All staff 2015 DRAFT 4Rachel Murphy
 

Similar to DevSecCon Singapore 2019: The journey of digital transformation through DevSecOps in the Banking industry (20)

What organisations are doing to nurture and grow a culture of high-performance
What organisations are doing to nurture and grow a culture of high-performanceWhat organisations are doing to nurture and grow a culture of high-performance
What organisations are doing to nurture and grow a culture of high-performance
 
CWIN17 london digital ops model and transformation - max bocchini and ishit...
CWIN17 london   digital ops model and transformation - max bocchini and ishit...CWIN17 london   digital ops model and transformation - max bocchini and ishit...
CWIN17 london digital ops model and transformation - max bocchini and ishit...
 
Presentation by lavika upadhyay
Presentation by lavika upadhyayPresentation by lavika upadhyay
Presentation by lavika upadhyay
 
auto-mobile-service-station.pdf
auto-mobile-service-station.pdfauto-mobile-service-station.pdf
auto-mobile-service-station.pdf
 
Project Report on Employee Management System.docx
Project Report on Employee Management System.docxProject Report on Employee Management System.docx
Project Report on Employee Management System.docx
 
ROI Driven Digital Development
ROI Driven Digital DevelopmentROI Driven Digital Development
ROI Driven Digital Development
 
Munkhzorig - Digital Transformation
Munkhzorig - Digital TransformationMunkhzorig - Digital Transformation
Munkhzorig - Digital Transformation
 
Methodologies 1: Managing Agile Projects
Methodologies 1: Managing Agile ProjectsMethodologies 1: Managing Agile Projects
Methodologies 1: Managing Agile Projects
 
Methodologies 3: Using Spira for Waterfall
Methodologies 3: Using Spira for WaterfallMethodologies 3: Using Spira for Waterfall
Methodologies 3: Using Spira for Waterfall
 
Agile project management - a deep dive 2.2
Agile project management  - a deep dive 2.2Agile project management  - a deep dive 2.2
Agile project management - a deep dive 2.2
 
Accelerating Business Growth with Agile Software Delivery.pdf
Accelerating Business Growth with Agile Software Delivery.pdfAccelerating Business Growth with Agile Software Delivery.pdf
Accelerating Business Growth with Agile Software Delivery.pdf
 
PMI-Oslo chapter: PMI-ACP & Agile contracts
PMI-Oslo chapter: PMI-ACP & Agile contractsPMI-Oslo chapter: PMI-ACP & Agile contracts
PMI-Oslo chapter: PMI-ACP & Agile contracts
 
Agile Project Management.pptx
Agile Project Management.pptxAgile Project Management.pptx
Agile Project Management.pptx
 
Project Requriement Management Vs Agile software development
Project Requriement Management Vs  Agile software developmentProject Requriement Management Vs  Agile software development
Project Requriement Management Vs Agile software development
 
Resume July 2016
Resume July 2016Resume July 2016
Resume July 2016
 
Agile Development Process
Agile Development ProcessAgile Development Process
Agile Development Process
 
Successful Agile Transformation - The NCS Story
Successful Agile Transformation - The NCS StorySuccessful Agile Transformation - The NCS Story
Successful Agile Transformation - The NCS Story
 
Tech reboot Jan All staff 2015 DRAFT 4
Tech reboot Jan All staff 2015 DRAFT 4Tech reboot Jan All staff 2015 DRAFT 4
Tech reboot Jan All staff 2015 DRAFT 4
 
Resume
ResumeResume
Resume
 
Subhasis Mukherjee
Subhasis MukherjeeSubhasis Mukherjee
Subhasis Mukherjee
 

More from DevSecCon

DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...
DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...
DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...DevSecCon
 
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?DevSecCon
 
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...DevSecCon
 
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...DevSecCon
 
DevSecCon Seattle 2019: Containerizing IT Security Knowledge
DevSecCon Seattle 2019: Containerizing IT Security KnowledgeDevSecCon Seattle 2019: Containerizing IT Security Knowledge
DevSecCon Seattle 2019: Containerizing IT Security KnowledgeDevSecCon
 
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...DevSecCon
 
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...DevSecCon
 
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...DevSecCon
 
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...DevSecCon
 
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...DevSecCon
 
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...DevSecCon
 
DevSecCon Singapore 2019: Workshop - Burp extension writing workshop
DevSecCon Singapore 2019: Workshop - Burp extension writing workshopDevSecCon Singapore 2019: Workshop - Burp extension writing workshop
DevSecCon Singapore 2019: Workshop - Burp extension writing workshopDevSecCon
 
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscapeDevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscapeDevSecCon
 
DevSecCon Singapore 2019: Web Services aren’t as secure as we think
DevSecCon Singapore 2019: Web Services aren’t as secure as we thinkDevSecCon Singapore 2019: Web Services aren’t as secure as we think
DevSecCon Singapore 2019: Web Services aren’t as secure as we thinkDevSecCon
 
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...DevSecCon
 
DevSecCon Singapore 2019: Preventative Security for Kubernetes
DevSecCon Singapore 2019: Preventative Security for KubernetesDevSecCon Singapore 2019: Preventative Security for Kubernetes
DevSecCon Singapore 2019: Preventative Security for KubernetesDevSecCon
 
DevSecCon London 2018: Is your supply chain your achille's heel
DevSecCon London 2018: Is your supply chain your achille's heelDevSecCon London 2018: Is your supply chain your achille's heel
DevSecCon London 2018: Is your supply chain your achille's heelDevSecCon
 
DevSecCon London 2018: Get rid of these TLS certificates
DevSecCon London 2018: Get rid of these TLS certificatesDevSecCon London 2018: Get rid of these TLS certificates
DevSecCon London 2018: Get rid of these TLS certificatesDevSecCon
 
DevSecCon London 2018: Open DevSecOps
DevSecCon London 2018: Open DevSecOpsDevSecCon London 2018: Open DevSecOps
DevSecCon London 2018: Open DevSecOpsDevSecCon
 
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...DevSecCon London 2018: Building effective DevSecOps teams through role-playin...
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...DevSecCon
 

More from DevSecCon (20)

DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...
DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...
DevSecCon London 2019: Workshop: Cloud Agnostic Security Testing with Scout S...
 
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?
DevSecCon London 2019: Are Open Source Developers Security’s New Front Line?
 
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...
DevSecCon London 2019: How to Secure OpenShift Environments and What Happens ...
 
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...
DevSecCon London 2019: A Kernel of Truth: Intrusion Detection and Attestation...
 
DevSecCon Seattle 2019: Containerizing IT Security Knowledge
DevSecCon Seattle 2019: Containerizing IT Security KnowledgeDevSecCon Seattle 2019: Containerizing IT Security Knowledge
DevSecCon Seattle 2019: Containerizing IT Security Knowledge
 
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...
DevSecCon Seattle 2019: Decentralized Authorization - Implementing Fine Grain...
 
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...
DevSecCon Seattle 2019: Liquid Software as the real solution for the Sec in D...
 
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...
DevSecCon Seattle 2019: Fully Automated production deployments with HIPAA/HIT...
 
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...
DevSecCon Singapore 2019: Four years of reflection: How (not) to secure Web A...
 
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...
DevSecCon Singapore 2019: crypto jacking: An evolving threat for cloud contai...
 
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...
DevSecCon Singapore 2019: Can "dev", "sec" and "ops" really coexist in the wi...
 
DevSecCon Singapore 2019: Workshop - Burp extension writing workshop
DevSecCon Singapore 2019: Workshop - Burp extension writing workshopDevSecCon Singapore 2019: Workshop - Burp extension writing workshop
DevSecCon Singapore 2019: Workshop - Burp extension writing workshop
 
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscapeDevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
DevSecCon Singapore 2019: Embracing Security - A changing DevOps landscape
 
DevSecCon Singapore 2019: Web Services aren’t as secure as we think
DevSecCon Singapore 2019: Web Services aren’t as secure as we thinkDevSecCon Singapore 2019: Web Services aren’t as secure as we think
DevSecCon Singapore 2019: Web Services aren’t as secure as we think
 
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...
DevSecCon Singapore 2019: An attacker's view of Serverless and GraphQL apps S...
 
DevSecCon Singapore 2019: Preventative Security for Kubernetes
DevSecCon Singapore 2019: Preventative Security for KubernetesDevSecCon Singapore 2019: Preventative Security for Kubernetes
DevSecCon Singapore 2019: Preventative Security for Kubernetes
 
DevSecCon London 2018: Is your supply chain your achille's heel
DevSecCon London 2018: Is your supply chain your achille's heelDevSecCon London 2018: Is your supply chain your achille's heel
DevSecCon London 2018: Is your supply chain your achille's heel
 
DevSecCon London 2018: Get rid of these TLS certificates
DevSecCon London 2018: Get rid of these TLS certificatesDevSecCon London 2018: Get rid of these TLS certificates
DevSecCon London 2018: Get rid of these TLS certificates
 
DevSecCon London 2018: Open DevSecOps
DevSecCon London 2018: Open DevSecOpsDevSecCon London 2018: Open DevSecOps
DevSecCon London 2018: Open DevSecOps
 
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...DevSecCon London 2018: Building effective DevSecOps teams through role-playin...
DevSecCon London 2018: Building effective DevSecOps teams through role-playin...
 

Recently uploaded

[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxKatpro Technologies
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 

Recently uploaded (20)

[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 

DevSecCon Singapore 2019: The journey of digital transformation through DevSecOps in the Banking industry

  • 1. Singapore | 28 Feb - 01 Mar 2019 The journey of Digital Transformation through Devsecops in Banking Industry NADIRA
  • 2. Singapore | 28 Feb - 01 Mar 2019 Nadira Bajrei IT Continuous Improvement and Knowledge Management at Bank MandiriTbk MIT from University of Indonesia, IT Governance Specialist. ⁻ 9 years experience as a IT process and governance ⁻ 6 years experience in Banking Industry ⁻ Develop All IT process. ⁻ Integrated whole SDLC process through automation. ⁻ Built up internal community and become community leader for agile and devops. ⁻ Bank Mandiri ChangeAgent for Devops Adoption ⁻ Built up Devsecops IndonesiaCommunity. Email : bajrei.nadira@gmail.com Linkedin: nadirabajrei
  • 3. Singapore | 28 Feb - 01 Mar 2019 1 2 3 4 Background Transformation Roadmap DevSecOps Journey Challenges AGENDA :
  • 4. Singapore | 28 Feb - 01 Mar 2019 Background1
  • 5. Singapore | 28 Feb - 01 Mar 2019 What is digital transformation? Integration of digital technology into all areas of a business, fundamentally changing how you operate and deliver value to customers. It’s also a cultural change that requires organizations to continually challenge the status quo, experiment and get comfortable with failure.
  • 6. Singapore | 28 Feb - 01 Mar 2019 Engage customers through multiple channels EnterThe Digitalization Era and Competition with Disruptor Achieve OurVision 2020 ”Become Indonesia’s Best, ASEAN’s prominent” Quickly respond to changing customer needs WhyWe Need to doTheTransformation? 1 2 3 4 Digital BankingTransformation Improve internal capabilities in many areas such as : • IT Security, Availability & Reliability • Digital and Infrastructure • People, Process, Governance
  • 7. Singapore | 28 Feb - 01 Mar 2019 Digital BankingTransformation – Business Function Define the “Digital Banking Roadmap” to become customer – centric organization 2017 Mobile banking launched 2018- Improved Digital Services 2020 - Be no.1 Digital Banking Application • Provide personalized and targeted offers to specifics customer • Drive digital onboarding process • Offer Innovative services / features through external collaboration • Increasing service transaction • Build Cashless ecosystem • Fintech Collaboration • Improve Internal Capabilities to enable digital banking initiatives • Build strong foundation in digital capabilities
  • 8. Singapore | 28 Feb - 01 Mar 2019 Transformation Roadmap 2
  • 9. Singapore | 28 Feb - 01 Mar 2019 Infuse agile devops culture and mindset in business and IT Leadership and seek strong buy in and sponsorship to change. Adopt right organizational structure to quickly incubate agile skills and start piloting agile project Start practicing agile with collaborative workspaces, business co- ownership (Product Owner) and right sized governance Start defining policies and procedures for Agile Methodology Start build Devsecops architecture and automate everything 1 2 3 4 5 ProcessPeople Technology Roadmap Plan( 2017-2020)
  • 10. Singapore | 28 Feb - 01 Mar 2019 DevSecOps Journey 3
  • 11. Singapore | 28 Feb - 01 Mar 2019 DevOps will complementAgile Methodology to break the “silos” and achieve better Business-ITAlignment, increased delivery certainty and faster speed to market and deliver more secure application. WANTING FLEXIBILITY WANTING CHANGE WANTING STABILITY WANTING SECURITY Wall Wall Wall Customers Development IT Operations IT Security  Create Flexibility  Improve time to market  Create effective change  Add/Modify Features  Create Stability  Enhance services  Create Security  Enhance security services  Security as a code Agile DevOps DevSecOps Better Business - IT alignment Increased Delivery Certainty Faster Speed to Market Deliver more Secure Application 1 2 3 4
  • 12. Singapore | 28 Feb - 01 Mar 2019 BuildCode Integrate Test Deploy Release Operate Agile Development Continous Integration Continous Delivery Continous Deployment Devops Business decision to go live Security as a code Shift left security testing DevSecOps
  • 13. Singapore | 28 Feb - 01 Mar 2019 DevOps Values Culture Automation LeanMeasure Sharing
  • 14. Singapore | 28 Feb - 01 Mar 2019 C Organizational culture is one of the strongest predictors of both IT performance and overall performance of organization We are to do shifting thought and Behaviors, Culture of Safe Failure and also culture of Continous Improvement FROM TO 1) IT Focus (Inside out) 2) Silos 3) Command & Control 4) Task Oriented 5) Blame 6) Reactive 7) Resistant 8) LowTrust 1) Customer Focus (Outside in) 2) Cross Functional 3) Self Organized & Collaboration 4) Outcome Oriented 5) Take Responsibility 6) Proactive 7) Flexible 8) HighTrust
  • 15. Singapore | 28 Feb - 01 Mar 2019 Organization Structure CIO B B1 C C1 D D1 SM PO Dev Team SM PO Dev Team SM PO Dev Team UI/UX EA Devops Engineer Other SME Stakeholder Stream / Product A Stream / Product B Stream / Product C Dedicated Team Shared Team  From Structural to Matrix Structure  Divided by stream/product  Provide organic growth
  • 16. Singapore | 28 Feb - 01 Mar 2019 AAdopting automation we avoid tools that enforce silos What We Do? 1. Architect before automating 2. Assess our existing tools and automation capabilities 3. Identify critical gaps 4. Seek vendor for POC 5. Automate high value and repetitive work 6. Optimize workflow bottleneck “Do not underestimate the effort and cost building toolchain from open source applications, open source is not necessarily free, you need to modify the source fit to your needs”
  • 17. Singapore | 28 Feb - 01 Mar 2019
  • 18. Singapore | 28 Feb - 01 Mar 2019 Plan Operate ObjectiveTools DeployTestBuildDevelop Agile - CI Devsecops Backlog grooming, define user story, burnt down charts, security Requirement Develop apps and services using version control, traceability, and CI Manage, track and document all changes to application and configuration management Automate test script execution including regression, user acceptance and security Deploy apps and provision environments using automation & standardized configurations Measure performance of environment and application
  • 19. Singapore | 28 Feb - 01 Mar 2019 Continuous Integration – Continuous Delivery (CI/CD) Life Cycle
  • 20. Singapore | 28 Feb - 01 Mar 2019 L Muda -Waste Simple statement to identify waste “If you are not adding value , then you are adding waste” How we eliminating waste?  Start finishing stop starting or limit WIP (work in progress)  Avoid hand-overs. Mura - Reduce inconsistency  Make everything as simple as possible Muri – Overburden Its represents the activities where processes, people, or machines are pushed beyond a reasonable limit.  Remove bottlenecks
  • 21. Singapore | 28 Feb - 01 Mar 2019  No Changes while development 2-speed IT / Bimodal IT 21 Initiation Planning Analysis & Design Development Implementation Closure Waterfall  Evolving requirements and incremental delivery  Frequent changes and faster time to market  Customer oriented products and get early feedback  Accommodate changes during development Agile  Clear expectation and fix requirement  Minimal rate of changes  Focus on application that required highest stability L
  • 22. Singapore | 28 Feb - 01 Mar 2019 Discovery Workshop (2 Days)  Agile Charter PO-SM-DT-SME-BP-RR 2 1 Sprint Planning (4 hours)  Sprint Goal  Prioritize User Story  Definition of Done  Release Plan PO-SM-DT Sprint Execution (2 weeks)  Specification Document  Test Script & Unit Test Result  Training Material  PTO  Nota Migrasi SM-DT 4 Sprint Review (2 hours)  Demo Result & Acceptance PO-SM-DT-SME-BP-RR 5 Sprint Retrospective (2 hours)  Minutes of Retrospective PO-SM-DT 6 RCB  Migration Approval PO-SM-RCB Member 7 Migration  Deploy to Prod SM-Release Team 8 3 PO - Product Owner SM - Scrum Master DT – Development Team SME – Subject Matter Expert BP – Business Partner RR – Risk Reviewer Our Agile Approach Daily Standup (15 minutes) 3 question : • What you do yesterday • What you do today • What is impediment SM-DT 3 L
  • 23. Singapore | 28 Feb - 01 Mar 2019 Discovery Workshop Sprint Planning Sprint Execution Daily Stand Up Description Duration Who Involved Defining user stories details, Plan to prepare the supporting infrastructure, acceptance criteria and also definition of done. Sprint Review Retrospective 2 Days Product Owner, Scrum Master, Development Team, SME, Risk Reviewer Determine the stories that match the definition of ready to be prioritized and delivered in the next sprint. 4 Hours Product Owner, Scrum Master, Development Team, SME Development Team,2 Weeks Demo product increment, getting more feedback 2 Hours Start developing and create product increment Development Team, SM (opt) 15 Minutes Align on three key questions within the team: what did you do yesterday, what will you do today, and/or are there any impediments? Product Owner, Scrum Master, Development Team, SME • Review the process from the last sprint: what went well, what didn’t go well, what can we improve • Identify action to improve collaboration 2 Hours Scrum Master, Development Team
  • 24. Singapore | 28 Feb - 01 Mar 2019 Security within software lifecycle VA/Pentest Operate Source code review Security Req. SIEM Plan Develop Test Deploy Security Hardening Antivirus Patch Management Security Awareness Security guy as SME to build on the mindset that ‘everyone is responsible for security’ with the goal of safely distributing security decisions at speed and scale to those who hold the highest level of context without sacrificing the safety required.
  • 25. Singapore | 28 Feb - 01 Mar 2019 M If you can’t measure, then you don’t know if you’re improving! The essence of measure in DevOps, namely capture and review your metrics / measurements and then take action. Measure methods Logging and Monitoring Strategy There are a number of useful reliability KPIs that can be captured:  MTTR (Mean Time To Recover/Restore)  Change Fail rate  % of Failed / Successful deployments  Time in cycle
  • 26. Singapore | 28 Feb - 01 Mar 2019 S Community of Practices to provide sharing values in Devops Agile DevOps Community Infosec Community Cloud Community Data Sciences Community Whatsapp or Telegram Group Formal or Informal Meeting SharedWeb Space  I share / e-KMS Benefits to Members Build professional network of similar interests Access to expertise to seek help with work challenges Nurture personal development and professional identity Help to achieve meaningful work Benefits to Organization Foster capability building Enable knowledge sharing, retention, and reuse Support synergy across units Retention of talents
  • 27. Singapore | 28 Feb - 01 Mar 2019 Our Community of Practices Activities - Sharing
  • 28. Singapore | 28 Feb - 01 Mar 2019 Challenges4
  • 29. Singapore | 28 Feb - 01 Mar 2019 Our Challenges  Cultural Change – resistance to change  Regulatory aspect (Internal audit, Risk and Compliance and also OJK) Devops Benefits  People disconnect between delivery and application support  Collaborations between delivery and application support  Work in silos  Drive integration, repetability & realibility through automation  Handover is slow and complex limiting time to market  Continous evaluation of practices and tools  People disconnect between delivery and application support  Collaborations between delivery and application support  Work in silos  Drive integration, repetability & realibility through automation  Handover is slow and complex limiting time to market
  • 30. Singapore | 28 Feb - 01 Mar 2019 Thank you Keep CALMS and Do DevOps
  • 31. Singapore | 28 Feb - 01 Mar 2019 Q n A5