Containing Security: Integrating Security (DevSecOps) into Container Ecosystems

Thursday, May 02, 2024 | 11:45AM–12:30PM CT | Northstar Ballroom A, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel Session
Container technologies have permeated several common use cases in higher education IT, offering flexibility, scalability, and efficiency. This adoption has created a new target for malicious cyber actors due to potential vulnerabilities. This talk will draw from our experience working with IT organizations securing mission-critical workloads in containers at higher education institutions. It will present strategies to help guide IT organizations in constructing a secure container-based ecosystem, as well as technical details that offer tangible value for engineers responsible for ensuring its security. These recommendations will cover common sources of compromise as well as mitigation methods across the container ecosystem, including container orchestration systems, workloads (images, containers, pods), and CI/CD workflows for building container images. Examples in this talk will be derived primarily from Kubernetes and docker, but will be applicable to other container technologies as well.

Presenters

  • Gabe Tocci

    Sr. Consultant/Sr. Cloud Architect, Strata Information Group

Resources & Downloads

  • Containing Security Integrating Security into Container Ecosystems

    Updated on 7/26/2026