Loading…
November 8-10 | Lake Tahoe, California
View More Details

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for the Linux Foundation Member Summit 2022 to participate in the sessions.

Please note that the schedule is subject to change.
Wednesday, November 9 • 4:15pm - 4:45pm
Open Source Control Harmonization and Automating Compliance - Zeal Somani, Google LLC & Ann Wallace, Shopify

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Is it possible to make cloud compliance fun and less stressful? The main reason why cloud adoptions stall is due to lack of unified view on cloud controls and risks. A lot of enterprises today experience control sprawl because they operate in a mix of public and private cloud. The old way of doing compliance audits is to manually gather evidence once or twice a year and hope nothing bad is found during your audit. In this talk, we’ll go over the concepts of control harmonization and controls automation, and how to apply this to your current DevSecOps program. Zeal will talk about how the control harmonization efforts around Open Security Controls Assessment Language (OSCAL) that can be used to create automated control based assessments. Lastly, Ann will walk through how Shopify uses OSS tools to achieve continuous compliance at scale. You will walk away from this session with information on how you can make compliance fun or at least less painful.

Speakers
avatar for Zeal Somani

Zeal Somani

GRC Lead, JupiterOne
Zeal has 10+ years of experience in security, compliance and open source. She is well versed in infrastructure, automation, security and compliance for frameworks like PCI DSS, NIST 800-53, ISO 27001, FedRAMP, HTRUST, and privacy regulations such as HIPAA, GDPR, CCPA - both as an... Read More →
avatar for Ann Wallace

Ann Wallace

Senior Security Engineering Manager, Shopify
Ann Wallace (she/her) leads compliance & risk teams at Shopify. Prior to Shopify, she worked at Google leading the go to market efforts for Security Solutions. She also set and ran the Global Security Practice that created Google Cloud's first set of professional services offerings... Read More →



Wednesday November 9, 2022 4:15pm - 4:45pm PST
Grand Sierra Ballroom A