Hasan Yasar

Hasan Yasar

Technical Director, Teaching Professor

Pittsburgh, Pennsylvania, United States

Actions

Hasan Yasar is the Sr Technical Director of the Rapid Fielding of High Assurance Software group at the Software Engineering Institute (SEI) of Carnegie Mellon University (CMU). In this role, he leads an engineering group dedicated to enabling, accelerating, and assuring digital transformation at the "speed of relevance." He leverages SRE, DevSecOps, Agile, Lean, AI/ML, and other emerging technologies to architect smart, secure software platforms and pipelines. With over 25 years of experience, Hasan has served as a senior security engineer, software architect, and manager across all phases of secure software development. He is also a Teaching Professor at CMU’s Heinz College and the School of Computer Science (Software and Societal Systems), where he currently teaches Software and Security and DevOps for Engineering Secure Development and Deployment. Hasan actively contributes to international standards development with IEEE, ISO, The Open Group, and NIST. He recently co-authored the IEEE 2675 DevOps standard and is currently involved in shaping IEEE 828 (Configuration Management), IEEE 982.1 (Software Reliability), and ISO Working Group 29 (Agile and DevOps). Additionally, he serves as Vice Chair of The Open Group Security Forum, establishing standards to build a safer digital world.

Area of Expertise

  • Information & Communications Technology

Topics

  • DevOps
  • DevSecOps
  • AppSec
  • DevOps & Automation
  • Agile Methodologies
  • SRE
  • Testing
  • Software testing
  • Agile Testing
  • deployment
  • App Deployment
  • Dependency Injection
  • SBOM

How to solve technical dept in AI System development with DevOps?

Growing interest in development AI systems also brings some challenges besides data models, such as technical dept, deployment of the AI system timely. Statistically, more than 65% of companies are taking longer than a month to deploy a developed model. There is a huge knowledge gap in understanding how foster collaboration between data science teams and other stakeholders. The purpose of collaboration is to evolve the model and maintain the AI system relevant to a user’s need. However, there are challenges which are hidden feedback loops, configuration management complexity, data dependencies, and end-2-end development pipeline. These challenges can be overcome with common DevOps practices including continuous feedback and continuous integration and deployment. We may call it MlOps or something, but the root of the solution is DevOps.

Continuous Verification & Validation of Critical Software via DevOps

The current challenges to verification and validation of building the right system for fast paced deployment cycle from difficultly of specifying software quality attributes to effectively monitoring artifacts on each phase of software development. We continuously face two questions for V&V: “1. Are we building the right system?" and "2. Are we building the system right?". Although these questions seem distinct, they depend on one another. To answer them correctly it requires planning and exercising various V&V activities. However, it is very challenging when it is done siloed processes or practices. The approach is: V&V should be integrated into system lifecycle process by utilizing continuous integration/delivery (CICD) practices (aka DevOps) for Continuous Verification and Validation of each systems’ feature from inception to production.

Expanding DevOps to Embedded Systems: Lessons Learned!

DevOps practices have become a standard option for entities seeking to streamline and increase comprehensive participation by all stakeholders in their secure Development Lifecycle (SDLC). In most cases in industry, academics, and government, applying DevOps is a straightforward process. There is a subset of entities in these three sectors where applying those practices and principles is challenging. One of these entities is an embedded system as challenged by HW/SW integration for various reasons. The most often being general security and difficulties of early integrations where software and hardware development are executed concurrently as a complete system development effort fully supported by proven DevOps principles. Overall, the key idea is to develop program, performance, security and quality metrics that are critical to a successfully executed software and embedded systems development project; introduce frequent synchronization points throughout software and hardware development cycles; make embedded systems development synchronization with software development practical for complex system’s use; and develop applicable tools to support the synchronization process for a modern software and embedded systems development project.

Continuous ATO: Myth or Reality

Continuous ATO is another overloaded term that folks really don't fully understand. From cyber requirements to automations to process repeatability, CATO can be achieved if organizations understand what's involved.

Hasan Yasar

Technical Director, Teaching Professor

Pittsburgh, Pennsylvania, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top