DevSecOps
Improving Security with Mapping, Automation and DevOps
Strong cybersecurity is paramount for every organization. But all too often, security teams are disconnected from ongoing development processes and viewed either as an impediment to bringing products to market or as ...
Accelerate Your SDLC With DevSecOps
DevOps has been the answer to rising software development complexity, but the granularity and multiplicity of actors, technologies and environments brings added security requirements. Moving to DevSecOps will not only help with ...
How to Build an Options-Based Observability Strategy
The global pandemic forced companies to accelerate their digital transformations, pushing them toward new technologies and architectures as they struggled to adapt to a changing world. Companies wanted fast development and deployment ...
Cycloid Tool Can Reverse Engineer Provisioned IaC
Cycloid this week unveiled a tool that makes it possible to reverse engineer code used to manually provision cloud infrastructure. The Infra Import tool is part of an effort to create a ...
12 Ways to Bake Security Into a DevOps Transformation
Security has become an integral part of any DevOps transformation. According to the Upskilling 2021: Enterprise DevOps Skills Report, DevSecOps achieved a must-have percentage vote of 56% in the automation tool category ...
WhiteSource Tool Automatically Fixes Code Vulnerabilities
WhiteSource today announced that it has developed the first-ever tool that automatically remediates vulnerabilities discovered in custom code. Rami Sass, WhiteSource CEO, said WhiteSource Cure surfaces recommendations for fixing security vulnerabilities in ...
JFrog, Vdoo Securing SecOps
Earlier this summer, JFrog acquired Vdoo to deliver end-to-end continuous security from development to device—is this what DevSecOps looks like? JFrog CEO Shlomi Ben Hami and Natenel Davidi, CEO of Vdoo, speak ...
Redefining Continuous Security for DevSecOps
In the mobile app development world, security often takes a backseat to developing features and delivering the app. In fact, the 2021 Verizon Mobile Security Index found that 45% of organizations sacrificed ...
CloudTruth Acquires Tuono to Advance Configuration Management
CloudTruth, a provider of a unified configuration management platform, today revealed it has acquired Tuono, a provider of a cloud secrets management platform, as part of an effort to make it simpler ...
Don’t Look at This! IT’S A SECRET!
To continue the discussion about secrets after perusing this excellent report by GitGuardian—last time I went a little nuts about the number of secrets exposed in IT folks' personal repositories. And it ...
Aqua Security Acquires tfsec to Advance DevSecOps
Aqua Security today announced it has acquired tfsec, an open source project that provides a static analysis scanner for infrastructure-as-code (IaC) that is designed to be integrated within a DevOps workflow. Amer ...
8 Security Considerations for CI/CD
In the software development enterprise, CI/CD refers to the combined practices of continuous integration and either continuous delivery or continuous deployment. CI/CD enables organizations to bridge the gap between development, operation activities ...

