DevSecOps
GitLab Presses Case for DevSecOps Collaboration
GitLab today at its GitLab Commit Virtual event pledged to make securing its open source continuous integration/continuous delivery (CI/CD) platform a more collaborative effort. Cindy Blake, senior security evangelist for GitLab, said ...
TechStrong TV: How strongDM Helps mParticle in Secure Remote Access
In this interview for TechStrong TV, I am joined by strongDM CEO Elizabeth Zalman and mParticle CISO Dave Anderson. Dave shares with us how mParticle uses strongDM proxy services to rapidly enable ...
DevOps and Compliance: A Recipe for Success
In today’s world, DevOps and compliance teams need to work together, not separately Imagine this: You organized a dinner party weeks ago, promptly forgot about it and just realized tonight’s the night! ...
7 Things to Make DevSecOps a Reality
While talking about DevSecOps has become a hot trend, it is clear that many organizations claiming to follow such methodologies are actually mired in traditional waterfall development. Let’s figure out if you’re ...
DevSecOps and Passwords: Lessening the Burden
The point of DevOps is to make IT more responsive (and hopefully more stable, but we have evidence that is not always the case). The point of DevSecOps (so far) is to ...
Accurics Adds Compliance Control Support to Code Analyzer
Accurics, at the online KubeCon + CloudNativeCon 2020 conference today, launched an update to its open source Terrascan static code analyzer that adds support for Open Policy Agent (OPA) engine to make ...
Why Service Meshes Are Security Tools
Are service meshes overhyped, or do they solve a real puzzle for enterprise IT systems? Service meshes are a relatively new technology, and many people have found it challenging to fit them ...
Functional Safety in Embedded Design Starts with Code Development
With embedded software likely to become more complex, now is the time to start thinking about functional safety As the world has become increasingly more dependent on embedded systems in functional safety ...
DevOps and Security in a Cloud-Native World
DevOps teams have naturally embraced microservices and modern application delivery workflows. But, they may get pushback from risk-averse leadership or feel slowed by security teams who struggle to keep pace. Development teams ...
Survey: Organizations Knowingly Deploy Vulnerabilities
A survey published today by Synopsys, a provider of electronic design automation (EDA) and application security tools, finds nearly half (48%) of respondents admit they consciously push code with known vulnerabilities into ...
Automation: The Human-Free Zone Approach to Software
Humans hate repetitive manual tasks. We suck at them—we make mistakes, lose concentration, get bored. Throughout history, humans have instinctually developed automation to keep us away from the hazard-prone, tedious work of ...
MuseDev Offers DevOps-Optimized Security Code Analyzer
MuseDev today announced it has made available on GitHub under an early access program a code analysis tool dubbed Muse that is designed to surface cybersecurity issues as pull requests are made ...

