DevSecOps
Catch Emerging Security Risks Earlier by Leveraging Kubernetes Audit Logs
When a Kubernetes deployment suffers a security breach, it can be difficult for security teams to diagnose and identify the source of the intrusion and its impact. Each Kubernetes cluster may host ...
The DevOps Sweet Spot: Inserting Security at Pull Requests (Part 1)
Today’s organizations are increasingly benefiting from the modernization of the software development lifecycle (SDLC), including the adoption of cloud, DevOps, Agile methodologies, containers and more. Thanks to this modernization, organizations are innovating ...
Better Apps and Better Security When You Shift Left
Tens of thousands of people and hundreds of cybersecurity vendors descended on San Francisco at the end of April. While the RSA Conference was the primary draw, there are a number of ...
EP 2: DevSecOps and AppSec
In this second episode of our DevOps Unbound streaming broadcast on TechStrong TV and DevOps.com's sister site Digital Anarchist, Mitchell Ashley of ASG and Alan Shimel are joined by Caroline Wong, CSO ...
Tenable Allies With Datadog to Drive DevSecOps
Datadog and Tenable have teamed up to enable organizations to adopt best DevSecOps processes. Tenable CTO Renaud Deraison said his company is making the cybersecurity data it gathers via its Nessus vulnerability ...
The DevSecOps Landscape is Maturing — We Want to Hear About Your Journey
The race to out-innovate one’s competition has led to high performing organizations chasing increased deployment velocities but often ignoring the quality of parts being used to manufacture their applications. It was 2003 ...
Cybersecurity Fears May Drive Shift to Managed DevOps
Should organizations consider using a managed service for DevOps to keep their platforms up to date and secure? The recent disclosure of a vulnerability that would allow open source Jenkins continuous integration/continuous ...
DevSecOps: A Renewed Commitment to Secure Delivery, Part 2
If done right, DevSecOps eliminates the cultural roadblocks that often prevent organizations from getting IT security proactively involved with development and operations. Barriers are the last thing any organization should contend with ...
Synopsys Advances DevSecOps via IDE Plugin
Synopsys has extended the static application security testing (SAST) and software composition analysis (SCA) of the Code Sight plugin it makes available for integrated development environments (IDEs). The latest iteration of Code ...
What Is DevSecOps and How to Enable It on Your SDLC?
For the past three to four years, all the companies around the IT world have adopted agile and different application development methodologies that leverage the work for different departments or areas and ...
DevSecOps: A Renewed Commitment to Secure Delivery, Part 1
Security has never been as high a priority than it is today, as companies fear they’ll be the next headline, the next victim of a data breach. Executives also worry about applications ...
The Risks and Potential Impacts Associated with Open Source
Open source software (OSS) is built by communities of developers who contribute their knowledge and time to OSS projects they find appealing. That code can then be used by individuals, communities and ...

