DevSecOps
Software Supply Chain Attacks: How to Disrupt Attackers
Supply chain attacks—compromising an organization via insecure components in its software supply chain—are a growing concern for organizations. Throughout the past three years, an increasing number of open source software package repositories ...
DevSecOps: 10 Best Practices to Embed Security into DevOps
For companies that employ the agile approach, DevOps seems like a natural extension. Traditionally, enterprises started with integration, development and test automation early in the product lifecycle. Gradually, the agile delivery team ...
API Security in DevOps: Are We Too Comfortable?
Postman performed its annual survey of developers, and as this survey and many other surveys have shown, developers are generally comfortable with the level of API security that their organization has implemented ...
Service Meshes: Improving Security, Delivery and Availability
Containerized microservices are taking over the software world. These services provide developers a way to quickly create and deploy cloud-native applications. However, containers aren’t perfect. Orchestrating and managing container deployments can be ...
Certificates a Fly in the DevOps Ointment
The way cybersecurity teams have managed certificates is turning out to be a major impedance that could best be addressed by more organizations adopting best DevSecOps practices in 2020. A survey of ...
Breaking Down the OWASP API Security Top 10, Part 2
Due to the widespread usage of APIs, and the fact that attackers realize APIs are a new attack frontier, the OWASP API Security Top 10 Project was launched. From the beginning, the ...
Secure Your Network: How to Integrate EDR and DevOps
DevOps and Endpoint Detection and Response (EDR) solutions converge when no human element is required while deploying applications or detecting the threat and executing preventive measures. In this article, I am evaluating ...
Best of 2019: Breaking Down the OWASP API Security Top 10, Part 1
As we close out 2019, we at DevOps.com wanted to highlight the five most popular articles of the year. Following is the fifth in our weeklong series of the Best of 2019 ...
Best of 2019: The Time Has Come for an Engineering Approach to DevOps
As we close out 2019, we at DevOps.com wanted to highlight the five most popular articles of the year. Following is the third in our weeklong series of the Best of 2019 ...
Predictions 2020: Infrastructure and Ops Trends to Watch in 2020
Today, modernizing systems is more than simply moving technology to a new location. It requires an IT stack of a new generation of technologies and tools to work. As we head into ...
CNCF Graduates TUF Project to Secure Software Updates
The Cloud Native Computing Foundation (CNCF) announced today that an open source specification for securing software update systems has graduated to becoming a top-level project. The Update Framework (TUF) is made up ...
Synack: DevSecOps Being Accelerated by Cultural Shifts
The 2020 State of Compliance and Security Testing Report from cybersecurity testing platform vendor Synack claims that some of the world's largest organizations are encountering a significant cultural shift within their development ...

