DevSecOps
HashiCorp Extends Secrets Management Reach
Secrets management is core to DevSecOps—how credentials are managed can make all the difference in preventing an application from being compromised in the first place. The challenge is making it as simple ...
Early Automation: A Key Requirement for DevSecOps Success
According to the "2017 DevSecOps Community Survey," by Sonatype, almost 60 percent of the respondents consider security to be an inhibitor to DevOps agility, while more than 50 percent of developers say ...
Building a Solid Foundation for Microservices Security
It’s often true that threats evolve faster than development practices and technologies can keep up with, which can be seen in the current microservices approach to application development. While microservices bring clear ...
DevSecOps: Don’t Invest In Hope
A successful DevSecOps approach is rooted in action, not hope. There is a lot of investment in hope. I hope we won’t get breached. I hope our DevOps teams aren’t deploying thousands ...
Barracuda Networks Survey: DevSecOps Is Hard
Organizations that have adopted DevSecOps processes may be making progress when it comes to improving cybersecurity, but it’s far from easy. A survey of 618 IT decision-makers conducted by Dimensional Research on ...
Software Liability Goes Global
This month, France turned up the conversation on software liability for manufacturers who place known defective software components in their products. But, they are not the first. Software Liability in France According ...
DevSecOps: Digging into Root Cause Analysis
We have all been there in a postmortem when someone says, “Let’s get to the root of the problem.” And, we all know what that means: Who or what is to blame? ...
DevSecOps: Deception in Depth
Mantraps, tripwires and tarpits ... sounds like the start of a solid spy-movie plot, doesn’t it? These are among the many concepts of physical security that are making the crossover to software ...
Malicious Intent: Open Source Developers, Please Protect Your Users
For the second time in just a few weeks we’re seeing the fallout of missteps taken by publishers of open source components. It was just recently that I wrote about the GitHub id of ...
Security: How to Conduct an Agile Incident Postmortem
In a perfect world, every organization could block every attack, no employee would ever make a mistake, and there would be advance warning that an organization is on some cybercriminal's list of ...
Integrating Security into DevOps: The Benefits and Drawbacks
The efficiency of DevOps for your enterprise will depend on the level of security you integrate in it. The integration of security into DevOps is new to many enterprises, but is highly ...
DevSecOps: If You Build It, They Will Come
Spring training for Major League Baseball in the United States has begun. Millions of people share my love for baseball; however, the same can’t be said for security and compliance—well, at least ...

