DevSecOps
DevSecOps: Digging into Root Cause Analysis
We have all been there in a postmortem when someone says, “Let’s get to the root of the problem.” And, we all know what that means: Who or what is to blame? ...
DevSecOps: Deception in Depth
Mantraps, tripwires and tarpits ... sounds like the start of a solid spy-movie plot, doesn’t it? These are among the many concepts of physical security that are making the crossover to software ...
Malicious Intent: Open Source Developers, Please Protect Your Users
For the second time in just a few weeks we’re seeing the fallout of missteps taken by publishers of open source components. It was just recently that I wrote about the GitHub id of ...
Security: How to Conduct an Agile Incident Postmortem
In a perfect world, every organization could block every attack, no employee would ever make a mistake, and there would be advance warning that an organization is on some cybercriminal's list of ...
Integrating Security into DevOps: The Benefits and Drawbacks
The efficiency of DevOps for your enterprise will depend on the level of security you integrate in it. The integration of security into DevOps is new to many enterprises, but is highly ...
DevSecOps: If You Build It, They Will Come
Spring training for Major League Baseball in the United States has begun. Millions of people share my love for baseball; however, the same can’t be said for security and compliance—well, at least ...
Continuous Delivery: No Excuses
Jez Humble’s (@jezhumble) career has spanned roles through coding, infrastructure, and product development across three continents and organizations of varying sizes. To say he knows a lot about continuous delivery is a ...
DevSecOps: How Security Teams Can Better Support Their Developer Counterparts
Much of the conversation around digital transformation revolves around technology. But the new wave of technology this era has ushered in has also made a big impact on the way organizations, and ...
Chef Advances Compliance Automation
Chef today expanded the reach of its InSpec platform for automating compliance management with an update that adds support for Amazon Web Services (AWS) and Microsoft Azure public clouds, as well as ...
Survey: Not Much Compliance Progress in DevOps World
A survey of 1,500 customers conducted by Chef illustrates the lacking state of DevSecOps in the enterprise today, finding that nearly three-quarters of IT organizations still manually assess whether applications comply with ...
DevOps Brings Value to Security (and Vice Versa)
Many enterprises today are implementing security solutions that can be deployed and maintained more quickly and easily, and at lower cost, using a DevOps methodology. Organizations applying DevOps to security are not ...
GitLab Acquires Gemnasium to Advance DevSecOps
GitlLab, as part of its effort to extend the reach of its DevOps platform into the realm of security, has acquired Gemnasium, a provider of tools to mitigate vulnerabilities in open source ...

