DevSecOps
Continuous Delivery: No Excuses
Jez Humble’s (@jezhumble) career has spanned roles through coding, infrastructure, and product development across three continents and organizations of varying sizes. To say he knows a lot about continuous delivery is a ...
DevSecOps: How Security Teams Can Better Support Their Developer Counterparts
Much of the conversation around digital transformation revolves around technology. But the new wave of technology this era has ushered in has also made a big impact on the way organizations, and ...
Chef Advances Compliance Automation
Chef today expanded the reach of its InSpec platform for automating compliance management with an update that adds support for Amazon Web Services (AWS) and Microsoft Azure public clouds, as well as ...
Survey: Not Much Compliance Progress in DevOps World
A survey of 1,500 customers conducted by Chef illustrates the lacking state of DevSecOps in the enterprise today, finding that nearly three-quarters of IT organizations still manually assess whether applications comply with ...
DevOps Brings Value to Security (and Vice Versa)
Many enterprises today are implementing security solutions that can be deployed and maintained more quickly and easily, and at lower cost, using a DevOps methodology. Organizations applying DevOps to security are not ...
GitLab Acquires Gemnasium to Advance DevSecOps
GitlLab, as part of its effort to extend the reach of its DevOps platform into the realm of security, has acquired Gemnasium, a provider of tools to mitigate vulnerabilities in open source ...
DevOps in the Cloud: Security’s Groundhog Day
Throughout the internet age, enterprise IT has given security a lower priority than qualities such as speed-to-deployment, scalability, availability and usability. We first saw this in the late 1990s and early 2000s, ...
DevOps Chat: ASRTM for DevOps with Rohit Sethi, Security Compass
In this DevOps/Security Boulevard Chat we speak with Rohit Sethi, COO of Security Compass about ASRTM, which stands for Application Security Requirements and Threat Management. Gartner has recently released a hype cycle ...
How Developers Can Take a More Proactive Approach to Security
Developers tend to get thrown under the bus when it comes to application security, but recent data shows that developers do, in fact, care about security. Take mitigation for example. Developers don’t ...
Predictions for DevOps Security in 2018
Automation continues to be a major driver of DevOps as a whole. In 2018, we’ll continue to see a shift in how and where automation is applied in the DevOps life cycle ...
Are Your Web Applications Prepared for the Holidays?
Three best practices to secure your website for the coming retail boom The holidays are upon us, which means retailers are racing to launch new promotions, sales and other temporary web pages ...
Moving Security Beyond SSH and PKI
SSH (secure shell) is still the most common method of remotely accessing a Linux server, which makes it a common target for attackers attempting to infiltrate corporate networks. While the protocol itself ...

