DevSecOps
DevSecOps @RSAC, My 2 Favorite Presentations
For the third year, DevOps.com hosted a DevSecOps/Rugged DevOps event at RSA Conference. As with years before, we smashed attendance records. We had just shy of 900 people stop in on Monday ...
Securing Immutable Servers in a Serverless World
Snowflakes are beautiful, unique creations. But, let’s keep them in nature. They don’t belong in our server infrastructure. Snowflake servers, where every configuration is just a little different, can introduce unnecessary security ...
From a Commodore 64 to DevSecOps
We all know the story: a farm, a kid, a Commodore 64, and a modem maxing out at 300bps. A few unexpected phone bills later, and young Ian Allison is figuring out ...
Threat Protection Appliances: As Valuable to Security as Your Toaster
Nothing in the IT security community is as widely deployed and universally reviled as anti-virus. But, threat detection appliances, including intrusion prevention appliances, application firewalls and advanced threat protection appliances, should be ...
All Day DevOps: System Hardening with Ansible
The DevOps pipeline is constantly changing. Therefore, relevant security controls must be applied contextually. We want to be secure, but I think all of us would rather spend our time developing and ...
Ransomware will Double in 2017. Are you Prepared?
A recent report found that ransomware attacks quadrupled in 2016, and are likely to double in 2017. Not surprisingly, a research survey showed that 48 percent of organizations had been hit by ...
Security @ the Speed of DevOps Survey: Efforts Still Lag
Enterprises today are in a relentless race to digitize or die. If they don’t digitize business processes, services or internal workflows and their competitors do, they will be at a steep disadvantage—and ...
A Modern Database Backup and Recovery Checklist
Do you have single points of failure? How do you handle deduplication? These questions and more need consideration when you're dealing with database backup and recovery. Enterprises are quickly onboarding next-generation, mission-critical ...
Elasticsearch Ransomware Attacks Highlight Need for Better Security
Recently, reports surfaced that a large number of Elasticsearch servers fell victim to potential ransomware attacks. Ransomware is the type of malware a company doesn’t want on its systems or network. It ...
2017 Security Blogger Awards – Open for Voting!
It's another year, and another awards ceremony to come at the Security Blogger Meet-Up at RSA Conference in San Francisco. It's time to vote for your favorite blogs, which were selected solely ...
The Secure Developer Podcast: Continuous Security at Chef
Welcome to The Secure Developer, a podcast about security for developers, covering security tools and practices you can and should adopt into your development workflow. The Secure Developer is hosted by Guy Podjarny, ...
What the Current DDoS Landscape Means for DevOps
Businesses, governments, hospitals, schools, charities and even individuals—they’re all the same to a DDoS perpetrator. If you have a website, it’s likely to be targeted by a distributed denial of service (DDoS) ...

