DevSecOps
Software Assurance Takes Center Stage at Developer Day
Cloud Security Alliance and SAFECode Develop Training for Improved Software Security Using Cloud and DevOps Practices Software assurance is one of the most important and possibly one of the least understood areas ...
It’s All About the Tools: Lifecycle Security and Testing
In the past, whenever a new application or a new version of an application was bought to market, users often were abused as beta testers for security and usability. This was largely ...
DEF CON: Where Have All the Black Hats Gone?
DEF CON is one of the most controversial conferences in the world. Only at that annual event have arrests been made, legal threats shut down presentations and zero-day attacks been anted in ...
Private Practice: Encryption Exposed
In September 2014, Apple made encryption a default with the introduction of the iPhone 6. Then, in February 2016, a Los Angeles judge issued an order to force Apple to help break ...
Dismantling Inefficiency: The DevOps Point of View
I recently caught up with Paula Thrasher, application delivery lead at CSC and DevOps pioneer in government circles. In our conversation, we discussed a number of important topics including cross-functional teams, software ...
3 Simple Steps to Rugged DevOps 101
As the CEO of WhiteSource, I regularly consult enterprises about building and enforcing their open-source security policies. In the course of my consultations, I discuss open-source security protocol with many software companies ...
DDoS Defense: Can You Tell Friend from Foe?
In many organizations, networks are at the core of the business, enabling not only internal functions such as human resources, supply chain and finance, but also the services and transactions the business ...
The DevOps Force Multiplier: Competitive Advantage + Security
Several years ago, DevOps started hitting the eyes of enterprise business leaders when news outlets such as The Wall Street Journal and Forbes began reporting that the IT culture and methodology was ...
How DevOps Can Help Improve Security
Automation and standardization along with development-inspired reviews can address the three top risks to IT security. The term “DevOps” these days tends to evoke images of automation and push-button application deployments whenever ...
Does Security Slow Down DevOps?
Since the primary goal of DevOps is to eliminate bottlenecks to increase a company's speed and efficiency, organizations tend to embrace new strategies that make DevOps even more efficient. However, when it ...
DevOps Security in Spotlight as Gartner Names vArmour Cool Vendor
News Reports vArmour CEO Eades Nabbed $41 Million Ahead of Trump Presidency In May, Gartner named 2016 Cool Vendors in several security categories. Given the focus of this column, I was interested ...
Lean Security: How Better Development Can Protect Your Business
If companies are to reach their strategic goals—reducing time to market, boosting sales, improving product market fit and brand image, and cutting cybersecurity costs—then it's time for a new outlook on software ...

