DevSecOps
Lance Crosby’s Vision To Bring Scale, Speed and Security To Developers with StackPath
The last most of us heard from Lance Crosby we thought he was riding off to an island sunset, to bask in the glow of a very successful exit from SoftLayer. The ...
DevOps Lessons from the Dyn Attack Fiasco
Dyn's DNS servers suffered a major DDoS attack last week, slowing a host of major websites. Does the drive for DevOps automation increase the risk of similar attacks? Maybe, but it doesn't ...
Network Resilience and Security from A to Z
An observer watching a bunker shot by legendary pro golfer Gary Player was heard to say: “I’ve never seen anyone so lucky in my life.” The player retorted: “Yes, and the more ...
Empower Developers to Build Security into DevOps
Over the past 10 years, as more organizations have made the transition to DevOps, there has been a cultural shift in which security and development teams agree quality is a priority. Yet, ...
Fixing Flaws: Bridging InfoSec and DevOps
The Road to Creating More Secure Code and Interlocking two Traditionally Distinct Practices As DevOps continues to expand across verticals, including the financial and government sectors, security has become paramount in the ...
Top 5 DevOps Practices to Improve Security in Engineering
We’ve all been there ... A new application or feature needs to be deployed yesterday and the last thing anyone wants to do is address security requirements. On the flip side, the ...
Software Assurance Takes Center Stage at Developer Day
Cloud Security Alliance and SAFECode Develop Training for Improved Software Security Using Cloud and DevOps Practices Software assurance is one of the most important and possibly one of the least understood areas ...
It’s All About the Tools: Lifecycle Security and Testing
In the past, whenever a new application or a new version of an application was bought to market, users often were abused as beta testers for security and usability. This was largely ...
DEF CON: Where Have All the Black Hats Gone?
DEF CON is one of the most controversial conferences in the world. Only at that annual event have arrests been made, legal threats shut down presentations and zero-day attacks been anted in ...
Private Practice: Encryption Exposed
In September 2014, Apple made encryption a default with the introduction of the iPhone 6. Then, in February 2016, a Los Angeles judge issued an order to force Apple to help break ...
Dismantling Inefficiency: The DevOps Point of View
I recently caught up with Paula Thrasher, application delivery lead at CSC and DevOps pioneer in government circles. In our conversation, we discussed a number of important topics including cross-functional teams, software ...
3 Simple Steps to Rugged DevOps 101
As the CEO of WhiteSource, I regularly consult enterprises about building and enforcing their open-source security policies. In the course of my consultations, I discuss open-source security protocol with many software companies ...

