DevSecOps
What approach to application hardening is right for your organization?
There’s no shortage of readily available hacker tools and techniques and stories in the news about mobile app hacks for both the iOS and Android platforms. Fortunately, security solutions providers have responded ...
Combining SecOps and DevOps
Security has to be top of mind for most any company that is moving, or has moved, to the cloud. And, businesses know they need to act swiftly to ensure that any ...
Avoiding Common AWS Security Risks
According to IBM’s Cyber Security Intelligence Index, 95% of all security incidents involve human error. That's beyond significant, and when rapidly deploying multiple iterations in a DevOps shop, that means there are lots ...
AWS re:Invent – New Releases Drive Cloud Security Innovation
The recent AWS re:Invent conference in Las Vegas saw the release of several new AWS services for security. Some of these announcements such as AWS Web Application Firewall and AWS Inspector seemed to take ...
Upcoming SANS Webinar: Orchestrating Security in the Cloud
Organizations are increasingly migrating to cloud-based services to handle sensitive data and business processes, meaning security teams need to carefully review and understand what security controls are available to help protect them ...
Alert Logic Cloud Insight brings cloud-based security to your cloud infrastructure
One of the primary driving forces behind DevOps is its fluidity. There is a domino-effect that cascades from the developers who create the apps to the IT admins who deploy and administer ...
Alert Logic lends more agile, cloud-native security to DevOps architects
Amid the avalanche of research and product news emerging from this year’s Black Hat USA 2015 conference, held in Las Vegas this week, at least one vendor is attempting to advance a ...
The Software BOM Squad
In my previous post, "When Good Code Goes Bad", I shared new research showing the average large development organization consumes over 15,000 known vulnerable and defective components annually. While we can't stop ...
The Cost to DevOps: 27 Mufflers
Imagine Imagine that you are designing the 2016 Range Rover line of sport utility vehicles. Like all gas powered vehicles, each one needs an exhaust muffler. Range Rover likely has narrowed in ...
Bring Your Own Exploit
Here's a simple question: for each tool that your organization uses, have you (or someone else on your DevOps team) changed the default passwords? That should be a no-brainer, shouldn't it? Of ...
Security Breaks DevOps – Here’s How to Fix It
The concepts of communication, collaboration, abstraction, automation and orchestration are cornerstones of the rapidly growing DevOps movement. At the same time reliance on virtualized infrastructure and Infrastructure-as-a-Service has exploded, making manual provisioning ...
Stop whining about shadow IT and do something about it
Much has been written about shadow IT at the business unit and employee level where the proliferation of cloud applications has all but eliminated IT’s control over what applications are used in ...

