DevSecOps
Alert Logic lends more agile, cloud-native security to DevOps architects
Amid the avalanche of research and product news emerging from this year’s Black Hat USA 2015 conference, held in Las Vegas this week, at least one vendor is attempting to advance a ...
The Software BOM Squad
In my previous post, "When Good Code Goes Bad", I shared new research showing the average large development organization consumes over 15,000 known vulnerable and defective components annually. While we can't stop ...
The Cost to DevOps: 27 Mufflers
Imagine Imagine that you are designing the 2016 Range Rover line of sport utility vehicles. Like all gas powered vehicles, each one needs an exhaust muffler. Range Rover likely has narrowed in ...
Bring Your Own Exploit
Here's a simple question: for each tool that your organization uses, have you (or someone else on your DevOps team) changed the default passwords? That should be a no-brainer, shouldn't it? Of ...
Security Breaks DevOps – Here’s How to Fix It
The concepts of communication, collaboration, abstraction, automation and orchestration are cornerstones of the rapidly growing DevOps movement. At the same time reliance on virtualized infrastructure and Infrastructure-as-a-Service has exploded, making manual provisioning ...
Stop whining about shadow IT and do something about it
Much has been written about shadow IT at the business unit and employee level where the proliferation of cloud applications has all but eliminated IT’s control over what applications are used in ...
Managing Open source software components
Building any software need lots of efforts including resources, time, money, etc. It is really a great pleasure when it goes live or gets released. In parallel, there is always a chance ...
2015 State of the Software Supply Chain Report
In April of this year, I embarked on a six-week journey diving deep into an analysis of the world’s software supply chains. I evaluated the practices of 106,000 organizations, the 100,000+ suppliers ...
Sleep easy: release automation reduces DevOps security threats
Sleep easy: release automation reduces DevOps security threats “Devops reigns”. “DevOps redefines the way services are launched and managed”. Just two of the recent headlines from the sea of coverage on DevOps ...
The devOpsSec Dilemma: Effective Strategies for Social Networking
I was sad to hear of the passing of John Nash and his wife Alicia this weekend. May they rest in peace. As a game theorist I am familiar with his work ...
DevOps Connect: Rugged DevOps @Infosecurity Europe
We have assembled another top flight list of speakers for our DevOps Connect event @Infosecurity Europe. While pre-registration is sold out, if you are one of the 15,000+ attendees of Infosecurity Europe, ...
What is Adaptive Security?
72 days after the fact AdultFriendFinder.com, a “very mature” dating site, realized they had been hacked. The VERY personal information of 3 million registrants has been held hostage. By now, it should be ...

