DevSecOps
Managing Open source software components
Building any software need lots of efforts including resources, time, money, etc. It is really a great pleasure when it goes live or gets released. In parallel, there is always a chance ...
2015 State of the Software Supply Chain Report
In April of this year, I embarked on a six-week journey diving deep into an analysis of the world’s software supply chains. I evaluated the practices of 106,000 organizations, the 100,000+ suppliers ...
Sleep easy: release automation reduces DevOps security threats
Sleep easy: release automation reduces DevOps security threats “Devops reigns”. “DevOps redefines the way services are launched and managed”. Just two of the recent headlines from the sea of coverage on DevOps ...
The devOpsSec Dilemma: Effective Strategies for Social Networking
I was sad to hear of the passing of John Nash and his wife Alicia this weekend. May they rest in peace. As a game theorist I am familiar with his work ...
DevOps Connect: Rugged DevOps @Infosecurity Europe
We have assembled another top flight list of speakers for our DevOps Connect event @Infosecurity Europe. While pre-registration is sold out, if you are one of the 15,000+ attendees of Infosecurity Europe, ...
What is Adaptive Security?
72 days after the fact AdultFriendFinder.com, a “very mature” dating site, realized they had been hacked. The VERY personal information of 3 million registrants has been held hostage. By now, it should be ...
The #1 trick DevOps shops use to reduce vulnerabilities
A new report out this week highlights how important it is to find ways to fold in vulnerability assessment information into the software development lifecycle. Released by WhiteHat Security, the Website Statistics ...
DevOps Leadership Series: Security at Velocity
If it does not fit, it does not get done. For many DevOps practices, application security falls into the “does not get done” bucket. That’s because for many DevOps-centric organizations, application security ...
The DevOps and Security Manifesto
Early in Illumio’s history, I saw the future of DevOps security. The CISO of an electronics manufacturer brought us in to help secure a new support service that was built entirely in ...
DevOps Leadership Series: Software Supply Chains
We kicked off this series on Monday with Gene Kim (@RealGeneKim) sharing his views on the big theme for DevOps in 2015: proving that DevOps is applicable for large organizations. Another theme that arose ...
It’s time security pros shake their DevOps fear, uncertainly, and doubt
There’s been considerable discussion recently about how to make certain good security practices remain integrated within DevOps-driven environments. To get the scoop from a security pro who is experienced working on delivering ...
Swim in the DevOps pool or drown in security problems
There has been a significant shift recently in security. Most security vendors and organizations recognize that the traditional model of keeping the bad guys out by detecting malicious exploits is flawed at ...

