DevSecOps
Security automation with DevOps: show me the code!
Last week Andrew Storms put up a good post hinting at the promise of security automation in [SecDevOps: Security Automation By Example – The Firewall Change]. He included an example of automating ...
SecDevOps: Security Automation By Example – The Firewall Change
Security Automation By Example The Firewall Change Just when you thought DevOps was the new black, along comes SecDevOps. Yes folks, like most things in life, the new cool is already here ...
You have to crawl before you walk…
In previous posts I have explained what Security Policy Orchestration is, why DevOps folks should care, and how it can help facilitate the cultural change necessary for organizations to reap the long-term ...
DevOps: Security’s last best hope
Help us Obi Wan! The fact is that DevOps is security’s last best hope. The sooner the security industry realizes it the better it will be for everyone. I read George Hulme’s ...
Delivering Delight At ChefConf 2014
Chef CEO Barry Crist stirs the pot to open ChefConf 2014 The theme from ChefConf 2014 is stirring delight and if you listened to Barry Crist during todays opening keynote, then you ...
Trust and Computers Make the News
The Heartbleed bug in OpenSSL was major news this week. While you are waiting for sudo apt-get dist-upgrade to run on all your servers, let’s take a minute to reflect on how ...
Continuous integration for better security
One of the big advantages to smaller deploys and continuous integration is that it can make it easier to provide more proactive security. In short, continuous integration (and the associated automated testing ...
Using AWS CloudWatch for Anomaly Detection
Based on my unscientific poll of friends, one of the least used and most overlooked features of AWS is CloudWatch. Not only can CloudWatch be used to monitor the availability of your ...
How to un-domesticate your network: DevOps!
When I look at how compliance and regulations have affected network security over the years, I’m reminded of what dog breeder standards and regulations have done to dogs over the years. I’ll ...
Dev, Ops and Security Collaboration: Bring the body and the mind will follow
Complexity has a way of muddying even the clearest of waters, and this has certainly been the case with IT Operations. While Dev, Ops and Security teams share a common purpose, the ...
Trust & the trusted image
What is Your Trust Model? Information security conversations often start with the question “What is your threat model?” This blog asks: “What is your trust model?”. Trust is a complex subject and ...
Protect and Defend: Repositories
When you're creating work that gets deployed into production, there is typically a repository involved. It could be a code base, a deployment hub, a definitive software library, a library of VM ...

