DevSecOps
Continuous integration for better security
One of the big advantages to smaller deploys and continuous integration is that it can make it easier to provide more proactive security. In short, continuous integration (and the associated automated testing ...
Using AWS CloudWatch for Anomaly Detection
Based on my unscientific poll of friends, one of the least used and most overlooked features of AWS is CloudWatch. Not only can CloudWatch be used to monitor the availability of your ...
How to un-domesticate your network: DevOps!
When I look at how compliance and regulations have affected network security over the years, I’m reminded of what dog breeder standards and regulations have done to dogs over the years. I’ll ...
Dev, Ops and Security Collaboration: Bring the body and the mind will follow
Complexity has a way of muddying even the clearest of waters, and this has certainly been the case with IT Operations. While Dev, Ops and Security teams share a common purpose, the ...
Trust & the trusted image
What is Your Trust Model? Information security conversations often start with the question “What is your threat model?” This blog asks: “What is your trust model?”. Trust is a complex subject and ...
Protect and Defend: Repositories
When you're creating work that gets deployed into production, there is typically a repository involved. It could be a code base, a deployment hub, a definitive software library, a library of VM ...
Hacking Your Auditor
No, not that kind of hacking, give me a little credit... Recently I was having a conversation with a consulting friend about DevOps, and he found himself in a bit of a ...
Logging Wins for Devops and Security
Its always great when companies can invest in tools that serve multiple groups and purposes. Ensuring proper setup and use of logs is one toolset that can serve both DevOps and Security ...
Organizational Dysfunction: The original vulnerability
During your teenage years, you may have figured out a way to get a ‘yes’ from your parents by playing off of the responsibility and knowledge gap between them…walking up to your ...
What is Security Policy Orchestration and Why Should DevOps Teams Care?
After attending the DevOps day I wrote about in my last post, I wanted to take a minute to explain exactly what Security Policy Orchestration actually is so we can begin to ...
DevOps and Security Are Compatible
When I speak with information security organizations faced with the prospect of moving to DevOps, one of the most common fears I hear is that this transition will degrade security of infrastructure ...
It’s the Outbound Stupid!
As nice as the word "Egress" may sound, I like "Outbound" better. Outbound is hardcore firewalling for the traffic that was initiated on the "trusted" side of the firewall, and is destined OUT to ...

