Tag: security

Modern DevOps is a Chance to Make Security Part of the Process
I’ve mentioned before, and many of you have lived through, the slowly changing beliefs around DevOps versus security. We are past the days of “Security slows us down” and into “How can ...

DevSecOps Provides a Modern Security Model for Modernization
Developers and security experts are now tasked with bolstering, extending and adjusting cloud and Kubernetes security to protect against cyberattacks that are ever more complex, volatile, and frequent. To foil attacks and ...

FAA Ground Stop due to Technical Debt? | Don’t Do DIY Crypto!
In this week’s #TheLongView: The FAA’s NOTAM database gets corrupted, and Threema shows why DIY encryption is bad ...

Prioritizing Product Security With DevSecOps
Building software with strong security can no longer be an afterthought for organizations. The need for a reliable cybersecurity posture has proven vital amid the constant attacks we're seeing across industries, all ...

Implementing Shift Left Security in the Cloud
While ransomware has been the leading concern for enterprise security teams over the few past years, software vulnerabilities are nipping at its heels. The boom in cloud-based apps and services and increased ...

Faster and Better Testing?
The whole concept of Agile and DevOps was to iterate development faster and deliver results in a more timely manner. As we learned more about both methodologies, processes and policies were put ...

5 Tips for Securing DevOps: What You Wish You Knew Sooner
Foundations and frameworks, concrete and steel—not exciting. But that’s the foundation and framing of pretty much every modern building. Everything else that is part of a building–flooring, wiring, lighting, room placement and ...

Shift That [bleep] Left
Seriously. The more you can shift things like security and test to the left, the more responsive the DevOps process will be. Some things are better shifted right ... But only while ...

Where Does Your Data Go?
One of the most interesting developments in security and compliance in recent years is the ability to follow a piece of data through an application from input to consumption and see each ...

Keeping the DevOps Pipeline Flowing as Attack Surfaces Grow
The attack surfaces that today’s businesses and public entities must manage have never been more complex and difficult to protect. The introduction of cloud and SaaS offerings over the past decade has ...

What Developers Need for Software Security Success
Given today’s evolving threat landscape, organizations and businesses in every sector now have a critical need to produce secure software. Criminal gangs, professional attackers and hostile nation-states are employing advanced tactics designed ...

The Real Pipeline
I’ve made no secret of the fact that DevOps was a game-changing advance in how the business of IT was done. But people tend to get religious about the methodology and forget ...