DevSecOps: Where DevOps and Security Meet

Source – devops.com The DevOps methodology as a software and engineering culture goes back nearly 10 years—Patrick Debois coined the term when he named a Belgian software conference “devopsdays.” Since then, the movement has taken on a mind of its own, turning into the go-to strategy for enterprises the world over aiming to accelerate their development timelines and deliver better products faster. In the shifts and changes that have happened over the last decade, one has been the idea of “DevSecOps,”

Read more

ENABLING DEVOPS WITH A BETTER SECURITY STRATEGY

Source – datacenterjournal.com Survey data from Qualia suggests that as DevOps becomes mainstream, both organizational resources and budget allocation tied to measurable business outcomes will be attached to this method of rapid application development. DevOps enables a faster iterative process that drives innovation while doing more with less and increasing efficiency. It’s all a productive, well-oiled machine—until the security or auditing team arrives. When that happens, the challenging yet manageable pace is bogged down with additional (perceived unnecessary) impediments to getting the job

Read more

How DevOps can use smart data to protect against security risk

Source – devopsonline.co.uk As businesses everywhere undergo a digital transformation, the hybrid cloud has become a key component of success. Organisations around the world are moving applications and services workloads to the cloud, and reaping the benefits of lowered CAPEX, OPEX, and quicker time to market with new services as a result. The role of DevOps in capitalising on these benefits has become increasingly important, with developers and IT operations now working together closer than ever in an effort to continuously

Read more

What is devsecops and why should your business care?

Source – techcentral.ie Although tacking on another three letters to the already heavily abbreviated ‘devops’ has the uncomfortable aura of word soup, ‘devsecops’ is a logical, essential continuation of the devops mindset. Devops is loosely defined as the process of breaking down silos within organisations so that developer and operations teams are working side by side, and using automation wherever possible, with the aim of working towards common goals and releasing better, more stable software at speed. Bringing security into that

Read more

DevSecOps: How to conquer 3 big culture challenges

Source – enterprisersproject.com Just about any DevOps shop will hit speed bumps on the path toward continuous learning and improvement. “Organizations are increasingly adopting DevOps environments in hopes of achieving transformative velocity and innovation,” says Elizabeth Lawler, VP of DevOps security at CyberArk. “But like any new business initiative, this comes with challenges – and in the case of DevOps, it’s often around culture and areas of responsibility.” Even issues that seem technical in nature are often rooted in people. Take security: It’s as

Read more

Agencies Should Look Beyond DevOps to DevSecOps

Source – meritalk.com As Federal agencies adopt DevOps practices to shorten development cycles and increase deployment frequency, security must be interwoven into every aspect of the process from design, through coding, testing, release, and operation. DevOps, a moniker that is a combination of development and operations, is now morphing into DevSecOps as organizations and security professionals rethink how they develop, manage, and secure applications. A primary goal of DevSecOps is to break down barriers and open collaboration between development, security, and

Read more

How the new developer culture dictates development security

Source – sdtimes.com The 24×7 digital economy is requiring many organizations to release apps and application updates on a near-continuous basis in order to keep up with increasing customer demand—or face being left in the dust by competitors. Developer teams have their hands full trying to deliver functional, feature-rich updates on time. In this hyper-competitive environment, security is often too easy to deprioritize when faced with the pressure to get an app out the door. The rising trend of breaches from

Read more

When AI meets DevOps: Getting the best out of both worlds

Source – cloudcomputing-news.net DevOps has been widely embraced by businesses under pressure to get competitively advantageous digital deliverables to market at the fastest possible cadence—especially given the reality of limited coder headcount and the need to rigorously avoid brand-toxic snafus in the customer experience. Artificial intelligence (AI), in stark contrast, is a potentially transformative digital discipline that is still very new to most enterprise IT organizations. But while it’s certainly important that CIOs nurture AI adoption with appropriately resourced pilots, it’s

Read more

DevSecOps: 3 ways to bring developers, security together

Source – enterprisersproject.com Applications are the heart of the digital business, with code central to the infrastructure that powers it. In order to stay ahead of the digital curve, organizations must move fast and deploy code quickly, which unfortunately is often at odds with stability and security. With this in mind, where and how can security fit into the DevOps toolchain? And, in doing so, how can we create a path for successfully deterring threats? As DevOps continues along its path

Read more

The 5 Common Mistakes Your Devops Team is Making

Source – whitesourcesoftware.com DevOps has become an important and inseparable part of every business today. The rise of DevOps has meshed the development and operations teams together, largely contributing to the faster development and deployment of software. Despite the most obvious problems that DevOps solves, there are a few common mistakes that DevOps teams and their organizations continuously commit while working together to deliver the companies’ products. We have chosen to highlight the 5 most common mistakes your DevOps team is

Read more

Speed and Security Can Coexist in Mainframe DevOps

Source – devops.com DevOps teams face a constant tug-of-war in their daily work, balancing the need for speedy rollouts of high-performing (fast, reliable) applications that are secure also. If the team moves too quickly, an overlooked security vulnerability may make its way into production. If the team is not nimble enough to identify those security gaps, it can slow down the entire development process, hampering organizational agility. The need to strike this critical balance has led to the rise of DevSecOps,

Read more

Rules automation puts the “Sec” in DevSecOps

Source – helpnetsecurity.com Imagine if safety were an afterthought in automobiles: Manufacturers would create a pristine new car and then hand it off to the safety team
which would bolt airbags onto the dashboard, seatbelts onto the side panels, and bumpers onto both ends. And if they were under a lot of pressure to get the car to dealers as quickly as possible, they might just leave off some of this stuff, ship the car to the dealer, and tell the safety

Read more

Application security needs to shift left

Source – sdtimes.com As teams are pressured to release software more rapidly, more and more aspects of software development are being forced to “shift left,” moving up earlier in the development lifecycle. Because of the speed in which code is updated and delivered, security can no longer be thought of as an afterthought, said Rani Osnat, VP of product marketing at Aqua Security, a company that specializes in container security. “That’s why we profess to shift left security and basically embed

Read more

When AI meets DevOps: Getting the best out of both worlds

Source – cloudcomputing-news.net DevOps has been widely embraced by businesses under pressure to get competitively advantageous digital deliverables to market at the fastest possible cadence—especially given the reality of limited coder headcount and the need to rigorously avoid brand-toxic snafus in the customer experience. Artificial intelligence (AI), in stark contrast, is a potentially transformative digital discipline that is still very new to most enterprise IT organizations. But while it’s certainly important that CIOs nurture AI adoption with appropriately resourced pilots, it’s

Read more

What Comes after DevOps? Two Possibilities

Source – devops.com People have been talking about the “post-DevOps” world since at least 2014. But have we actually arrived in the post-DevOps era? If so, what comes after DevOps? Let’s explore those questions. The DevOps concept is more than a decade old. DevOps has seen widespread adoption across companies large and small. “DevOps engineer” is now a common job title for tech folks. At a minimum, these developments mean that DevOps is now very mature and mainstream. They may even signal the end of DevOps,

Read more

DevSecOps: Embedding a Security Practice into your DevOps Approach

Source – devops.com It’s a no-brainer that the element of security cannot be compromised even to the smallest of extents in today’s competitive, fast-paced, modern technology-driven IT infrastructure. However, to keep up with the rapid developments of other processes in this agile world, security is often given relatively less importance and in some cases, even left behind. As the term suggests, DevSecOps is primarily concerned with the incorporation of security in the DevOps pipeline. The intended primary function of DevSecOps is

Read more

DevOps requires a fresh approach to security

Source – itworldcanada.com DevOps originated from the need/desire to break down the silos between development and quality control. The need to be more agile, to continuously produce and deliver code in a quick, iterative approach, while maintaining quality. The developers became accountable for the quality of code that went into production. When practiced properly, agile development is an efficient approach that allows for constant upgrades and feature releases, while maintaining code quality. However, security has still remained a tack-on afterthought. Enter

Read more

Securing DevOps Without Undermining It

Source – itbusinessedge.com Everybody wants to do DevOps right, and part of that equation is making sure applications and services remain secure even as development and integration transition to a continuous workflow model. But chaos, even the controlled chaos of DevOps, poses a particular challenge to security. It opens up too many attack vectors and introduces too much uncertainty into what is now a very staid, stable data environment. When everything, even infrastructure, is defined and managed as code, security requires

Read more

Continuous Discussions Video Podcast: DevSecOps, Best Practices and More

Source – devops.com In a recent episode of the Continuous Discussions (#c9d9) podcast, a group of industry experts discussed why DevSecOps is officially more than just a buzzword, tips on how to get everyone in the organization to own security and some of their own challenges and experiences baking security into the software delivery pipeline. The panel included: Alan Shimel, editor in chief at DevOps.com; Chenxi Wang, managing general partner at Rain Capital; Derek E. Weeks, VP and DevOps Advocate at Sonatype; Paula Thrasher, Chief Architect, National Security Division at

Read more

Interview: CyberArk tells why DevOps must adopt ‘secure innovation by the numbers’

Source – securitybrief.com.au DevOps is becoming a major force across software development. For various reasons, security can be sidelined until far later in the development process – but there’s also a movement that is putting security rightly where it belongs – at the beginning. That’s the essence of DevSecOps, which maintains that security by design should be central to any strategy. Elizabeth Lawler is CyberArk’s vice president of DevOps Security. She was the former CEO of Conjur – a DevOps security startup

Read more
1 8 9 10 11 12 15