Embedding Security into the DevOps Toolchain

Source – darkreading.com The adoption of DevOps continues to grow rapidly, and security teams are still trying to keep up. A natural starting point has been to focus on application security and securing the code itself. Although this is definitely an important piece of the puzzle, DevOps today has moved beyond just building application code into binaries into building complete system infrastructure in containers and virtual machines. With this increased scope of DevOps comes all of the risks of the tens

Read more

Study: DevOps Servers In The Wild Highlight Infrastructure Security Needs

Source – tripwire.com A mature DevOps practice involves applying multiple tools at different steps of the delivery pipeline, and a new study from IntSights focuses on these tools that may be open to attack on the Internet. Each new tool added to your process can expand your attack surface area – and, in many cases, new development and delivery tools are being used without oversight from a security team. With complex tools being used in each DevOps step, potential attack vectors and the risk of

Read more

The future of DevOps: What to expect for 2018

Source – itproportal.com This year we have witnessed more industries adopting the set of practices and solutions that make up DevOps. According to a Capgemini report, 60% of companies have adopted DevOps or plan to do so in the next year. This demonstrates how widely understood it is for DevOps to be a necessary part of your business strategy if you intend to quickly respond to market demands, keep your software and solutions regularly updated, and improve time-to-market within your business.

Read more

Node.js Popular With DevOps, But Security Lags

Source – enterprisetech.com Developers are painfully aware of the risks inherent in deploying applications on the open Internet, but few are using tools designed to secure code and mitigate risks. A survey released by Node.js JavaScript runtime vendor NodeSource and software security startup Sqreen found that more than one-third of the Node.js developers and executives it polled expect to be hacked. Indeed, many were resigned to large-scales attack over the next six months. Perhaps reflecting the current harried state of application

Read more

Is security killing your digital transformation?

Source – sdtimes.com Hackers love traditional security. So do your competitors. Want to ruin their day? Forget what you know about how faster development increases risk. If your approach to security is slowing you down, it’s only a question of which you’ll lose faster — your data or your customers. To begin, let’s agree on one fundamental principle: In the era of DevOps, agile, and the cloud, survival depends on speed. If you’re not first to market with the innovations today’s

Read more