Tag: security
-
Teaching to the Test. Why It Security Audits Aren’t Making Stuff Safer – Bullshit Work in enterprise security. // Plus, why not start with basics before going advanced: ‘The world would be better off if organizations stopped wasting so much time and money on these vendor solutions and instead stuck to much more basic solutions.…
-
Kubernetes Security Report: Evolving Landscape of DevSecOps – Red Hat Kubernetes surveys results, here, looking at the security part. The theory is: there’s too many different parties working on security, causing “confusion and delay.”
-
AWS CISO: In AI gold rush, folks forget application security – “the places where we’re seeing the security gaps first are actually at the application layer”
-
UK.gov efficiency hurt as legacy tech upgrades stall – Security is always the FUD-stick: “Dame Meg Hillier MP, PAC chair, said: ‘Whitehall’s digital services, far from transforming at the pace required, are capable of only piecemeal and incremental change. Departments’ future-proofing abilities are hobbled by staff shortages, and a lack of support, accountability and focus…
-
Shadow IT guidance – Advice from the UK government: “Though clearly not desirable, the existence of shadow IT presents your organisation with learning opportunities. If employees are having to resort to insecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make…
-
What the Government Email Account Hack Says About the Future of Cybersecurity – Always be securing all the things.
-
Security Team Culture Matters – Being in security should be a happy job. // “Security and risk teams are more motivated and purpose-driven than others. As a 25-year cybersecurity veteran, this totally checks out for me. “Almost everyone I know in [IT security] is mission- and purpose-driven. They took on this job to protect others!”
-
Adopt Platform Engineering to Scale Application Security Practices – “Gartner Survey Data Reveals a Missed Opportunity – Platform teams focus on improving developer experience, developer productivity, software quality and delivery speed. According to Gartner’s 2022 Software Engineering Leaders Role Survey, only 25% of respondents cited “reduced security risks’’ as one of the top three goals…
-
The Care and Feeding of Internal Developer Platforms – Five benefits of monitoring and managing internal developer platforms are noted: improved system performance, cost reduction, scalability, enhanced security, and improved feedback loops. Achieving these benefits entails securing deployment environments, establishing system baselines, setting up alerting rules, monitoring application performance, and automating processes.
-
2023-05-30 day note
I recorded a podcast today on security in cloud native. Security can seem like an incomprehensible complexity from the outside, but when you ask an expert to break it down, it’s simple. Sure, lengthy and tedious and precise, but not impossible. I’ll post it in the Tanzu Talk podcast feed sometime this week. I spent…
-
Thinking Strategically About Software Bills of Materials (SBOMs) – As with most things, the whole SBOM push is probably a lot simpler to solve than it seems. Also, a delightful “old man yells at secure software supply chain hype” vibe as only Jon could do well.
-
Setting the Record Straight on Cloud Computing ROI – Ability to add new features(quickly), access to new tech, scaling and performance, toil reduction to focus on things valuable to the business or competitive advantage, better security. Of course reducing costs (or “efficiency” if you’re forced to feel the “do more with the same/less” vibe) is…
-
Enterprise interest in sovereign cloud on the rise, survey – “In a poll of 1,000 enterprise leaders from 10 countries, including Australia, France, Germany, India, and the UK and US, 69% of respondents cited potential exposure to extra-territorial laws when using cloud as being a top concern.”







You must be logged in to post a comment.