Tag: security
-
OpenAI launches ChatGPT Gov for U.S. government agencies – That should get a lot of enterprise CISO’s to move in allowing AI in their orgs. // ”Since the beginning of 2024, OpenAI said that more than 90,000 employees of federal, state and local governments have generated more than 18 million prompts within ChatGPT, using the…
-
OpenAI finally launches screen and live video observation for paying ChatGPT users – CISO’s must be freaking the fuck out about this.
-
To Improve Your Mean Time to Recovery, Start at the Beginning – How to think about securing your cloud native apps, and apps in general.
-
CIOs: Get Tech Sprawl Under Control – “According to Forrester’s Q2 2024 Tech Pulse Survey, a staggering 77% of US technology decision-makers report moderate to extensive levels of technology sprawl. This sprawl can result in unsustainable costs, slower IT delivery, reduced operational resilience, and increased security risks.”
-
VMware Tanzu Platform 10: Unified cloud app development simplified – ‘“With Tanzu platform 10, we have a unified single console to manage your applications, look at your CVEs, security governance, compliance,” she stated. “There are three main messages. Keep it very simple for the developer, never expose YAML files, configuration files and lower level configs.…
-
Spring Boot 3.3 Boosts Performance, Security, and Observability – All these years later, Spring is still in wide use and still evolving.
-
Teaching to the Test. Why It Security Audits Aren’t Making Stuff Safer – Bullshit Work in enterprise security. // Plus, why not start with basics before going advanced: ‘The world would be better off if organizations stopped wasting so much time and money on these vendor solutions and instead stuck to much more basic solutions.…
-
Kubernetes Security Report: Evolving Landscape of DevSecOps – Red Hat Kubernetes surveys results, here, looking at the security part. The theory is: there’s too many different parties working on security, causing “confusion and delay.”
-
AWS CISO: In AI gold rush, folks forget application security – “the places where we’re seeing the security gaps first are actually at the application layer”
-
UK.gov efficiency hurt as legacy tech upgrades stall – Security is always the FUD-stick: “Dame Meg Hillier MP, PAC chair, said: ‘Whitehall’s digital services, far from transforming at the pace required, are capable of only piecemeal and incremental change. Departments’ future-proofing abilities are hobbled by staff shortages, and a lack of support, accountability and focus…
-
Shadow IT guidance – Advice from the UK government: “Though clearly not desirable, the existence of shadow IT presents your organisation with learning opportunities. If employees are having to resort to insecure workarounds in order to ‘get the job done’, then this suggests that existing policies need refining so that staff aren’t compelled to make…
-
What the Government Email Account Hack Says About the Future of Cybersecurity – Always be securing all the things.
-
Security Team Culture Matters – Being in security should be a happy job. // “Security and risk teams are more motivated and purpose-driven than others. As a 25-year cybersecurity veteran, this totally checks out for me. “Almost everyone I know in [IT security] is mission- and purpose-driven. They took on this job to protect others!”
-
Adopt Platform Engineering to Scale Application Security Practices – “Gartner Survey Data Reveals a Missed Opportunity – Platform teams focus on improving developer experience, developer productivity, software quality and delivery speed. According to Gartner’s 2022 Software Engineering Leaders Role Survey, only 25% of respondents cited “reduced security risks’’ as one of the top three goals…
-
The Care and Feeding of Internal Developer Platforms – Five benefits of monitoring and managing internal developer platforms are noted: improved system performance, cost reduction, scalability, enhanced security, and improved feedback loops. Achieving these benefits entails securing deployment environments, establishing system baselines, setting up alerting rules, monitoring application performance, and automating processes.
-
2023-05-30 day note
I recorded a podcast today on security in cloud native. Security can seem like an incomprehensible complexity from the outside, but when you ask an expert to break it down, it’s simple. Sure, lengthy and tedious and precise, but not impossible. I’ll post it in the Tanzu Talk podcast feed sometime this week. I spent…




You must be logged in to post a comment.