🔥⏲️ Fudge Sunday "Shock the Chaos Monkey" A look at chaos engineering adoption within platform engineering teams
#chaos #chaosengineering #faulttolerance #faultfinding #faultinjection #securityengineering #dataops #dataoperations #ai #resiliency #devx #devops #devsecops #platformengineering #platformengineer #cloudinfrastructure #securityautomation #securitybydesign #shiftleft #shiftup #newsletter #newsletters
#chaos #chaosengineering #faulttolerance #faultfinding #faultinjection #securityengineering #dataops #dataoperations #ai #resiliency #devx #devops #devsecops #platformengineering #platformengineer #cloudinfrastructure #securityautomation #securitybydesign #shiftleft #shiftup #newsletter #newsletters
🔥⏲️ Fudge Sunday "Fuzz Jam June" A look at the growing importance of fuzzing in platform engineering
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
#fuzzing #fuzztesting #fuzzylogic #fuzzball #fuzzy #platformengineering #platformengineer #toolchains #attestation #softwaresupplychain #softwaresupplychainsecurity #dast #owasp #waf #cncf #aif #artificialintelliegence #machinelearningmodels #cloudinfrastructure #securityautomation #securitybydesign #scanning #defenseindepth #shiftleft #newsletter #newsletters
Last December I gave my first talk at Open Conf (https://www.open-conf.gr/) about what it means to shift security left and why this is important, along with some best practices.
You can now watch it here.
https://www.youtube.com/watch?v=Z-jtOjCkfbA
I am really interested about your thoughts and your experience on this matter. Please feel free to share your ideas.
#appsec #applicationsecurity #security #shiftleft #openconf22
#appsec #applicationsecurity #security #shiftleft #openconf22
My article just scratches the surface. Be sure to check out the presentations and videos of the sessions that are now posted https://events.linuxfoundation.org/cloudnativesecuritycon-north-america/ #CNScon #devsecops #cloudsecurity #kubecon #shiftleft #cncf #openssf 2/2
#CNSCon #devsecops #cloudsecurity #kubecon #shiftleft #cncf #openssf
Really enjoyed #CloudNativeSecurityCon a few weeks ago in Seattle. ICYMI: here are my top takeaways https://bit.ly/3K6k5T7 via @SearchSecurity
#CNScon #devsecops #cloudsecurity #kubecon #shiftleft #cncf #openssf
#cloudnativesecuritycon #CNSCon #devsecops #cloudsecurity #kubecon #shiftleft #cncf #openssf
My latest blog post is about top security initiatives for effective #cloudsecurity. Check it out here:
5 ways to enable secure software development in 2023 https://bit.ly/3HtMfWs via @SearchSecurity
#devsecops #cloudnative #appsec #infosec #shiftleft #apisecurity
#cloudsecurity #devsecops #cloudnative #appsec #infosec #shiftleft #apisecurity
Went ahead and fixed the cert for the SecDevSecOpsSec site and added a flat hmtl index.
No content, haven't quite decided on that yet. For now, just a silly domain
#DevSecOps #SecDevOps #DevOpsSec #SecDevSecOpsSec #DevOpsSecurity #ShiftLeft #ShiftEverywhere #SDSOS
#devsecops #secdevops #devopssec #secdevsecopssec #devopssecurity #shiftleft #shifteverywhere #sdsos
Pen testing is the “easy part”. Every week I get offers from companies specialising in Penetration Tests.
No one is ever banging on my door telling me about how they are going to support the dev teams to comprehensively understand how each detail in their job impacts the end product security.
Not saying pen tests are useless. They form an important part of the process. It’s just not the hard bit.
#cybersecurity #infosec #DevSecOps #PenTest #HumanCentredSecurity #SecureDevelopment #Cyber #ExpandLeft #ShiftLeft
#cybersecurity #infosec #devsecops #pentest #humancentredsecurity #securedevelopment #cyber #expandleft #shiftleft
Another of my efforts from the Wiz Academy - DevOps + Security + DevSecOps. Shift-Left and put security first 🔒
#cybersecurity #cloudsecurity #devops #devsecops #shiftleft
I'm still disappointed that #CarlosCorrea didn't sign with the #SFGiants. It would have allowed me to make a bunch of #ShiftLeft joke about #BrandonCrawford that only people who understand both #baseball and #InfoSec would actually understand. So I'll leave this here, in case anyone's interests intersect the same way mine do.
#carloscorrea #sfgiants #shiftleft #brandoncrawford #baseball #infosec
@fili thanks for the boost! Same question for you if you have a little time to opine: What's a challenging area of enterprise SEO we should explore?
I used to work in telemetry/observability and see many parallels to SEO, without the corresponding fancy tooling.
Things I'm asking a lot of questions about:
- large scale AB testing
- SEO and client side rendering
- bringing SEO closer to developer workflows (#shiftleft)
Anyway. Any nudge in the right direction helps us build useful things!
New #infographic on developer-focused security based on my latest research: Walking the Line: GitOps and Shift Left Security https://www.esg-global.com/research/infographic-walking-the-line-gitops-and-shift-left-security
#devsecops #infosec #cybersecurity #cloudsecurity #developersecurity #shiftleft #CloudSecurityOperations
#infographic #devsecops #infosec #cybersecurity #cloudsecurity #developersecurity #shiftleft #cloudsecurityoperations
New #infographic on developer-focused security based on my latest research: Walking the Line: GitOps and Shift Left Security https://www.esg-global.com/research/infographic-walking-the-line-gitops-and-shift-left-security
#devsecops #infosec #cybersecurity #cloudsecurity #developersecurity #shiftleft #CloudSecurityOperations
#infographic #devsecops #infosec #cybersecurity #cloudsecurity #developersecurity #shiftleft #cloudsecurityoperations
Sheri Byrne-Haber presents How (and why) to 'shift-left' your accessibility testing https://www.youtube.com/watch?v=UmPBLoJI3jY
𝐃𝐞𝐯𝐎𝐩𝐬 Keynote at Baloise OpenX Day 2022
In today's world, everybody wants to do DevOps. But why? What problems are we trying to solve? Together we will take a step back and look at how you can architect for continuous delivery.
Thank you Michael Mühlebach and Joachim Prinzbach for the excellent organization.
👉link to video🎞️ : https://youtu.be/ssA9pxvdJfQ
#devops #valuestreammapping #shiftleft #devsecops #keynote
ESG Data Point of the Week from my research on #gitops and #shiftleft security: 83% of organizations have seen an increase in misconfigurations with infrastructure-as-code (IaC) usage
#devsecops #cloudsecurity https://www.esg-global.com/data-point-of-the-week-11-21-22
#gitops #shiftleft #devsecops #cloudsecurity
ESG Data Point of the Week from my research on #gitops and #shiftleft security: 83% of organizations have seen an increase in misconfigurations with infrastructure-as-code (IaC) usage
#devsecops #cloudsecurity https://www.esg-global.com/data-point-of-the-week-11-21-22
#gitops #shiftleft #devsecops #cloudsecurity
Something I’ve been thinking about a lot lately is how to use interface design and types to #shiftleft on #security. Under strongly typed systems you can do things like forcing validation of data before accepting as input, centralize and enforce the correct checking of permissions, and stop the logging of sensitive data. Combine this with strong static analysis and you can enforce these rules as code as written, preventing security flaws from being written in the first place.
To share some content (and perhaps balance out my hiring post). Here's a post I wrote some time ago about Holistic Testing (aka Shift-Left) https://team-agile.com/2018/10/08/testing-as-a-holistic-exercise/ #testing #shiftleft #holistictesting
#testing #shiftleft #holistictesting