emacs/var/elfeed/db/data/2b/2b986f166557461f47bad24fc00c8bea58c1bcdb
2022-01-03 12:49:32 -06:00

4 lines
2.7 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<p>Ell and Wes sit down with Karthik Gaekwad to sort through the buzzword bingo and explain what DevSecOps is, what it isnt, and why security should be part of the full lifecycle of your apps.</p><p>Special Guest: Karthik Gaekwad.</p><p>Links:</p><ul><li><a href="https://www.devsecopsdays.com/2019-devsecopsdays-austin" title="DevSecOps Days is coming to Austin, Texas." rel="nofollow">DevSecOps Days is coming to Austin, Texas.</a> &mdash; Join us for the first ever DevSecOps Days Austin, Texas. Meet fellow practitioners integrating security into their DevOps practices. Learn about their journeys, share ideas on integrating security into your teams, and trade insights on automating security within the entire developer and production pipeline. Come learn how to put the "Sec" into DevSecOps. </li><li><a href="https://thenextweb.com/podium/2019/11/25/how-devops-and-security-teams-can-get-along-better/" title="How DevOps and security teams can get along better" rel="nofollow">How DevOps and security teams can get along better</a> &mdash; One of the biggest issues for IT security teams is getting involved early enough in the development process. For many, security is something that gets applied once the applications have been built and are moving into production. However, this is an old fashioned approach that is held over from the days when development took place in waterfall phases and applications were held behind strong perimeter security implementations.</li><li><a href="https://www.redhat.com/en/topics/devops/what-is-devsecops" title="What is DevSecOps?" rel="nofollow">What is DevSecOps?</a> &mdash; DevOps isnt just about development and operations teams. If you want to take full advantage of the agility and responsiveness of a DevOps approach, IT security must also play an integrated role in the full life cycle of your apps.
</li><li><a href="https://www.signalsciences.com/blog/devsecops-security-shift-right/" title="Securitys Shift Right" rel="nofollow">Securitys Shift Right</a> &mdash; Once you give up on the idea of teaching developers to not write bugs, you are freer to think of approaches to help them. One of the best approaches is to provide rapid feedback to developers. In the land of application performance, we found that running APM tools in production was a way to help developers find places to optimize their code. This created a feedback loop from production (the right) to development (the left).</li><li><a href="https://twitter.com/iteration1" title="Karthik on Twitter" rel="nofollow">Karthik on Twitter</a> &mdash; I live in Austin, work with @golang, k8s & containers at Oracle; @lynda author; organize @devopsdays, @container_days and @cloud_austin. Views are my own.</li></ul>