Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

OWASP® Global AppSec US 2021 Virtual - Saman Fatima's 'Why SecDevOps Is The New Way In Cybersecurity?' →

May 05, 2022 by Marc Handelman in OWASP®, Global AppSec US ’21, AppSec Conferences, Education, Security, SecDevOps, SecDevOps Education

Our thanks to both the OWASP® Foundation and the OWASP Global AppSec US 2021 Virtual Conference for publishing their well-crafted application security videos on the organization’s’ YouTube channel.

May 05, 2022 /Marc Handelman
OWASP®, Global AppSec US ’21, AppSec Conferences, Education, Security, SecDevOps, SecDevOps Education

via the astounding cartoonery of Daniel Stori of turnoff.us!

Daniel Stori's Depressed Developer #43 In 'Bedtime Story' →

April 02, 2019 by Marc Handelman in DevOps, Sarcasm, Satire, DevSecOps Humor, SecDevOps, SecDevOps Humor
April 02, 2019 /Marc Handelman
DevOps, Sarcasm, Satire, DevSecOps Humor, SecDevOps, SecDevOps Humor

BSides Delaware 2018 , Jon Mosco's (@jpmosco) 'Introduction To Container Security In Kubernetes' →

January 11, 2019 by Marc Handelman in BSides Delaware, Conferences, Education, Information Security, SecDevOps, Container Security
January 11, 2019 /Marc Handelman
BSides Delaware, Conferences, Education, Information Security, SecDevOps, Container Security

OWASP APPSEC Cali 2018, Clint Gibler's 'SecDevOps: Current Research and Best Practices' →

April 10, 2018 by Marc Handelman in OWASP, Application Security, Conferences, Education, Information Security, DevSecOps, DevOps, SecOps, SecDevOps, Infosec Coding
April 10, 2018 /Marc Handelman
OWASP, Application Security, Conferences, Education, Information Security, DevSecOps, DevOps, SecOps, SecDevOps, Infosec Coding

OWASP APPSEC Cali 2018, James Wickett's 'The Path Of DevOps Enlightenment For InfoSec' →

April 09, 2018 by Marc Handelman in OWASP, Application Security, Conferences, Education, DevOps, DevSecOps, SecDevOps, SecOps, Information Security
April 09, 2018 /Marc Handelman
OWASP, Application Security, Conferences, Education, DevOps, DevSecOps, SecDevOps, SecOps, Information Security

OWASP APPSEC Cali 2018, Caroline Wong's 'The Only Reason Security Really Matters for DevOps' →

April 05, 2018 by Marc Handelman in OWASP, Application Security, Conferences, Education, Information Security, SecDevOps, SecOps, DevSecOps
April 05, 2018 /Marc Handelman
OWASP, Application Security, Conferences, Education, Information Security, SecDevOps, SecOps, DevSecOps

"the Art of Secure Application Deployment" →

September 19, 2016 by Marc Handelman in SecDevOps, Rugged Security, DevOps

In my opinion, there is absolutely no 'art' in securely deployed applications...

Not withstanding this, the subject of this post is the well engineered conversational interview over at Linux.com, with Tim Mackey, an evangelist at Black Duck Software; in which the two participants in the conversation hold forth in 'DevOps and the Art of Secure Application Deployment' (scribed by Amber Ankerholz). Worth the read.

September 19, 2016 /Marc Handelman
SecDevOps, Rugged Security, DevOps

Bad Relationship, Technical Debt →

December 29, 2015 by Marc Handelman in Security Heal Thyself, SecDevOps, Cybersecurity, Information Security

Technical Debt, and it's consequences... Illuminated for us - mere mortals - by Chris Hockings - IBM Master Inventor. Todays' MustRead.

In the worst-case scenario, an enterprise continues to invest in platforms that are no longer sufficiently effective, resulting in more personnel delivering currency rather than capability. Security debt is a term that has been coined to describe application vulnerabilities that result from such laggardly behavior. - via by Chris Hockings writing at SecurityIntelligence

December 29, 2015 /Marc Handelman
Security Heal Thyself, SecDevOps, Cybersecurity, Information Security
Netflix (1).png

NetFlix Unleashed FIDO →

May 06, 2015 by Marc Handelman in All is Information, Incident Handling, Incident Response, Information Security, Automation, SecDevOps

via Netflix's Jason Chan, comes word of a OSS automation effort targeting security related events, and actions thereo. Monikered FIDO or more accurately 'Fully Integrated Defense Operation' the system ostensibly serves as an orchestration layer for automated response activities, in the case of security event triggers. Comprised of a well thought-out architecture of infrastructure components, an encapsulated orchestration, correlation and scoring engine coupled to a threat intelligence system... But, I'll leave the full explanation in the obviously capable hands of Netflix's Security Team; examine. if you will, FIDO at GitHub. And, because it's Open Source Software, the security community at large can reap the benefits of this superalitve effort. Outstanding.

May 06, 2015 /Marc Handelman
All is Information, Incident Handling, Incident Response, Information Security, Automation, SecDevOps

SecDevOps, The Change

May 14, 2014 by Marc Handelman in Data Security, Application Security, Information Security, SecDevOps, DevOps

In a tour-de-force example of Security Automation, those crazy kids at DevOps have produced a model for enterprise implementation. You'll be well served, I reckon, in taking the time to read their vision of an automated firewall modification.

A Workflow by any other name, would smell as sweet...

May 14, 2014 /Marc Handelman
Data Security, Application Security, Information Security, SecDevOps, DevOps