All Things Compliance
26 Min Read July 2, 2019
Tips for Choosing the Right CI/CD Tools
Building an effective CI/CD pipeline can be a complex process with countless decisions that require a great deal of planning. Whether it’s a massive DevOps team or a single developer working alone, the more you can draw on practical, real-world knowledge in making decisions about CI/CD tools the better off you are. While highly experienced developers can pass along tips to less experienced team members, the constantly changing nature of DevOps means that even the most experienced developer can benefit.
Like all workflows, CI/CD workflows are susceptible to security concerns, so it’s a best practice to integrate security into your DevOps world (something commonly known as DevSecOps). By pairing leading continuous integration tools with a cloud security and compliance solution like the Threat Stack Cloud Security Platform®, you can build security directly into the entire software development lifecycle. With security across the CI/CD pipeline, you can ensure that your team is developing more reliable and secure applications, without compromising your team’s efficiency.
In this post, we offer 50 tips offered up by a variety of industry experts as a good place for software engineers to start building a knowledge base. To make things easier, we’ve divided the list into the following categories, beginning with a few general tips that are useful no matter the team or project: (more…)
4 Min Read June 27, 2019
AWS re:Inforce 2019 Recap: A Look Back at the First AWS Security Show
The last day of the first AWS re:Inforce conference has wrapped up and it’s time to take the lessons we learned back to the office and put them into practice. In this post, we’ve compiled a few of the key takeaways from our team on the ground at re:Inforce broken into Day 1 and Day 2. We did a deep dive into Day 1 already, so check out the full post if you want to dig into the details. (more…)
4 Min Read June 26, 2019
AWS re:Inforce 2019 — Day 1 Recap
Note: For a recap of Day 2, please take a look at AWS re:Inforce Recap: A Look Back at the First AWS Security Show.
Day 1 of AWS re:Inforce 2019 — the first-ever AWS conference dedicated entirely to security — has wound down, and Day 2 is already underway, but we wanted to provide a quick recap for those of you who couldn’t make it to the show or were too busy to get the big picture. Here are a few of the high-level takeaways from the Threat Stack Team on the ground at re:Inforce 2019. (more…)
21 Min Read June 20, 2019
50 of the Best DevOps Podcasts
DevOps is a challenging and complex field, requiring professionals to constantly seek knowledge and acquire new skills and techniques to improve their productivity and effectiveness. Fortunately, software engineers are great at compartmentalization and multitasking, which is where these DevOps podcasts come in. We’ve assembled a list of 50 of the best DevOps podcasts that both educate and entertain, provide tips and insights to make you a better software engineer, keep you up-to-date on industry news and innovations, and expand your knowledge of the vast DevOps ecosystem. This list is all about learning from your peers as well as the thought leaders in the industry who have been there and done that. (more…)
6 Min Read June 6, 2019
Tips on Recruiting Top Talent in the Current DevOps and Cloud Security Markets
Q&A With Michael Race, Senior Consultant in Cloud/Infrastructure Security and DevSecOps at Stott and May
Hiring and retaining talent in continually changing areas such as Cloud Security and DevSecOps has never been a straightforward, black and white process. Given the way these disciplines are evolving as well as the unique needs that individual organizations have in these areas, finding, recruiting, and retaining the best talent can be a complex and challenging proposition.
To sort out some of the key issues, I recently sat down with Michael Race, Senior Consultant in Cloud/Infrastructure Security and DevSecOps at Stott and May. In the resulting Q&A, he shares some of his insights on the current state of the DevOps and Cloud Security markets as well as guidance on how to grow successful DevOps, Cloud Security, and DevSecOps team. (more…)