Security Automation By Example The Firewall Change Just when you thought DevOps was the new black, along comes SecDevOps. Yes folks, like most things in life, the new cool is […]
You have to crawl before you walk…
In previous posts I have explained what Security Policy Orchestration is, why DevOps folks should care, and how it can help facilitate the cultural change necessary for organizations to reap […]
DevOps: Security’s last best hope
Help us Obi Wan! The fact is that DevOps is security’s last best hope. The sooner the security industry realizes it the better it will be for everyone. I read […]
Delivering Delight At ChefConf 2014
Chef CEO Barry Crist stirs the pot to open ChefConf 2014 The theme from ChefConf 2014 is stirring delight and if you listened to Barry Crist during todays opening keynote, […]
Trust and Computers Make the News
The Heartbleed bug in OpenSSL was major news this week. While you are waiting for sudo apt-get dist-upgrade to run on all your servers, let’s take a minute to reflect […]
Continuous integration for better security
One of the big advantages to smaller deploys and continuous integration is that it can make it easier to provide more proactive security. In short, continuous integration (and the associated […]
Using AWS CloudWatch for Anomaly Detection
Based on my unscientific poll of friends, one of the least used and most overlooked features of AWS is CloudWatch. Not only can CloudWatch be used to monitor the availability […]
How to un-domesticate your network: DevOps!
When I look at how compliance and regulations have affected network security over the years, I’m reminded of what dog breeder standards and regulations have done to dogs over the […]
Dev, Ops and Security Collaboration: Bring the body and the mind will follow
Complexity has a way of muddying even the clearest of waters, and this has certainly been the case with IT Operations. While Dev, Ops and Security teams share a common […]
Trust & the trusted image
What is Your Trust Model? Information security conversations often start with the question “What is your threat model?” This blog asks: “What is your trust model?”. Trust is a complex […]











