Tag: sponsored content

  • The Google Cloud DevOps Awards: Apply Now!

    DevOps continues to be a major business accelerator for our customers and we continually see success from customers applying DevOps Research and Assessment (DORA) principles and findings to their organization. The DevOps Awards are targeted to recognize customers shaping the future of DevOps with DORA. Share your inspirational story, supported by examples of business transformation and operational excellence, today! 

    With inputs from over 33,000 professionals worldwide and eight years of research, the Accelerate State of DevOps Report is the largest and longest running DevOps research of its kind. The different categories of DevOps Awards map closely to the practices and capabilities that drive high performance, as identified by the report. 

    Organizations, irrespective of their size, industry, and region are able to apply to one or all ten categories. Please find the categories and their descriptions below:

    • Leveraging loosely coupled architecture: This award recognizes one customer that successfully transitioned from a tightly coupled architecture to loosely coupled (service-oriented; microservice) architectures.
    • Designing tools of the future: This award recognizes one customer that has meaningfully contributed to an open source DevOps tool or open source security DevOps tool.
    • Securing the software supply chain: This award recognizes one customer that successfully demonstrates high levels of security implementation based on specific examples of how the organization has worked to secure every stage of the software supply chain. 
    • Growing DevOps throughout your organization: This award recognizes one customer that employed DevOps best practices on one team and were able to scale successfully to more teams throughout the organization over a period of time. 
    • DevOps communities of practice award: This award recognizes one customer that has created a community structure in the organization which makes it easier for teams to share DevOps best practices that work in their organization and make them more resilient to reorganizations and product changes.
    • Going beyond the four keys: This award recognizes one customer that not only shows how they have implemented the four key metrics throughout their teams, but also how they have gone beyond the four keys to demonstrate continuous iteration that drives business success. 
    • Nurturing team culture: This award recognizes one customer that implemented effective processes to improve work/life balance, foster a healthy DevOps culture, and ultimately prevent burnout. 
    • Unleashing the full power of the Cloud: This award recognizes one customer that is leveraging all five capabilities of cloud computing to improve software delivery and organizational performance.
      • On demand self-service
      • Broad network access
      • Measured service
      • Rapid elasticity
      • Resource pooling

    Read more about the five essential characteristics of cloud computing

    • Unlocking the secrets of DevOps: This award recognizes one customer that is able to demonstrate the outside benefits that come from adopting DevOps – aside from the operational and organizational performance improvements. This award recognizes one customer that:

    For example, set out to drive DevOps transformation and found increased DEI representation showing up more in their teams (increasing ppt of underrepresented groups) 

    -OR 

    Discuss how your organization creates unique solutions to help build a more diverse, inclusive, and accessible workplace for your customer, leading to higher levels of engagement, productivity, and innovation.

    • Continuous improvement with DORA: This award recognizes one previous DevOps Award winner that continues to integrate DORA practices and guidance into their workflow using Google Cloud Platform tools and who can deliver software with more speed and better stability to quickly meet end user needs. 

    This is your chance to show your innovation globally and become a role model for the industry to improve. Winners will receive invitations to roundtables and discussions, press materials, special announcements and even a trophy award!

    We are excited to see all your great submissions. Applications are open until January 31st, 2023 so apply for what best suits your company and stay tuned for our awards show in March 2022!

    For more information on the awards visit our webpage and check out The Google Cloud DevOps Awards Guidebook.  Feel free to check out the 2021 DevOps Award winner ebook to learn from the winners of the inaugural Google Cloud Awards!

  • AWS Well-Architected Framework Elevates Agility

    AWS Well-Architected Framework Elevates Agility

    What started as a white paper from AWS, the Well-Architected Framework has evolved into a large ecosystem of partners and more

    In the past year, agility has become one of the most prized IT attributes as organizations race to deploy more workloads in the cloud. There is a paradox, however: The faster organizations deploy applications, the more likely mistakes will be made. Cloud computing deployments are rife with misconfigurations that are the direct result of developers provisioning cloud infrastructure rapidly and incorrectly. Application environments are almost never as efficient as they could be.

    The challenge and the opportunity IT teams now face is defining a set of best practices for securely and consistently deploying application workloads on cloud infrastructures that complement and extend agile development methodologies. IT organizations should not have to slow down application development and deployment because of security concerns. Identifying high-risk issues (HRIs) and being able to consistently achieve and maintain security without sacrificing agility is an absolute requirement.

    It seems that Amazon Web Services (AWS) couldn’t agree more. The cloud leader has defined the AWS Well-Architected Framework to help organizations build workloads on AWS that are secure, efficient, reliable, cost-optimized and operationally excellent.

    Through this effort, AWS hopes IT organizations benefit from removing the guesswork for building workloads on cloud. Cloud misconfiguration mistakes that conspire to make organizations question their commitment to agile development methodologies are eliminated. The only remaining issue is finding a set of tools that turn those AWS guidelines into a set of policies that can be achieved and enforced easily.

    Agile Meets Well-Architected

    In addition to making it possible to build and deploy applications faster, agile development methodologies make it possible to test the application code. IT teams gain unprecedented visibility into how applications behave. The equivalent of an application development methodology for managing cloud infrastructure is the AWS Well-Architected Framework.

    The Well-Architected Framework is battle-tested, based on best practices AWS has observed over its 14-year history. The pillars of the Well-Architected Framework are:

    1. Operational Excellence: Under this pillar, operations teams need to understand their business and customer needs so they can support business outcomes. Operations teams create and use procedures to respond to operational events and then validate their effectiveness to support business needs. Those teams also collect metrics that are used to measure the achievement of desired business outcomes. It’s important to design operations to support evolution in response to change and to incorporate lessons learned through their performance.
    2. Security: This pillar focuses on the importance of putting in place practices that influence security before any workload is architected. IT teams need to control who can do what. In addition, they need to be able to identify security incidents, protect systems and services, and maintain the confidentiality and integrity of data through data protection.
    3. Reliability: This pillar encompasses the ability of a workload to perform its intended function correctly and consistently when it’s expected to. This includes the ability to operate and test the workload through its total life cycle. The workload architecture of the distributed system must be designed to prevent and mitigate failures, handle changes in demand or requirements and be able to detect failures and automatically heal itself.
    4. Performance Efficiency: This pillar addresses the need to use computing resources efficiently to meet system requirements and to maintain that efficiency as demand changes and technologies evolve. Teams must gather data on all aspects of the architecture, from the high-level design to the selection and configuration of resource types and make trade-offs in their architecture to improve performance, such as using compression or caching or relaxing consistency requirements.
    5. Cost Optimization: This pillar focuses on how to run systems to deliver business value at the lowest price point. Design decisions are sometimes directed by haste rather than data, and it can be tempting to overcompensate rather than spend time performing benchmarking to determine the most cost-optimal deployment. As a result, deployments can be both overprovisioned and underutilized. Using the appropriate services, resources and configurations for workloads is key to cost savings.

    Each of these pillars requires tools to enable DevOps teams to proactively manage their cloud environments—not only by provisioning and deploying applications faster but also by making more informed decisions when considering trade-offs between performance, reliability, cost and security. It’s a balance as rarely are these decisions independent of each other.

    The COVID-19 Imperative

    The COVID-19 pandemic has made the Well-Architected Framework essential. The number of workloads being deployed on AWS has increased sharply as organizations of all sizes accelerate digital business transformation initiatives. IT projects that once were expected to take months to complete now are expected to be up and running in a matter of weeks.

  • What is Cloud-Native Workload Protection?

    What is Cloud-Native Workload Protection?

    We’re living in a cloud-native age. That means that many of the paradigms that worked in the days of on-premises hosting no longer suffice.

    Chief among them is security. To thrive in today’s cloud-native world, organizations need to rethink their approach to workload protection and bring it up to speed with cloud-native environments.

    In this article, I walk through what that means by explaining how cloud-native computing changes the calculus of workload protection and security.

    The Rise of Cloud-Native Computing

    More and more organizations are shifting from on-premises hosting to cloud-based environments built using shared infrastructure. As a result, applications and infrastructure these days exist in more dynamic and complex environments that contain a lot of moving parts and are dependent on a slew of external resources (which, in turn, may rely on other compute and infrastructure resources). Thus, we have to think in terms of an entire workload (instead of just our application code) for our applications to run effectively on the cloud.

    This new paradigm is enabling the concept of “cloud-native workload” to gain traction. We can think of this as a distinct capability that we can run on a cloud instance—in other words, all of the resources required to make an application functional, which could be anything from a web server to a database, to network resources, to the data that needs to be fed in (and of course the application code itself). A lot of these workloads likely would run on containers.

    These discrete sets of workloads running on cloud platforms necessitate a new way of mitigating risks and protecting our application and its dependencies. Cloud-native workload protection is a security category that is fast becoming very relevant among security-minded folks and distinguishes itself from application security. Applications are only part of a broader context of workloads (which may include things such as deployment and monitoring), and we must think of security in terms of a workload. Any means of protecting these workloads and mitigating risks and attacks against them is what cloud-native workload protection refers to.

    Although cloud environments can be more secure than self-hosting on-premises, security is a shared responsibility, and our cloud workload protection strategy does not fully fall into the hands of our cloud service provider. Surveys have discovered that many companies have at least one critical security flaw in their AWS configurations. We must take precautions and be proactive when it comes to protecting our cloud-native workloads, which could mean extending security policies and tools we have for our cloud-based systems.

    Security may be the greatest challenge for cloud-based workloads due to the myriad components that require a security analysis, along with the different attack plane combinations that these components produce together. We will dive deeper into what protecting our cloud workloads means in this new environment.

    Security Threats in Cloud-Native Environments

    We need to be aware of system vulnerabilities, data breaches, account hijackings and insecure APIs. We also need to identify any flaws in our identity and access management protocols and make sure two-factor authentication is enforced. Other considerations include running due diligence on third-party systems and understanding the implications of sharing cloud resources with other users on the same platform—we also may be compromised if they are.

    Finally, we need to understand containers and their implications in terms of security. Containers are particularly vulnerable because their ephemeral nature makes enforcing standard security difficult, and the variations in container images introduce more points of entry. This makes intrusion detection in cloud environments a tricky business.

    Discover

    Perform regular assessments that oversee and can uncover weaknesses in this dynamic environment. Make sure to routinely test code for any weaknesses, monitor new deployments for vulnerabilities and breaches, then keep a watchful eye on security logs and fire off appropriate alerts. Manage and monitor network security and ensure the visibility of all traffic.

    Visualize

    We can’t understand what we need to control if we don’t maintain an effective visibility strategy. This entails being able to visualize the workloads that we are running and being able to act swiftly if there are problems related to the workload. Ideally, some type of central interface can allow us to synthesize different workloads and events to help us manage our security solutions and tools.

    Protect

    Cloud platform providers are responsible for securing the physical hardware infrastructure and virtual machine instances, but we are responsible for securing access to and between our workloads that are running on this infrastructure. So we must maintain the operating systems that we have chosen to run on these virtual machines, and be diligent in applying security updates and patches and installing antivirus software.

    Implement some real-time policies and best practices that prevent the propagation of exploits, and restrict access to servers as much as possible and ensure the correct configuration of your firewall. Have a system for managing configurations, patching, logs and administration privileges. Regularly audit your system and procedures. Are you running any arbitrary code?

    Invest in a Cloud-Native Workload Protection Platform

    To optimize your cloud-native workload protection strategy, it may be beneficial to look into outsourcing the work to security platforms by trusted leaders in cybersecurity (e.g., Symantec Cloud Workload Protection Suite). These platforms can employ advanced and comprehensive protection for all types of cloud workloads against exploits that traditional methods cannot sustain. It can scale easily and automatically, be controlled from a single cloud-based dashboard and provide automatic discovery, visibility and protection of cloud-native workloads.

    Remediation

    Despite your best efforts, some security issues will arise. That’s why it’s important to have a remediation plan in place. Your remediation plan should include guidelines that define who will respond to security incidents, how information about incidents will be shared within your organization and how response actions will be recorded. For more serious incidents, it is also wise to have a plan in place for handling any legal- or PR-related concerns.

    Compliance

    Meeting compliance requirements is not the only reason to secure your cloud workloads. But it is one important reason. Non-compliance could mean fines, as well as a loss of reputation. Compliance needs vary from case to case, so you’ll need to determine which compliance frameworks apply to your business and workloads, then take steps to ensure that you are in compliance. You’ll also want a plan in place for revisiting your compliance policies periodically, to make sure that you remain compliant even as the rules and your workloads evolve.

    Data

    Data protection is a big topic, and even more so with the advent of the PII and GDPR data compliance regulations. As mentioned previously, the shared responsibility model between the cloud platform provider we choose and us means that we remain responsible for the protection and security of sensitive customer data. To avoid failing a data security compliance audit or suffering the consequences of a data breach, we must implement some protective policies and build governance and controls surrounding data stores into the business:

    • Enforce the appropriate levels of authentication according to the sensitivity and availability needs of the data. Use security groups to give authorized access and make sure that services and service accounts are securely implemented.
    • Refine your data retention policies. A breach of data is often unavoidable, so have a plan in place to periodically erase data that you no longer need to minimize the loss incurred during a breach.
    • Encrypt all data at rest and data in transit when dealing with your cloud-native workloads. Cloud platform providers cannot be relied upon to guarantee end-to-end encryption for data in transit.
    • Use additional external tools to safeguard data. Consider safeguarding to be the highest priority and leave nothing to chance.

    Learning More

    It is crucial for businesses adopting cloud platforms to have a cloud-native workload protection strategy, understand the threats that exist for this new landscape and ensure the security of their cloud implementation within the infrastructure from their cloud provider.

    This new complexity can be managed with a more sophisticated protection strategy. Symantec is a leader in cybersecurity, and its offerings are designed to meet the unique challenges that businesses confront in this cloud-native landscape. Find out how to use their tools to protect cloud-native workloads.

    Be sure also to check out Cloud Security Alliance, a non-profit organization that has performed comprehensive studies on best practices and new requirements for cloud computing.

    To see how Symantec’s CWP product can help you secure cloud-native workloads, sign up for a free trial.

    — Daisy Tsang