Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

2015 - DevOpsDays DC - 36 - DevOps Security and Continuous Failure: Lessons From Heartbleed, Shellshock, and Countless Other Security Flaws

2015 - DevOpsDays DC - 36 - DevOps Security and Continuous Failure: Lessons From Heartbleed, Shellshock, and Countless Other Security Flaws

FromDevOps Days Podcast


2015 - DevOpsDays DC - 36 - DevOps Security and Continuous Failure: Lessons From Heartbleed, Shellshock, and Countless Other Security Flaws

FromDevOps Days Podcast

ratings:
Released:
Sep 5, 2015
Format:
Podcast episode

Description

We pursue increasingly rapid delivery cycles while acheiving previously unimaginable degrees of scalability, reliability, and raw performance. But there is obviously a growing and serious mismatch between our develoment and operations performance in securing our applications compared to our performance in other areas. I work at a company extensively involved in Drupal and other open source projects that concentrate on both DevOps and security, but continue to be plagued by serious security vulnerabilities. Organizations and individuals negatively affected by Heartbleed and other security flaws probably would have readily traded some delay in accessing new features or temporary access problems for better security. So, how can we better focus DevOps culture and practices on the concept of Continous Security to deliver this? Perhaps we need to look at ongoing advances in automated security testing, more rigorous and frequent manual code review, and paired/team programming practices, and work better on more fully integrating these all into DevOps.
Released:
Sep 5, 2015
Format:
Podcast episode

Titles in the series (89)

Audio recordings of DevOpsDays conferences (http://devopsdays.org).