Voice of the DBA

The Need for DevSecOps

10.01.2023 - By Steve JonesPlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

One of the things that happens with many companies that start adopting DevOps is that they release new features constantly. They publish their lists of changes, and they try to attract customers and grow their businesses. They may make some mistakes, but they fix those quickly and keep pushing forward. That's the idea, and it works well. However, many of the developers (and most managers), don't think about the security side of their changes. This piece looks at the way hackers and criminals view DevOps, often using release notes and feature changes as a target to focus their efforts. In this way, they exploit holes and vulnerabilities in software to attack data storage. The examples include S3 buckets of storage and Elasticsearch, which is notoriously poorly secured by many people. Read the rest of The Need for DevSecOps

More episodes from Voice of the DBA