Relating to DevSecOps

De: Ken Toler and Mike McCabe
  • Sumário

  • A Podcast dedicated to forging iron clad relationships between developers, engineers, operations, and security practitioners by discussing hot topics in the world of DevSecOps. This podcast aims to air out some of the common gripes, misconceptions, and hardships that these teams face in the real world every day.
    © 2024 Relating to DevSecOps
    Exibir mais Exibir menos
Episódios
  • Episode #072: Measuring the Immeasurable: The Power and Pitfalls of Metrics in DevSecOps
    Aug 28 2024

    Send us a Text Message.

    Ken and Mike dive deep into the world of metrics and measurement in the context of security and DevSecOps. They explore the critical role metrics play in driving security improvements, from tracking vulnerabilities to gauging the effectiveness of incident response. The hosts discuss what makes a good metric, the importance of aligning metrics with business goals, and the dangers of relying too heavily on numbers alone. They also tackle the challenges of quantifying "squishy" aspects like culture and training effectiveness. Whether you're a seasoned security professional or just getting started, this episode offers valuable insights into the art and science of measurement in security

    Reference talk:

    https://www.youtube.com/watch?v=GXTvlQXVCOs&t=0s

    Exibir mais Exibir menos
    34 minutos
  • Episode #071: Retro Vibes with Retrospectives
    Jun 19 2024

    Send us a Text Message.

    Ken and Mike discuss the importance of postmortems in incident response and security incidents. They explore the definition of postmortems, the value of reflection, the challenges of blame, and the significance of actionable outcomes. They also touch on the transparency of postmortems and the need for root cause analysis. The conversation concludes with a brief announcement about an upcoming conference series.

    Exibir mais Exibir menos
    26 minutos
  • Episode: #070: Putting da BOM in SBOM and SCA
    May 8 2024

    Send us a Text Message.

    Ken and Mike discuss supply chain security, including software composition analysis (SCA) and software bill of materials (SBOM). They highlight the importance of understanding the components that make up your software and the risks associated with using third-party libraries. They also discuss recent supply chain failures, such as the XZ library hack and the SolarWinds attack. The hosts emphasize the need for organizations to stay up to date with software patches and to consider the security of commercial off-the-shelf software. They caution against placing too much focus on any one security tool or approach, including SBOM, and instead advocate for a well-rounded approach to security.

    Exibir mais Exibir menos
    40 minutos
activate_samplebutton_t1

O que os ouvintes dizem sobre Relating to DevSecOps

Nota média dos ouvintes. Apenas ouvintes que tiverem escutado o título podem escrever avaliações.

Avaliações - Selecione as abas abaixo para mudar a fonte das avaliações.