Tag: security testing
Ensuring Application Security from Design to Operation with DevSecOps
Safe development is critical for any company that creates software, whether for its own use or for others. DevSecOps principles focus on automating information security processes and introducing security measures early in ...
The IT-DevOps Life Cycle is Like a Pyramid That Keeps Growing
For the most part, the demand for new technology to solve age-old problems has been a net increase in workload ...
Synopsys Preps Extensions to Polaris SaaS Platform
Synopsys plans to extend the capabilities of its Polaris Software Integrity Platform for securing application development environments by adding dynamic application security testing (DAST) tools along with the ability to scan code ...
At Some Point, We’ve Shifted Too Far Left
Those of us involved in DevOps have a tendency to see the world with blinders on. It is rather easy to fall into the “If all you have is a hammer, everything ...
Where Has All the Testing Gone?
Testing has long been a problem child of IT in general, AppDev in particular, and now it is DevOps' problem. There are things that DevOps can do to improve the chances of ...
Continuous Testing Practices – Part 3
In my prior blog, Continuous Testing – The Quest for Quality at Speed, I described five tenets and some of the practices for continuous testing to help with understanding what continuous testing ...
Make a Plan for Test Automation
The amount of testing that we could be doing is massive. Most of us don't look at testing across the spectrum and all-inclusively, but let's do that for a second. We have ...
Prevent False Positives From Derailing Shift Left
Static application security testing (SAST) tools are designed to balance false positives (incorrect warnings) with false negatives (missed vulnerabilities) primarily because deeper analysis requires more time and computing resources. Both of these ...
Integrating Security in the Development Process With DevSecOps
Occasionally, it's worthwhile to reflect on how we develop and deliver software during times of rapid change and significant disruption. In those moments of reflection, we learn from the exciting trends and ...
How to Create Bug-Free Blockchain Apps
While all developers strive for bug-free code, it’s particularly crucial in a blockchain deployment where sensitive data or other confidential info is being exchanged, such as in health care or finance. However, ...
Security Testing: Reducing Resistance to Change in an Agile and DevOps World
Software development has evolved, but security testing has not. That has to change In the bad, old days—which, sadly, many are still living in—security testing was tacked onto the end of the ...
CA Technologies Extends DevOps Push
At its CA World 2017 conference this week, CA Technologies moved to tighten the integration between the various elements of its DevOps portfolio acquired over the last year and unveiled CA Digital ...