OpenText launched the latest version of ValueEdge -- an innovative modular, cloud-based DevOps and value stream management (VSM) platform.
The world of tech is changing at an eye-watering rate. Whether you're in finance, marketing, manufacturing, or any other industry, your app functionality needs not only to keep up with the Joneses, but to keep ahead of them.
When you have a customer-facing app, you need to ensure that it's always updated with the newest tools and trends, offers cutting-edge features, and is perpetually responsive. If it lags behind in terms of features and functionality, that will impact on your user loyalty. Your app is used every day — you can't afford for it to go down for a few hours while you update capabilities.
Finally, your competition is always out there pushing to take advantage of any misstep you make. Speed of deployment affects your bottom line, making it one of the core DevOps metrics. Continuous integration (CI) and continuous delivery (CD) are now established principles that are standard in almost every business. The huge advantages that come with incremental, ongoing changes and deployment via Kubernetes, microservices, and containers have been proven and embedded into every business practice. While DevOps tools and practices are standard almost everywhere, there's still one DevOps tool left to go.
Security is the Speedbump in the Track of Continuous Delivery
There's just one flaw in the rapid delivery and innovation that's been enabled by DevOps, and that's security and compliance. No business can risk leaving a pathway open to hackers or missing a step in compliance, causing the app to be offline for hours or potentially days. It's a given that the faster you innovate, the greater the chances that you'll leave a vulnerability in the infrastructure, but traditional security testing processes are wholly incompatible with agile DevOps tools.
Traditional application security testing requires cumbersome, slow, and thorough one-time gating inspections. These processes take days or even weeks to complete and involve a significant number of security professionals — the antithesis to the agility, automation, and transparency that are the hallmarks of DevOps mindset. Compliance throws another monkey wrench into the fast-moving works of DevOps metrics. Some apps in specific industries need to be government-recertified after every update, seriously hampering the speed of deployment.
It's simply not practical to pause the entire CI/CD system for days at a time for an external security or compliance examination, nor can the entire process be repeated every few days, or possibly every few hours, each time the app is updated. These security testing strategies can't scale with DevOps tools, and the majority of DevOps employees lack the necessary knowledge and understanding of security to be able to carry them out.
DevSecOps is the Final Step
Not only is app security compromised when security measures are applied as a final stage at the end of development, but the core KPI of speed of deployment is undermined. The only option is to evolve business processes one step further, from DevOps to DevSecOps. Together, IT, security, and risk management professionals can adopt and support a DevOps mindset that bakes security into the very beginning of the DevOps process.
DevSecOps adapts security tools, processes, and policies into the DevOps toolchain without slowing down deployment. An integrated DevSecOps team can loop security best practices in from the very beginning of the service creation, automate them, and ensure that they progress continuously to improve through every iteration, keeping pace with the DevOps process.
Tactics like active security audits, pen testing, security unit tests, and static code analysis can and should be automated. By emulating the principles of CI/CD, we arrive at continuous security, which endlessly scans source code and imported open-source libraries to identify vulnerabilities in the smallest components of your app's development layer. DevSecOps brings security under the agile umbrella of continuous delivery, removing an obstacle to app security and a serious speedbump in the accelerating pace of deployment.
When seeking a resolution, prioritize your search on solutions that help security, development, and operational teams to overcome their silos and work together as a unified DevSecOps team in a single platform. Then, DevSecOps teams can continuously secure and protect their growing multi-cluster Kubernetes deployments without slowing it down. Also consider application security capable of replacing multiple fragmented firewalls, security groups, and ACLs with workload security that is as automated as possible and decoupled from the network infrastructure. This will enable DevSecOps teams to implement a digital identity for every workload at the CI/CD level, making it more intuitive to create security policies with fewer hassles and interruptions.
DevSecOps Brings in Security Without Slowing Down DevOps
Security is vital for all business applications, but DevOps cannot afford to slow down from its agile, continuous delivery position. DevSecOps allows and organization to unite IT, security, R&D, and operations teams for a single unified response that secures and protects continuous deployment without slowing it down. By automating workload security, the operation brings continuous security up to speed with CI and CD best practices to deliver the best of all possible worlds; speed and security in a single platform.
Oracle announced the availability of Java 20, the latest version of the programming language and development platform.
Rafay Systems introduced Environment Manager, a solution that empowers enterprise platform teams to improve the developer experience by delivering self-service capabilities for provisioning full-stack environments.
To meet the growing demand for Oracle Container Engine for Kubernetes (OKE) with global organizations, Oracle Cloud Infrastructure (OCI) is introducing new capabilities that can boost the reliability and efficiency of large-scale Kubernetes environments while simplifying operations and reducing costs.
Perforce Software joined the Amazon Web Services (AWS) Independent Software Vendor (ISV) Accelerate Program and listed its free Enhanced Studio Pack (ESP) in AWS Marketplace.
Aembit, an identity platform that lets DevOps and Security teams discover, manage, enforce, and audit access between federated workloads, announced its official launch alongside $16.6M in seed financing from cybersecurity specialist investors Ballistic Ventures and Ten Eleven Ventures.
Hyland released Alfresco Content Services 7.0 – a cloud-native content services platform, optimized for content model flexibility and performance at scale.
CAST AI has announced the closing of a $20M investment round.
Check Point® Software Technologies introduced Infinity Global Services, an all-encompassing security solution that will empower organizations of all sizes to fortify their systems, from cloud to network to endpoint.
OpsCruise's Kubernetes and Cloud Service observability platform is certified to run on the Red Hat OpenShift Kubernetes platform.
DataOps.live released an update to the DataOps.live platform, delivering productivity for data teams.
CoreStack and Zensar announced a strategic global partnership. CoreStack will provide its AI-powered NextGen cloud governance and FinOps capabilities, complementing Zensar’s composable cloud operations offering.
Delinea introduced the Delinea Platform, a cloud-native foundation for Delinea's PAM solutions that empowers end-to-end visibility, dynamic privilege controls, and adaptive security.
Sysdig announced a new foundation that will serve as the long-term custodian of the Wireshark open source project.
Talend announced the latest update to Talend Data Fabric, its end-to-end platform for data discovery, transformation, governance, and sharing.