<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Container on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/container/</link>
    <description>Recent content in Container on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 15 Jun 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/container/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Modern Application Stacks &amp; Security</title>
      <link>https://insinuator.net/2018/06/modern-application-stacks-security/</link>
      <pubDate>Fri, 15 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/modern-application-stacks-security/</guid>
      <description>&lt;p&gt;I had the pleasure to give a presentation at the &lt;a href=&#34;https://www.sig-switzerland.ch/conference/sigs-technology-conference/&#34;&gt;Security Interest Group Switzerland Technology Conference&lt;/a&gt; about modern application stacks and how they can be used to improve infrastructure and application security posture – the slides can be found &lt;a href=&#34;https://ernw.de/download/ERNW_SIG_Cloud_ModernAppStackSecurity_mluft.pdf&#34;&gt;here&lt;/a&gt;. Besides seeing a lot of &lt;a href=&#34;https://twitter.com/ioshints&#34;&gt;old friends&lt;/a&gt;, I particularly enjoyed a round table discussion on security integration into CI/CD pipelines. There was a relevant exchange on approaches that actually work and were tested in environments beyond just recommending some container scanner (product). One participant had an interesting case study on how they enabled developers to maintain WAF policies in configuration files in their code repository including automated deployment to the WAF. He also emphasized that the environments with actual security benefits resulted from a close cooperation between development and security team (were domain knowledge was combined 😉 ).&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
