Tag: DevSecOps
All the articles with the tag "DevSecOps".
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Private Repository#DevSecOps#Supply Chain Security
Private Repositories Security Review Process
A practical process for reviewing, approving, and continuously reassessing third-party artifacts before internal use.
4 min read - #AWS#ECR#EKS
Private ECR Delivery Architecture for Private EKS
A defense-in-depth design for delivering approved private ECR artifacts to private EKS workloads.
Updated:15 min read - #Contribution#Supply Chain Security#NIST SP 800-204
Private Registries and Package Mirrors: What I Contributed to the SEAL Security Frameworks
A new SEAL Security Frameworks page on internal package registries - what mirroring defends against, how routing blocks dependency confusion, and why the registry becomes a trust component in its own right.
11 min read - #Contribution#CI/CD Security#Supply Chain Security
Policy as Code Through the CI/CD Pipeline: What I Contributed to the SEAL Security Frameworks
A four-page section on policy as code across the CI/CD pipeline, mapped to NIST SP 800-204D, merged into the SEAL Security Frameworks.
11 min read - #NIST#NIST SP 800-218#NIST SP 800-204D
Relationship Between NIST SP 800-218 and SP 800-204D
Review the relationship between NISTP SP 800-218 and SP 800-204D. Walk through how the SSDF specifically focuses on cloud-native application CI/CD pipelines
11 min read - #SSDF#NIST#NIST SP 800-218
NIST SP 800-218(SSDF)
Secure Software Development Framework enhanced by Software Supply Chain Attack.
22 min read - #DevSecOps#DoD
DoD DevSecOps Strategy and Implementation Docs
DevSecOps documents structure of U.S Department of Defense.
5 min read