Wednesday, January 9, 2019

Container Security - If we continue to follow the traditional scanning process then we have a problem - Nearly half of all companies know that they're deploying containers with security flaws, according to a new survey. 60% of those surveyed say that their organization suffered a container security breach in the last year.



"The way to address container security is to build security controls into the DevOps process. If you're looking for vulnerabilities or mis-compliance, you want to find them in the build ahead of deployment, and you want to make sure the process will allow them to be fixed before deploying,"

The solution for the container security problem lies in the development cycle, Erlin says. "The way to address container security is to build security controls into the DevOps process. If you're looking for vulnerabilities or mis-compliance, you want to find them in the build ahead of deployment, and you want to make sure the process will allow them to be fixed before deploying," he explains.

Too many companies are using traditional security scanning processes, in which they scan for vulnerabilities when the application is deployed, and then try to fix issues in a DevOps process — and they're finding that it doesn't work, Erlin says. The problem isn't primarily with the tools they're using.

"I don't think this is a technology challenge as much as an adoption challenge. " Erlin says. Looking ahead, though, he sees promise in the form of new employees being hired to work with containers.

https://www.darkreading.com/vulnerabilities-and-threats/container-deployments-bring-security-woes-at-devops-speed/d/d-id/1333622

No comments:

Post a Comment