11 subscribers
התחל במצב לא מקוון עם האפליקציה Player FM !
פודקאסטים ששווה להאזין
בחסות


1 Throwing good parties and building community (w/ Priya Parker) 38:16
When Will IT Security Escape the Cat-and-Mouse Game? with Sean Atkinson, CISO of CIS
Manage episode 418563488 series 2865112
When Sean Atkinson says that “We’re on a trajectory to have the most vulnerabilities ever identified in a single year, starting this year,” take note: As Chief Information Security Officer for the Center for Internet Security, he knows what he’s talking about.
He’s referring to the ever-increasing tide of weaknesses and flaws that undermine the security of software used every single day by teams around the world. Between a more active threat landscape, demands for development velocity, and the rise of generative AI, the cat in this proverbial game of cat-and-mouse has their work cut out for them.
In this conversation, Robin Tatam, Puppet’s Evangelist and Certified Information Security Manager, talks with Sean about the role of a CISO, what’s behind the unprecedented rise in vulnerabilities, and how smart integrations turn automation into a first-line defense against threats, misconfiguration, errors, and software vulnerabilities.
Highlights:
- What a CISO actually does versus a CIO or a CTO
- The difference between “security” and “compliance”
- How compliance helps build the backbone of a long-term security posture
- Who really owns IT security and where IT operations fits into the security conversation
- What CIS Benchmarks are, what they do, and how CIS “wizards” keep them up-to-date on the latest vulnerabilities
- How Puppet’s partnership with CIS puts the power of automation behind CIS’s widely recognized frameworks
Speakers:
- Robin Tatam, Senior Technical Marketer and Evangelist, Puppet by Perforce
- Sean Atkinson, Chief Information Security Officer, Center for Internet Security
Links:
- Learn more about Security Compliance Enforcement, a premium feature for Open Source Puppet and Puppet Enterprise that automates secure configurations hardened against CIS Benchmarks and DISA STIGs
- Listen to Sean’s podcast with CIS, “Cybersecurity Where You Are,” wherever you get podcasts
Find Us Online:
57 פרקים
Manage episode 418563488 series 2865112
When Sean Atkinson says that “We’re on a trajectory to have the most vulnerabilities ever identified in a single year, starting this year,” take note: As Chief Information Security Officer for the Center for Internet Security, he knows what he’s talking about.
He’s referring to the ever-increasing tide of weaknesses and flaws that undermine the security of software used every single day by teams around the world. Between a more active threat landscape, demands for development velocity, and the rise of generative AI, the cat in this proverbial game of cat-and-mouse has their work cut out for them.
In this conversation, Robin Tatam, Puppet’s Evangelist and Certified Information Security Manager, talks with Sean about the role of a CISO, what’s behind the unprecedented rise in vulnerabilities, and how smart integrations turn automation into a first-line defense against threats, misconfiguration, errors, and software vulnerabilities.
Highlights:
- What a CISO actually does versus a CIO or a CTO
- The difference between “security” and “compliance”
- How compliance helps build the backbone of a long-term security posture
- Who really owns IT security and where IT operations fits into the security conversation
- What CIS Benchmarks are, what they do, and how CIS “wizards” keep them up-to-date on the latest vulnerabilities
- How Puppet’s partnership with CIS puts the power of automation behind CIS’s widely recognized frameworks
Speakers:
- Robin Tatam, Senior Technical Marketer and Evangelist, Puppet by Perforce
- Sean Atkinson, Chief Information Security Officer, Center for Internet Security
Links:
- Learn more about Security Compliance Enforcement, a premium feature for Open Source Puppet and Puppet Enterprise that automates secure configurations hardened against CIS Benchmarks and DISA STIGs
- Listen to Sean’s podcast with CIS, “Cybersecurity Where You Are,” wherever you get podcasts
Find Us Online:
57 פרקים
כל הפרקים
×
1 Open Source: “More than a License” but Not Quite a Business Model with Dotan Horovits 35:12

1 When Will IT Security Escape the Cat-and-Mouse Game? with Sean Atkinson, CISO of CIS 34:01

1 The Future of the Forge: Unpacking the Big (and Small) Changes 41:15

1 We Surveyed ~500 People Doing Platform Engineering. Here’s What We Learned. 40:14

1 Your Return-to-Office Plans Will Shape Your Platform. Here’s How. 28:02

1 The Politics of Your Job: Building Trust + Subverting DevOps Hierarchies (Respectfully) with Joshua Zimmerman 33:04

1 Who the Vox Pupuli Are and How They Work with Puppet 35:38

1 What CentOS, RHEL, and HashiCorp’s BSL Mean for the Future of Open Source 43:46

1 The Platform Engineering Pitfall You Aren’t Looking For (Yet) 36:20

1 “Write a Book About Puppet 8,” They Said. “It’ll Be Fun,” They Said. 27:35

1 It's Always Audit Time: Compliance is Coming for Your Department (Yes, Yours) 29:18

1 What It’s Actually Like to Build a Puppet Module 21:52

1 “How Long is a Piece of String?”: All the Ways New Puppet Training Simplifies Complexity 42:11

1 Diving Into the 2023 State of Open Source Report with Javier Perez 43:11

1 The Future of Platform Engineering 37:02

1 The gateway elixir to automated infrastructure testing 22:57


1 The benefits of using Hiera Data Manager 26:02

1 Halloween Edition: 2020 DevOps horror stories 31:00

1 The power of UX design at Puppet 22:50

1 OSP Assist: The one-stop Open Source Portal 21:13


1 Hydra: leveraging Slack to build seamlessly 20:10

1 How to build an awesome open source community 26:31

1 Modules, APIs, & SLAs: Automating Backups with Rubrik & Puppet 18:00

1 All coding and no games keeps the fun away 16:47

1 How to clean up the DevOps dumping ground with Relay 18:52

1 What's new with the Puppet VS Code Extension, anyway? 28:10

1 Continuous Delivery and Cloud Native Infrastructure with Nebula Team 11:58

1 2019 State of DevOps Report chat: Security is boring when it's working 24:05

1 Creating Community with an Employee Resource Group (ERG) 40:33

1 Managing your configuration management system shouldn't be hard 35:52


1 Automating your way to compliance across your entire cloud infrastructure 39:03

1 Practice and prepare for your next security threat 47:59

1 How Puppet's open source DNA is paving the path ahead 47:52

1 The best part of the PowerShell Gallery is that it's on the Puppet Forge 51:21

1 A paradigm shift: Puppet and ServiceNow integrations 35:19

1 Learn at your convenience with Puppet Practice Labs 25:35

1 Being out at work and the importance of role models 26:12

1 CTO Chronicles: The DevOps Edition 36:43

1 The keys to unlock your developer voice 25:10

1 Beaker's past, present and future 24:31

1 Virtualization & Kubernetes: Why another abstraction? 34:18

1 Life after the State of DevOps Report - Scaling DevOps 30:41
ברוכים הבאים אל Player FM!
Player FM סורק את האינטרנט עבור פודקאסטים באיכות גבוהה בשבילכם כדי שתהנו מהם כרגע. זה יישום הפודקאסט הטוב ביותר והוא עובד על אנדרואיד, iPhone ואינטרנט. הירשמו לסנכרון מנויים במכשירים שונים.