What’s New
LatestMost ReadFrom Our Sponsor
ABO and the Mystical Art of Source Code Compilation
Compilation can make or break the performance quality of an application. A developer might spend weeks creating the most elegant, efficient algorithm known to man, only to have it run at a snail’s pace in production because the compiler used to create the application’s executable binary is old, and not ... Read More
4 Steps to Introduce DevSecOps to Database Development
Although DevOps was implemented within application development, there is a growing awareness that including the database within DevOps processes is vital to success. We live in a data-driven world and many front-end applications use a database at the back end to collect, process and store customer and user data. The ... Read More
4 Steps to Improving Your Team’s Continuous Security
A recent npm survey revealed that 77 percent of developers were concerned about the quality and security of the open source libraries they use, while 52 percent said the tools currently available were inadequate. Given the trust issues in open source and the ongoing discovery of website and application vulnerabilities, ... Read More
API Security: A Key Part of the Bigger Plan
Standing as the “fuel” powering the customer-driven platform revolution, application programming interfaces (APIs) are the new “it thing” amongst operating systems. APIs are responsible for how apps communicate with each other and have become key components in many digital transformation strategies. Serving as a set of tools for building software ... Read More
Announcing DevOps Connect: DevSecOps Days Virtual Summit
We just wrapped up our fifth annual DevSecOps Days @ RSA Conference 2019, featuring an exceptional lineup of speakers and a variety of informative sessions, providing an unparalleled experience for all. If you couldn’t make it to San Francisco for RSAC or missed any sessions, we’ll be hosting a virtual ... Read More
DevSecOps: Fortanix Adds Open Source Rust SDK to Build Encrypted Apps
There’s a lot of focus these days on DevSecOps as part of an effort to fix what’s generally acknowledged as a broken cybersecurity paradigm. But instead of trying to ensure every potential vulnerability is addressed before an application is deployed, another idea is gaining momentum among the DevOps community: Build ... Read More
Survey Finds Mixed Progress on DevSecOps
A survey of 5,558 IT professionals published today by Sonatype in collaboration with CloudBees, Carnegie Mellon’s Software Engineering Institute, Signal Sciences, 9th Bit and Twistlock finds 27 percent of organizations have mature DevOps practices in place, while another 48 percent are still working on improving them. Despite the DevOps works ... Read More
DevOps Chat: AppSec and DevSecOps with Contrast Security’s Jeff Williams
I have known of Jeff Williams in the security industry for more than several years. He is a well-respected thought leader in AppSec and OWASP. I finally got a chance to catch up with Jeff and talk with him about Contrast Security, the company he co-founded and how it is ... Read More
DevOps and Security: The Path to DevSecOps
A secure DevOps is highly beneficial for organizations. However, a secure DevOps environment shouldn’t be the end goal. When it comes to DevOps security, it’s important to integrate security right from scratch, secure the entire architecture, automate the security and use this technology to test the environment and the codes ... Read More
DevOps Chat: Repos and Nexus Firewall Access, with Sonatype
There are really only two repositories of any scale for software components today: the Nexus repo managed by Sonatype and the Artifactory artifact repo managed by JFrog. Up until now they were separate and apart, and working with one was independent of another. In a big move toward keeping DevOps ... Read More
Announcing DevOps Connect: DevSecOps Days Virtual Summit
We just wrapped up our fifth annual DevSecOps Days @ RSA Conference 2019, featuring an exceptional lineup of speakers and a variety of informative sessions, providing an unparalleled experience for all. If you couldn’t make it to San Francisco for RSAC or missed any sessions, we’ll be hosting a virtual ... Read More
9 Pillars of Continuous Security Best Practices
Without proper consideration given to security best practices, the continuous delivery of software changes facilitated by DevOps is risky. On the other hand, DevOps provides an opportunity to reduce security risks if security is integrated into the continuous delivery pipeline according to best practices. This blog enumerates best practices for ... Read More
Applying DevSecOps to Address Cloud Security Challenges
Driven by the encouragement from 2018 progress, cloud technology is poised to be even bigger in 2019. However, one major hurdle continues to haunt the cloud trend: security. An overwhelming number of firms in the IT industry are preparing for cloud adoption, yet security continues to be a big question for ... Read More
DevOps Chat: Identity Management with ForgeRock’s Peter Barker
Two megatrends for 2019 and beyond is scale and automation. The identity management space is a perfect example. Considering all of the IP-enabled devices (machines) coming online and the billions of people and their identities, managing these billions and billions takes systems that will redefine scale and, almost by definition, ... Read More
Always-on Development: Why Continuous Delivery Relies on Security by Design
How continuous delivery can help organizations in their application security efforts The old model of developing secure applications followed a structured, siloed, step-by-step process—build, check, release. Organizations’ desire for speed has forced development teams to ramp up their release cycles by any means necessary, even if it means bypassing incremental ... Read More
Security and Speed: Why DevOps and Security Need to Play Nicely
It isn’t news that DevOps and IT security teams often struggle to align their departments and maintain a coherent balance between keeping a business secure and developing new applications to maintain customer interest. While security processes are a necessity, they can be deemed by DevOps teams to be manual and ... Read More
DevOps and Security: The Path to DevSecOps
A secure DevOps is highly beneficial for organizations. However, a secure DevOps environment shouldn’t be the end goal. When it comes to DevOps security, it’s important to integrate security right from scratch, secure the entire architecture, automate the security and use this technology to test the environment and the codes ... Read More
IoT, Not People, Now the Weakest Link in Security
Do a quick search on “people weakest link” and you’ll see a raft of articles in which cybersecurity experts and computer scientists point to employees or end users as the biggest vulnerability. No doubt, people do silly (or outright abusive) stuff and open the door for a variety of enterprise ... Read More
Study: CISOs Need to Take Charge of DevOps Security
A new report from CyberArk looks at the complexity that goes into securing emerging DevOps environments, and why CISOs need to take charge to protect them. As digital transformation is pushing more enterprises to adopt DevOps to address their needs for better software delivered faster and more frequently, a huge ... Read More
DevSecOps: Old Security Bugs Still Performing New Tricks
New Security Flaws Creep into Reliable Old Systems In cybersecurity, we are often like hunters. Our eyes are firmly glued to the horizon, scanning for the next breakout vulnerability (along with the right designing tools, techniques and tactics to stop it). However, this forward-looking focus can have the surprising effect ... Read More
Featured Articles, Papers and more...
Pervasive Encryption – A New Paradigm for Protection
This whitepaper examines the real-world impact on business security based on platform architecture. For that purpose, metrics for major architectures such as IBM’s z Systems ... Read More
Why pervasive encryption is the future of data security
The truth about Data breaches is that they are costly. A recent Ponemon study found that the average cost of a breach in 2017 was ... Read More
Bringing high-speed, low-cost, low-risk development to core banking systems
IT service provider Fiducia & GAD IT AG has introduced Java alongside COBOL within IBM® IMS™ on IBM z Systems®. By Java-enabling existing IMS core ... Read More
Offers customers the best of two worlds: stability of the mainframe and agility for the digital age
Fujitsu wanted to help its VME customers bring their enterprise applications into the digital age. It provides new services that utilize IBM® Application Discovery and ... Read More
IDC: Leveraging Effective Application Discovery, Delivery, Change, and Quality Strategies for Digital Transformation
This white paper discusses the evolution of organizations on their quest for digital transformation, examining pain points experienced by those who haven’t yet committed to ... Read More
Digital Transformation with IBM Application Discovery
This IBM® Redpaper™ publication describes how IBM Application Discovery (AD) complements IBM z/OS® Connect Enterprise Edition and IBM Developer for z Systems® in making older ... Read More
A Visionary Approach to Transforming IBM Z Development
A visionary approach always entails that the result is all encompassing, and transformative, rather than piecemeal and partial. This is the fundamental underpinning of the ... Read More
Ten New Steps to DevOps Success
Application development doesn’t stand still. There are always new resources. New methodologies. New user expectations. As enterprise development teams adapt their business-critical applications to today’s ... Read More
Application Discovery & Delivery Intelligence – ROI Calculator
How much can you save by implementing ADDI? The Application Discovery & Delivery Intelligence (ADDI) platform uses cognitive technology to analyze mainframe applications and provide ... Read More
IBM z/OS Connect trial
Start on your trial right away. No need to enter your credit card info. Get working in just a few short steps. Your trial environment ... Read More
Featured Videos
Featured Webinars
Is a Monolith Standing in the Way of Your Digital Transformation? Refactor for Better Agility
Monolithic applications are defined as single-tiered software in which the user interface and data access code is combined into a single application for a single platform. Monoliths can impact your ability to create APIs, deliver capability quickly, and even perform routine application maintenance. Refactoring is the antidote to monolithic software ... Read More
Replace Outdated DevOps Tools with Innovative & Modern Pipelines
In this webinar, learn how an open toolchain (including Git, SonarQube, IBM UrbanCode Deploy, and IBM Dependency Based Build)Â is key to driving a modern pipeline. Experts Rosalind Radcliffe and Suman Gopinath will demonstrate where traditional z/OS applications can fit in an existing modern toolchain with minimal modifications. Your developers can ... Read More
Featured Demos



