Monday, February 8, 2021

Third-party Governance for DevSecOps

For orgs that rely heavily upon outsourced development/technical resources (IT Outsourcing: ITO), it's important to ensure that contracts include covenants for the vendor to provide cyber (security) education, training & awareness (SETA).

Furthermore, a right to audit clause should be included as well that allows for the client to review SETA content, as well as attendance & scoring.    

Monday, January 11, 2021

Why are big data tools so darn expensive...?

 As we build out our web endpoint security scorecard (WESSy) I am in awe of the price points I see for data tools.

I get that these are enterprise-level tools; however, for smaller shops (like mine) that need this functionality it comes off as cost prohibitive.