You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Cloud Native Maturity Model requires further security and compliance updates.
Some points are as follow: Security Scanning
Should this be emphasised through the software supply chain such as a build time as well as runtime?
What about fuzzing? Should this be a practice undertaken? The CNCF is fuzzing graduated projects.
Security Divisions within Organisations
What role do these play and for example how often should product or infrastructure teams engage with them?
What is the scope of their "powers"? Should they have the ability to direct that business critical systems be shut down or should their role be more advisory?
Access to CSP portals and tooling for developers
Should developers have direct access to cloud service provider portals and tooling or should this be arbitrated by internal tooling?
Should more senior developers have different access compared to junior developers?
Measuring Compliance
We can measure MTTR and other metrics relating to resilience but how do we measure GDPR? Is this something organisations should aspire to?
The text was updated successfully, but these errors were encountered:
The Cloud Native Maturity Model requires further security and compliance updates.
Some points are as follow:
Security Scanning
Should this be emphasised through the software supply chain such as a build time as well as runtime?
What about fuzzing? Should this be a practice undertaken? The CNCF is fuzzing graduated projects.
Security Divisions within Organisations
What role do these play and for example how often should product or infrastructure teams engage with them?
What is the scope of their "powers"? Should they have the ability to direct that business critical systems be shut down or should their role be more advisory?
Access to CSP portals and tooling for developers
Should developers have direct access to cloud service provider portals and tooling or should this be arbitrated by internal tooling?
Should more senior developers have different access compared to junior developers?
Measuring Compliance
We can measure MTTR and other metrics relating to resilience but how do we measure GDPR? Is this something organisations should aspire to?
The text was updated successfully, but these errors were encountered: