POSTS CATEGORIZED UNDER

security-compliance

June 10th, 2019

5 minute read

At Fugue, we are obsessed with infrastructure baselines and especially with how they are utilized to correct cloud resource misconfiguration and drift—the leading cause of cloud-based data breaches. Baselines are a relatively new concept, so we thought an informative blog post about baselines, what they are, why organizations need them, and how.

June 6th, 2019

3 minute read

Since AWS re:Invent 2018, Fugue has supported two different products: the self-hosted Fugue Platform and the newer Software as a Service (SaaS) Fugue Risk Manager product. Today, we’re thrilled to announce that we have merged capabilities from the two products into a single, unified SaaS solution for autonomous cloud infrastructure security and.

May 24th, 2019

4 minute read

In an earlier blog post, we discussed at a high level how security can shift left regarding cloud infrastructure. In this post, we'll drill in with more detail on how this can be done through the discrete phases of the Software Development Life Cycle (SDLC), beginning with the development phase, and extending through testing, and ultimately all.

May 21st, 2019

6 minute read

 

PCI compliance. You’ve heard about it. You need it, but you are not quite sure what it's about and what’s involved to achieve PCI compliance for the cloud. In this blog, we are delving deeper into PCI compliance: the requirements that are relevant for organizations in the cloud, which organizations should be concerned with PCI, and how to.
April 18th, 2019

2 minute read

Yesterday Fugue announced some new features that make it easier than ever to bring cloud infrastructure environments into compliance, make sure they stay that way, and demonstrate it at any time. Let’s take a look.

April 17th, 2019

4 minute read

We're hearing a lot about “shifting left” these days in the industry, and like most popular terms the meaning can be hard to pin down, and some of the implications buried. This post will focus on how to shift security and compliance left in cloud computing. These two functions are closely related, but the operational aspect of each is quite.

March 28th, 2019

3 minute read

 For any organization that deals with payment transactions online, Payment Card Industry Data Security Standard (PCI DSS) compliance is mandatory. PCI DSS standards apply to all entities that store, process, or transmit cardholder data and are intended to thwart the theft of cardholder information that could happen anywhere in the.

March 25th, 2019

5 minute read

With cloud, security has shifted to the configuration--and misconfigurationof cloud resources. Developers are moving fast, making their own infrastructure decisions, and changing them constantly. The self-service freedom of cloud is a boon for innovation velocity, but mistakes can create infrastructure vulnerabilities that modern cloud threats.

March 8th, 2019

2 minute read

 

Lured by the promise of scalability, cost benefits, innovation and business growth, organizations are rapidly embracing the cloud for their IT resources and processing.  In fact, Gartner predicts that by 2025, 80 percent of enterprises will have shut down their traditional data center in favor of cloud, versus 10% today.

March 7th, 2019

3 minute read

 

There is a lot of talk about DevSecOps these days, and we've been working in the area for years now and have learned some things that work and some that don't. First, we'll give you our view on what DevSecOps is, and then we'll make a few recommendations on how to start doing it and get real results in an hour or two!

 

Jump to Page

1 2 3 4 5
New call-to-action

Secure Your Cloud

Find security and compliance violations in your cloud infrastructure and ensure they never happen again.