When Shannon Lietz and the team at DevSecOps.org published the DevSecOps Manifesto six years ago, security was uppermost in their minds. The manifesto starts with a
You might have noticed something different, a new name for the podcast, at the beginning of the program today. Keeping a feel of the pulse of the industry is one of
This is one in a series of short, simple J1 queries that will help you interrogate your AWS environments. The JupiterOne platform used to run these queries is free.
In this J1 Query example, we're going to be searching for people who are not the owners of an S3 bucket, but still have full control and meta-permissions for that
You've heard it before, "People, Process, and Technology". It's become a meme and a mantra that has lost meaning through overuse. It headlines hundreds of slide
Thank you for being part of our growing community at JupiterOne. Sincerely, thanks for your support in 2020 as we continue to grow the J1 universe. We are truly happy
Hello, my name is Henry Garrett. I developed the J1 Visual Query Builder to help you understand our query language and use a "no code" solution to write your own J1QL
In Cyber Asset Relationships Matter – Part One, we defined what the term "cyber asset relationship" means and explained the importance of modeling those relationship
As we go through our days as developers, there is a tendency for certain types of maintenance activity to be deprioritized or forgotten about. It might be because
Relationships matter. They matter in life, they matter in business, they matter in nearly everything we do. This is especially true when it comes to your cyber assets
In 2020, as we round out what has turned out to be a terrible start to the new decade, cyberattacks and breaches continue trending up. Threats are growing faster than
If all it takes is one bad apple to spoil the entire bunch, should the owner of an apple orchard do a statistical sampling to look for the bad apple, or should they
Three years ago, I joined LifeOmic, the latest of three companies founded by successful serial entrepreneur Donald Brown, with the crazy idea of building a startup in
I recently discovered an open source Google Apps script from Slack that describes some difficult questions one of their engineers was asking about their G Suite organ
Whether it's a self-assessment or an official audit or examination, evidence collection is central to how you evaluate your organization's compliance with security
LifeOmic, the creator of JupiterOne, the LIFE mobile apps and the Precision Health Cloud platform in use at major medical and cancer centers, today announced the
For most organizations – whether cloud-native or going through a digital transformation – managing your cloud and non-cloud digital assets has followed form with
Risk assessment is a foundational step to any security governance program. It is a mandatory step by regulations and compliance frameworks like HIPAA and GDPR.
Printed confidential information remains one of the leading culprits of data breaches organizations faced. But why is something like this still happening when a
For most cloud-based organizations, the number of resources, services and users make keeping up with changes across your digital environment nearly impossible.
There is no doubt multi-factor authentication (MFA) is a simple and effective way to reduce account compromise, yet only 11% of all enterprise accounts use a MFA
Whether you are gathering evidences for SOC 2 Type II or just doing some vulnerability analysis and reporting, data reliability is critical. Your confidence in your
One of the newer features of JupiterOne is the ability to download all evidence for a compliance standard. This feature collects the compliance requirements, question
Cloud-based organizations are increasingly leveraging open-sourced tools to help in their security and compliance monitoring. Whether it's trying to keep a handle on
As we look forward to the last week of 2019, with 2020 patiently waiting for us, we wanted to dive into some of the data highlighting how JupiterOne is helping dozens
Security budgets are growing and that trend is expected to continue in the coming year. However, that growth is built more on security fears, privacy concerns and
When you know exactly what you are looking for, it should be easier – not harder – to get to the data. But security teams know this is rarely the case. Think about
As we have noted in a previous blog post, leading SaaS and cloud-based organizations seeking to move upstream in customer acquisition or looking to improve their
We recently launched a new feature shortening the amount of time it takes for your team to get to the data they need to take necessary actions. Here is an overview of
JupiterOne CEO Erkang Zheng attended last weeks DevSecCon in Seattle, highlighting what it takes for security teams to keep up with the speed of DevOps.
It's been a little over a week since the coverage of the Capital One data breach. The impact of 100 million plus records that were compromised breathed gasoline onto
SaaS and cloud-providers operating in the healthcare space have to tackle HIPAA compliance. Once you've done that, a common question we hear is "how do I stack up
In order to build a sound and secure SaaS product, organizations have to create a thorough and scalable security program. This program will ensure your team has a
Most organizations take a linear, list-based approach to security operations. It's a two-dimensional process. First, identify resources. Second, manage their
That's right. It wasn't a typo. After enabling AWS Config across five of our AWS accounts, we decided to remove all but two of our Config rules. But why?
Security Assurance never looked so good. Security analysts and teams face a tall task when it comes to deploying new resources, team members and devices at scale
The deals are slower, more complex and full of legalize and redlines, but many SaaS providers look upstream as an opportunity to unlock their true potential.
Watch LifeOmic CISO and JupiterOne General Manager Erkang Zheng walk through how to leverage a graph-based database and search functionality to simplify security
Awareness training, after an incident, is about as valuable as an oven mitt after burning your hand taking something out of the oven. It's important to proactively
We are excited to announce JupiterOne's latest integrations with G Suite and Veracode in an ongoing effort to centralize and simplify security operations, helping
We are inundated with stories around security vulnerabilities and breaches all of the time. So how to we wade through the alerts and take action remediating security
Unlimited and instant scalability. Pay per use. Globally distributed infrastructure. These are just some of the reasons organizations have turned to the cloud.
Cyber security represents all of the below efforts and lengths an organization will go to to prevent themselves from cyber attacks. This onion is a good
In security operations, time is the ultimate currency. Your path to security assurance is dependent on time. Producing compliance evidence, identifying
The end of December can be a tremendously productive time of year for teams. With customers and coworkers beginning to take time off, the demands on time begin to
The NIST cybersecurity framework is a risk-based, rather than compliance drive, cybersecurity document. This approach means organizations focus on real risks and
When you think about cloud security, it's easy to see the similarities between managing one's digital infrastructure and flying a plane. Inside of a cockpit there are
Here we go again. Just last week there have been more major data breaches and hacks. Those organizations include Marriott, the nation's largest hotel chain, Amazon,
HITRUST is both a risk- and compliance-based, certifiable, cybersecurity framework that provides organizations with a comprehensive, flexible and efficient approach
I recently attended the Gartner Symposium ITXpo in Orlando, with nearly 10,000 other CIOs and IT leaders. It was an exciting week with conversations concentrated