Dispatches from Mission Control

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Podcast: Spotlight Interview with Damon Edwards | JupiterOne | Simplified Security Operations

When Shannon Lietz and the team at DevSecOps.org published the DevSecOps Manifesto six years ago, security was uppermost in their minds. The manifesto starts with a

Mark Miller
Jan 29th, 2021
  • SecOps
People, Process, Technology: The Podcast | JupiterOne | Simplified Security Operations

You might have noticed something different, a new name for the podcast, at the beginning of the program today. Keeping a feel of the pulse of the industry is one of

Mark Miller
Jan 27th, 2021
  • SecOps
Unencrypted S3 Buckets Containing CloudTrail Logs | JupiterOne

This is one in a series of short, simple J1 queries that will help you interrogate your AWS environments. The JupiterOne platform used to run these queries is free.

Akash Ganapathi
Jan 21st, 2021
S3 Buckets Granted Full Access to Someone Other Than Account OwnerInterrogate Your AWS Environments | JupiterOne | Simplified Security Operations

In this J1 Query example, we're going to be searching for people who are not the owners of an S3 bucket, but still have full control and meta-permissions for that

Akash Ganapathi
Jan 21st, 2021
People, Process, Technology: The Missing Factor | JupiterOne

You've heard it before, "People, Process, and Technology". It's become a meme and a mantra that has lost meaning through overuse. It headlines hundreds of slide

Mark Miller
Jan 7th, 2021
2020 JupiterOne Year in Review - Bigger, Better, Easier | JupiterOne

Thank you for being part of our growing community at JupiterOne. Sincerely, thanks for your support in 2020 as we continue to grow the J1 universe. We are truly happy

Mark Miller
Dec 29th, 2020
JupiterOne Visual Query BuilderVideo Overview (4 minutes)

Hello, my name is Henry Garrett. I developed the J1 Visual Query Builder to help you understand our query language and use a "no code" solution to write your own J1QL

Henry Garrett
Dec 21st, 2020
Cyber Asset Relationships Matter - Analyzing Relationship Mapping

In Cyber Asset Relationships Matter – Part One, we defined what the term "cyber asset relationship" means and explained the importance of modeling those relationship

JupiterOne Team
Dec 17th, 2020
  • CAASM
  • SecOps
`deferred-maintenance` CLI tool | JupiterOne

As we go through our days as developers, there is a tendency for certain types of maintenance activity to be deprioritized or forgotten about. It might be because

Erich Smith
Dec 14th, 2020
  • SecOps
Cyber Asset Relationships Matter - Part One | JupiterOne

Relationships matter. They matter in life, they matter in business, they matter in nearly everything we do. This is especially true when it comes to your cyber assets

JupiterOne Team
Dec 11th, 2020
  • CAASM
  • SecOps
Cyber Assets - The Future of Cybersecurity | JupiterOne

In 2020, as we round out what has turned out to be a terrible start to the new decade, cyberattacks and breaches continue trending up. Threats are growing faster than

Tyler Shields
Dec 3rd, 2020
Sampling Based Security – An Outdated Approach | JupiterOne

If all it takes is one bad apple to spoil the entire bunch, should the owner of an apple orchard do a statistical sampling to look for the bad apple, or should they

Erkang Zheng
Nov 11th, 2020
  • CAASM
  • GRC
JupiterOne Announces $19M A Round | JupiterOne

Three years ago, I joined LifeOmic, the latest of three companies founded by successful serial entrepreneur Donald Brown, with the crazy idea of building a startup in

Erkang Zheng
Sep 17th, 2020
Finding risky OAuth scopes in G Suite | JupiterOne

I recently discovered an open source Google Apps script from Slack that describes some difficult questions one of their engineers was asking about their G Suite organ

Austin Kelleher
Sep 10th, 2020
  • CAASM
  • SecOps
Why Do Compliance as Code | JupiterOne

Whether it's a self-assessment or an official audit or examination, evidence collection is central to how you evaluate your organization's compliance with security

JupiterOne Team
May 12th, 2020
  • GRC
JupiterOne Completes SOC 2 Type 2 | JupiterOne

LifeOmic, the creator of JupiterOne, the LIFE mobile apps and the Precision Health Cloud platform in use at major medical and cancer centers, today announced the

JupiterOne Team
May 12th, 2020
What is Asset Discovery? | JupiterOne | Simplified Security Operations

For most organizations – whether cloud-native or going through a digital transformation – managing your cloud and non-cloud digital assets has followed form with

JupiterOne Team
May 8th, 2020
  • CAASM
  • SecOps
Building a Streamlined Cyber Risk Assessment Process using Jira and JupiterOne | JupiterOne | Simplified Security Operations

Risk assessment is a foundational step to any security governance program. It is a mandatory step by regulations and compliance frameworks like HIPAA and GDPR.

Erkang Zheng
Apr 10th, 2020
  • SecOps
Quickly Spot Desk Top Vulnerabilities | JupiterOne | Simplified Security Operations

Printed confidential information remains one of the leading culprits of data breaches organizations faced. But why is something like this still happening when a

JupiterOne Team
Apr 1st, 2020
RSA 2020 | JupiterOne | Simplified Security Operations

RSA 2020 | JupiterOne | Simplified Security Operations

JupiterOne Team
Mar 30th, 2020
  • SecOps
Intelligent Security Remediation | JupiterOne

For most cloud-based organizations, the number of resources, services and users make keeping up with changes across your digital environment nearly impossible.

JupiterOne Team
Mar 26th, 2020
  • CAASM
  • SecOps
Reduce Noise when Analyzing User MFA Status with Graph Queries

There is no doubt multi-factor authentication (MFA) is a simple and effective way to reduce account compromise, yet only 11% of all enterprise accounts use a MFA

Erkang Zheng
Mar 17th, 2020
  • SecOps
The Devil's in the (Meta) Details | JupiterOne

Whether you are gathering evidences for SOC 2 Type II or just doing some vulnerability analysis and reporting, data reliability is critical. Your confidence in your

JupiterOne Team
Mar 11th, 2020
  • CAASM
  • SecOps
JupiterOne & Reddit at RSA | JupiterOne

Last week, LifeOmic CISO and JupiterOne Founder Erkang Zheng spoke with Reddit CISO Sean Catlett at RSA Confererce 2020.

JupiterOne Team
Mar 4th, 2020
  • CAASM
Building Compliance Evidence Download with a Functional Pipeline

One of the newer features of JupiterOne is the ability to download all evidence for a compliance standard. This feature collects the compliance requirements, question

JupiterOne Team
Feb 5th, 2020
  • GRC
Vuls & Gitleaks Integrations | JupiterOne

Cloud-based organizations are increasingly leveraging open-sourced tools to help in their security and compliance monitoring. Whether it's trying to keep a handle on

JupiterOne Team
Jan 22nd, 2020
  • SecOps
2019 Year in Review | JupiterOne | Simplified Security Operations

As we look forward to the last week of 2019, with 2020 patiently waiting for us, we wanted to dive into some of the data highlighting how JupiterOne is helping dozens

JupiterOne Team
Dec 23rd, 2019
SecOps Breadth vs Depth | JupiterOne | Simplified Security Operations

Which approach to managing security operations has a greater impact on security posture?

JupiterOne Team
Dec 13th, 2019
  • CSPM
  • SecOps
Finding Security Budget | JupiterOne | Simplified Security Operations

Security budgets are growing and that trend is expected to continue in the coming year. However, that growth is built more on security fears, privacy concerns and

JupiterOne Team
Nov 13th, 2019
  • CAASM
  • GRC
Out of the Box Insights | JupiterOne | Simplified Security Operations

When you know exactly what you are looking for, it should be easier – not harder – to get to the data. But security teams know this is rarely the case. Think about

JupiterOne Team
Nov 13th, 2019
  • CAASM
  • SecOps
The Path to SOC 2 Compliance | JupiterOne | Simplified Security Operations

As we have noted in a previous blog post, leading SaaS and cloud-based organizations seeking to move upstream in customer acquisition or looking to improve their

JupiterOne Team
Nov 12th, 2019
  • GRC
Introducing Insights Dashboards | JupiterOne

We recently launched a new feature shortening the amount of time it takes for your team to get to the data they need to take necessary actions. Here is an overview of

JupiterOne Team
Sep 30th, 2019
Keeping Security Up to the Speed of DevOps | JupiterOne

JupiterOne CEO Erkang Zheng attended last weeks DevSecCon in Seattle, highlighting what it takes for security teams to keep up with the speed of DevOps.

JupiterOne Team
Sep 26th, 2019
  • SecOps
Capital One Breach: Is your AWS environment just as susceptible?

It's been a little over a week since the coverage of the Capital One data breach. The impact of 100 million plus records that were compromised breathed gasoline onto

Erkang Zheng
Aug 9th, 2019
  • CSPM
  • CAASM
Overcoming the Data Navigation Challenge | Simplified SecOps

Introducing the latest functionality within JupiterOne's Asset Inventory features.

JupiterOne Team
Jun 14th, 2019
  • CAASM
  • SecOps
HIPAA versus GDPR

SaaS and cloud-providers operating in the healthcare space have to tackle HIPAA compliance. Once you've done that, a common question we hear is "how do I stack up

JupiterOne Team
Jun 7th, 2019
  • GRC
Building an Effective Security Program | Simplified Security Operations

In order to build a sound and secure SaaS product, organizations have to create a thorough and scalable security program. This program will ensure your team has a

JupiterOne Team
Jun 5th, 2019
  • SecOps
No Time for SecOps | JupiterOne | Simplified Security Operations

When only a few spare minutes can be spent on proactive security operations, what should you do?

JupiterOne Team
Jun 3rd, 2019
  • SecOps
Simplifying Security and Compliance with Amazon Neptune

Most organizations take a linear, list-based approach to security operations. It's a two-dimensional process. First, identify resources. Second, manage their

Erkang Zheng
May 17th, 2019
  • GRC
  • SecOps
We Turned Off AWS Config | JupiterOne

That's right. It wasn't a typo. After enabling AWS Config across five of our AWS accounts, we decided to remove all but two of our Config rules. But why?

Erkang Zheng
Apr 19th, 2019
  • CSPM
  • CAASM
JupiterOne Compliance Dashboard

Security Assurance never looked so good. Security analysts and teams face a tall task when it comes to deploying new resources, team members and devices at scale

JupiterOne Team
Apr 9th, 2019
  • CSPM
  • CAASM
  • GRC
Making Security a Feature of your SaaS Tool | JupiterOne

The deals are slower, more complex and full of legalize and redlines, but many SaaS providers look upstream as an opportunity to unlock their true potential.

JupiterOne Team
Apr 2nd, 2019
Transforming Security Operations JupiterOne

Watch LifeOmic CISO and JupiterOne General Manager Erkang Zheng walk through how to leverage a graph-based database and search functionality to simplify security

JupiterOne Team
Mar 26th, 2019
  • CAASM
  • SecOps
Top 8 Components of a 2019 Security Awareness Program

Awareness training, after an incident, is about as valuable as an oven mitt after burning your hand taking something out of the oven. It's important to proactively

JupiterOne Team
Mar 6th, 2019
New Integrations: G Suite and Veracode

We are excited to announce JupiterOne's latest integrations with G Suite and Veracode in an ongoing effort to centralize and simplify security operations, helping

JupiterOne Team
Mar 4th, 2019
Remediating Security Vulnerabilities and Threats

We are inundated with stories around security vulnerabilities and breaches all of the time. So how to we wade through the alerts and take action remediating security

JupiterOne Team
Feb 25th, 2019
  • SecOps
BSidesSLC 2019 | JupiterOne | Simplified Security Operations

BSidesSLC 2019 | JupiterOne | Simplified Security Operations

Erkang Zheng
Feb 22nd, 2019
6 Foundational Tips for AWS Security

Unlimited and instant scalability. Pay per use. Globally distributed infrastructure. These are just some of the reasons organizations have turned to the cloud.

JupiterOne Team
Feb 20th, 2019
  • CSPM
  • CAASM
  • SecOps
Cyber Security Layers | JupiterOne

Cyber security represents all of the below efforts and lengths an organization will go to to prevent themselves from cyber attacks. This onion is a good

JupiterOne Team
Feb 14th, 2019
  • CAASM
  • GRC
  • SecOps
Healthcare Security Frameworks

Understanding adoption and popularity of different security frameworks for Healthcare Organizations and how we expect that to change in 2019

JupiterOne Team
Feb 11th, 2019
  • GRC
Three Dimensional Security

I am going to skip the small talk about the security landscape, how much it all sucks and how we are all doomed and get straight to the point.

Erkang Zheng
Jan 28th, 2019
  • CAASM
  • SecOps
SecOps: An Exercise in Time Management

In security operations, time is the ultimate currency. Your path to security assurance is dependent on time. Producing compliance evidence, identifying

JupiterOne Team
Jan 23rd, 2019
  • SecOps
Priming your security operations | JupiterOne

The end of December can be a tremendously productive time of year for teams. With customers and coworkers beginning to take time off, the demands on time begin to

JupiterOne Team
Jan 4th, 2019
  • CAASM
  • SecOps
What is NIST CSF?

The NIST cybersecurity framework is a risk-based, rather than compliance drive, cybersecurity document. This approach means organizations focus on real risks and

JupiterOne Team
Dec 20th, 2018
  • CAASM
  • SecOps
Compliance Doesn't Matter

Effective plans start with a goal. For security and operations, compliance isn't that goal.

JupiterOne Team
Dec 13th, 2018
  • CSPM
  • CAASM
  • GRC
Security Should Fuel Business Growth. Why Doesn't It?

When you think about cloud security, it's easy to see the similarities between managing one's digital infrastructure and flying a plane. Inside of a cockpit there are

JupiterOne Team
Dec 6th, 2018
  • CAASM
4 Things Every Business Should Do after a Public Data Breach

Here we go again. Just last week there have been more major data breaches and hacks. Those organizations include Marriott, the nation's largest hotel chain, Amazon,

JupiterOne Team
Dec 3rd, 2018
  • CSPM
  • CAASM
  • SecOps
What is HITRUST?

HITRUST is both a risk- and compliance-based, certifiable, cybersecurity framework that provides organizations with a comprehensive, flexible and efficient approach

JupiterOne Team
Nov 20th, 2018
  • GRC
What Does Digital Transformation Mean for Security and Compliance?

I recently attended the Gartner Symposium ITXpo in Orlando, with nearly 10,000 other CIOs and IT leaders. It was an exciting week with conversations concentrated

Erkang Zheng
Nov 14th, 2018
  • CAASM
  • GRC
  • SecOps
Finding a cure to the cyber breach pandemic  - JupiterOne is here

Let's be honest. This is a mess. We are losing in the battle of cybersecurity. There is no stopping the attacks.

Erkang Zheng
Sep 5th, 2018
  • SecOps