Why container opacity has become a boardroom problem

https://diginomica.com/sites/default/files/images/2018-06/problem.jpg

Some of the biggest enterprise risks sit in the layer underneath applications, including the hypervisors, runtimes, base images and build management pipelines. Unfortunately, these also sit across and sort of outside the scope of any one team like testing, development, operations, or security and compliance. On the cost front, this means it's hard to respond to licensing changes such as Broadcom's VMware re-pricing or Oracle's shift to employee-based Java licensing. On the security front, this layer shows up in new supply chain attacks exemplified by SolarWinds, Log4Shell, and the xz-utils backdoor.

The gist is that most enterprises lack the visibility to respond to these situations as they occur. And the clock is ticking faster, with new resiliency regulations coming online in Europe, the use of AI to discover zero-days long buried in existing artifacts, and creative efforts to compromise the supply chains those artifacts are built on. Organizations that can't...

Copyright of this story solely belongs to diginomica.com. To see the full text click HERE

Read more