SlideShare a Scribd company logo
Mentor’s View: Aligning your team and your
powers for success
Chris Carlucci
Customer Success Engineer
Sonatype
Agenda
2 4/28/2016
• Getting Started on Your Journey
• Open Source Policy Guidelines
• Policy Results in Eclipse & Jenkins
• Meaningful Success Metrics
Getting started on your journey
3 4/28/2016
• Rugged DevOps, Software Supply Chain, Now What?
• The Hero’s Journey
• Align Your Heroes
• Building Bridges
• Setting Expectations
Building A Trusted Software Supply Chain
4 4/28/2016
Different Stakeholders, Different Priorities
5 4/28/2016
Where’s that
release?
Done! On to
the next sprint.
Now, where
are we in that
process?
6 4/28/2016
Building A Better Bridge Between Dev, Ops & Sec
• Tooling needs to adopt the practice of the practitioner
• A tool is not a process and a process is not a tool;
learn to leverage both
Two Philosophies
• Support & guide
• Objective information across
the lifecycle
• Each performs the task they
are good at
• Faster component selection
and issue resolution
• Bridges the developer
“compliance” gap
7 4/28/2016
• Scan & scold
• Reactive information late
in the lifecycle
• Creates rework and slows
remediation
• Hinders technology innovation
• More expensive
8 4/28/2016
Communicate Expectations
Determine lifecycle enforcement strategy:
Allows developers time to research & fix or to request waivers
Everything is documented on an internal WIKI
Development CI Build
Promotion to staging or
release
Fix the Red – Actionable?
9 4/28/2016
Fix the Red – Actionable?
10 4/28/2016
11 4/28/2016
Building A Good Component Practice
Phase 3
Reducing risk & enforcing
compliance
Phase 2
Creating policy &
rating risk
Phase 1
Understanding your environment
Interactive Policy Development
12 4/28/2016
13 4/28/2016
What Is Policy?
14 4/28/2016
Out-of-the-box Policies With Easy Customization
Architecture
Component
License
Security
IQ Server Policy Definition
15 4/28/2016
Tool Chain Integration – IDE & CI Server
16 4/28/2016
17 4/28/2016
ZTTR (Zero Time to Remediation)
Empower Developers From The Start1
18 4/28/2016
Design A Frictionless Approach2
19 4/28/2016
Create A Software Bill Of Materials3
Defining Meaningful Success Metrics
20 4/28/2016
http://www.aintitcool.com/node/44547
It’s Not Always What You Measure…
21 4/28/2016
http://ronjeffries.com/articles/016-03/you-want/
…It’s the Behavior that Results
22 4/28/2016
Manager: “Nathan, this isn’t fair. You’re just showing the number of stories,
not how big they are.”
Nathan: “That’s right.”
Manager: “But that’s not fair!”
Nathan: [silent]
Manager: “All I’d have to do would be to divide up my stories into little bits
and release those every month.”
Nathan: [silent, smiling]
Manager: “Oh.”
• Soon, the manager was doing small stories, to the benefit of everyone.
http://ronjeffries.com/articles/016-03/you-want/
Success Metrics
23 4/28/2016
• Short Term – Time to Value
• “By the end of the workshop, we configured ~80% of our policies.
Just six business days after training, we have made the test
environment available in our organization”
• Long Term – Quality Metrics
• MTTR
• WIP
• New violations delivered to production
Q&A
Wrap Up
25 4/28/2016
• Manage your Software Supply Chain
• Collaborate with counterparts – BA/PM/Dev/QA/Ops/Sec.
• Discuss mutual interdependence and shared objectives
• Automated Real-Time Feedback is a win-win
• http://bit.ly/app-check
We’re here, engaged &
READY
TO HELP
26
Nexus Newsletter Nexus Live – Google Hangouts Cool Things in 2 Minutes
Customer Success Team
Training On-Site or OnlineOnline Knowledge BaseNexus Community Pages
Books Online
Mentors View: Aligning Your Team and Your Powers for Success
Chicago, IL
April 27, 2016
Mentor’s View: Aligning your team and your
powers for success
Chris Carlucci, Customer Success Engineer, Sonatype

More Related Content

PPTX
Supply Chain Solutions for Modern Software Development
PPTX
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
PPTX
The State of Open Source Vulnerabilities - A WhiteSource Webinar
PDF
PCI and Vulnerability Assessments - What’s Missing?
PPTX
A "Firewall" for Bad Binaries
PDF
Q1 2016 Open Source Security Report: Glibc and Beyond
PPTX
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...
PPTX
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...
Supply Chain Solutions for Modern Software Development
The Top 3 Strategies To Reduce Your Open Source Security Risks - A WhiteSour...
The State of Open Source Vulnerabilities - A WhiteSource Webinar
PCI and Vulnerability Assessments - What’s Missing?
A "Firewall" for Bad Binaries
Q1 2016 Open Source Security Report: Glibc and Beyond
WhiteSource Webinar-New Research Reveals Key Strategy to Manage Open Source S...
5 Things Every CISO Needs To Know About Open Source Security - A WhiteSource ...

What's hot (20)

PDF
Winning open source vulnerabilities without loosing your deveopers - Azure De...
PPTX
Accelerating Innovation with Software Supply Chain Management
PPTX
Continuous Acceleration with a Software Supply Chain Approach
PDF
Say No To Dependency Hell
PDF
The AppSec Path to Enlightenment
PPTX
Open Source 360 Survey Results
PDF
Open Source Outlook: Expected Developments for 2016
PPTX
Say No to the Dependency Hell
PDF
The State of Open Source Vulnerabilities Management
PDF
The State of Open Source Vulnerabilities Management
PDF
Presentation
PDF
RSAC DevSecOpsDays 2018 - We are all Equifax
PPTX
The Journey to DevSecOps
PDF
OSSF 2018 - David habusha of Whitesource - Open Source Vulnerabilities 101
PDF
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
PDF
Taking Open Source Security to the Next Level
PPTX
DEVSECOPS: Coding DevSecOps journey
PPTX
Amy DeMartine - 7 Habits of Rugged DevOps
PPTX
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
PDF
RoboCop: Bringing Law and Order to CI/CD
Winning open source vulnerabilities without loosing your deveopers - Azure De...
Accelerating Innovation with Software Supply Chain Management
Continuous Acceleration with a Software Supply Chain Approach
Say No To Dependency Hell
The AppSec Path to Enlightenment
Open Source 360 Survey Results
Open Source Outlook: Expected Developments for 2016
Say No to the Dependency Hell
The State of Open Source Vulnerabilities Management
The State of Open Source Vulnerabilities Management
Presentation
RSAC DevSecOpsDays 2018 - We are all Equifax
The Journey to DevSecOps
OSSF 2018 - David habusha of Whitesource - Open Source Vulnerabilities 101
Find Out What's New With WhiteSource September 2018- A WhiteSource Webinar
Taking Open Source Security to the Next Level
DEVSECOPS: Coding DevSecOps journey
Amy DeMartine - 7 Habits of Rugged DevOps
Open Source Insight: CVE-2017-2636 Vuln of the Week & UK National Cyber Secur...
RoboCop: Bringing Law and Order to CI/CD
Ad

Viewers also liked (17)

DOCX
Taylor graduate capabilities( English Legal System)
PDF
Seneste arbejdsopgaver i Tryg
PDF
curriculum vitae nawaz
PPTX
It tools & technology
DOCX
Taylor graduate capabilities ( tort law)
PDF
BIG CALL WEBINAR. Святослав Павловский
PPTX
Initial Ideas Mind Map
PDF
Antalya pegasus ucuz uçak bileti telefon
PDF
D2P Autoparts
PPTX
Programming fundamentals 3
DOCX
2016 and 2017 Data Mining Projects @ TMKS Infotech
PDF
Modul Karsam 2013: Instruksi Penggunaan Ministing
PPT
Jisc Text Mining Capabilities
PDF
Evolución de las poblaciones de Patella ferruginea Gmelin, 1791 en el litoral...
PDF
Inversi Non-Linier Dengan Pendekatan Global: Systematic And Random Grid Search
PDF
Pendekatan Inversi Linier dengan Matriks Jacobi pada Kasus Perhitungan Hipose...
PPTX
Catcom | 6 yếu tố để có team startup tốt
Taylor graduate capabilities( English Legal System)
Seneste arbejdsopgaver i Tryg
curriculum vitae nawaz
It tools & technology
Taylor graduate capabilities ( tort law)
BIG CALL WEBINAR. Святослав Павловский
Initial Ideas Mind Map
Antalya pegasus ucuz uçak bileti telefon
D2P Autoparts
Programming fundamentals 3
2016 and 2017 Data Mining Projects @ TMKS Infotech
Modul Karsam 2013: Instruksi Penggunaan Ministing
Jisc Text Mining Capabilities
Evolución de las poblaciones de Patella ferruginea Gmelin, 1791 en el litoral...
Inversi Non-Linier Dengan Pendekatan Global: Systematic And Random Grid Search
Pendekatan Inversi Linier dengan Matriks Jacobi pada Kasus Perhitungan Hipose...
Catcom | 6 yếu tố để có team startup tốt
Ad

Similar to Mentors View: Aligning Your Team and Your Powers for Success (20)

PPTX
Aligning Your Team and Your Powers for Success
PDF
Dawn Stevens: Adapting Traditional Metrics to Measure, Monitor, and Achieve A...
PDF
Wipeout! Make New Mistakes
PDF
DevOps and End to End Visibility with Ed Gaile
PDF
DevOps and End to End Visibility with Ed Gaile
PPTX
DevOpsRoadTrip San Francisco Final Speaking Deck
PPTX
Transforming the impossible
PDF
Take Control of Your Career: A Personal Growth Framework
PDF
DaveInTheBox v3
PDF
A Brave New World of Delivering IT
PDF
Tuning and Improving Your Agility
PDF
Agile Network India | Data driven approach to Retrospectives | Sandhya Bhayana
PDF
Bloomberg PMI NYC Breakthrough consumer experience - Michael Nir
PDF
CWIN 17 Madrid / Nuno Duarte Oliveira - i naa-s
PDF
People Metrics: How to Use Team Data to Produce Positive Change
PDF
Estimate and Measure. Minimize work, maximize value. Part 2
PPTX
The Forgotten Secret to DevOps Success: Measurement
PDF
Paving the road to production
PPT
The Agile Revolution of IBM
PPTX
Measuring for team effectiveness (NEW)
Aligning Your Team and Your Powers for Success
Dawn Stevens: Adapting Traditional Metrics to Measure, Monitor, and Achieve A...
Wipeout! Make New Mistakes
DevOps and End to End Visibility with Ed Gaile
DevOps and End to End Visibility with Ed Gaile
DevOpsRoadTrip San Francisco Final Speaking Deck
Transforming the impossible
Take Control of Your Career: A Personal Growth Framework
DaveInTheBox v3
A Brave New World of Delivering IT
Tuning and Improving Your Agility
Agile Network India | Data driven approach to Retrospectives | Sandhya Bhayana
Bloomberg PMI NYC Breakthrough consumer experience - Michael Nir
CWIN 17 Madrid / Nuno Duarte Oliveira - i naa-s
People Metrics: How to Use Team Data to Produce Positive Change
Estimate and Measure. Minimize work, maximize value. Part 2
The Forgotten Secret to DevOps Success: Measurement
Paving the road to production
The Agile Revolution of IBM
Measuring for team effectiveness (NEW)

More from Sonatype (20)

PPTX
DevOps Days Columbus - Derek Weeks - 2019
PDF
2019 DevSecOps Reference Architectures
PPTX
DevSecOps reference architectures 2018
PDF
30+ Nexus Integrations to Accelerate DevOps
PDF
2017 DevSecOps Survey
PPTX
Starting and Scaling DevOps In the Enterprise
PPTX
DevOps Friendly Doc Publishing for APIs & Microservices
PDF
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
PPTX
DevOps and All the Continuouses w/ Helen Beal
PDF
Serverless and the Way Forward
PDF
A Small Association's Journey to DevOps w/ Edward Ruiz
PDF
What's My Security Policy Doing to My Help Desk w/ Chris Swan
PDF
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
PDF
Static Analysis For Security and DevOps Happiness w/ Justin Collins
PDF
Automated Infrastructure Security: Monitoring using FOSS
PDF
System Hardening Using Ansible
PDF
There is No Server: Immutable Infrastructure and Serverless Architecture
PDF
Getting out of the Job Jungle with Jenkins
PDF
Modern Infrastructure Automation
PDF
Continuous Everyone: Engaging People Across the Continuous Pipeline
DevOps Days Columbus - Derek Weeks - 2019
2019 DevSecOps Reference Architectures
DevSecOps reference architectures 2018
30+ Nexus Integrations to Accelerate DevOps
2017 DevSecOps Survey
Starting and Scaling DevOps In the Enterprise
DevOps Friendly Doc Publishing for APIs & Microservices
The Unrealized Role of Monitoring & Alerting w/ Jason Hand
DevOps and All the Continuouses w/ Helen Beal
Serverless and the Way Forward
A Small Association's Journey to DevOps w/ Edward Ruiz
What's My Security Policy Doing to My Help Desk w/ Chris Swan
Characterizing and Contrasting Kuhn-tey-ner Awr-kuh-streyt-ors
Static Analysis For Security and DevOps Happiness w/ Justin Collins
Automated Infrastructure Security: Monitoring using FOSS
System Hardening Using Ansible
There is No Server: Immutable Infrastructure and Serverless Architecture
Getting out of the Job Jungle with Jenkins
Modern Infrastructure Automation
Continuous Everyone: Engaging People Across the Continuous Pipeline

Recently uploaded (20)

PDF
Mushroom cultivation and it's methods.pdf
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Getting Started with Data Integration: FME Form 101
PDF
Encapsulation theory and applications.pdf
PPTX
A Presentation on Artificial Intelligence
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
Tartificialntelligence_presentation.pptx
PDF
gpt5_lecture_notes_comprehensive_20250812015547.pdf
PDF
Web App vs Mobile App What Should You Build First.pdf
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
August Patch Tuesday
PDF
project resource management chapter-09.pdf
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
A Presentation on Touch Screen Technology
Mushroom cultivation and it's methods.pdf
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Unlocking AI with Model Context Protocol (MCP)
Getting Started with Data Integration: FME Form 101
Encapsulation theory and applications.pdf
A Presentation on Artificial Intelligence
OMC Textile Division Presentation 2021.pptx
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
NewMind AI Weekly Chronicles - August'25-Week II
cloud_computing_Infrastucture_as_cloud_p
Tartificialntelligence_presentation.pptx
gpt5_lecture_notes_comprehensive_20250812015547.pdf
Web App vs Mobile App What Should You Build First.pdf
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
August Patch Tuesday
project resource management chapter-09.pdf
Heart disease approach using modified random forest and particle swarm optimi...
A Presentation on Touch Screen Technology

Mentors View: Aligning Your Team and Your Powers for Success

  • 1. Mentor’s View: Aligning your team and your powers for success Chris Carlucci Customer Success Engineer Sonatype
  • 2. Agenda 2 4/28/2016 • Getting Started on Your Journey • Open Source Policy Guidelines • Policy Results in Eclipse & Jenkins • Meaningful Success Metrics
  • 3. Getting started on your journey 3 4/28/2016 • Rugged DevOps, Software Supply Chain, Now What? • The Hero’s Journey • Align Your Heroes • Building Bridges • Setting Expectations
  • 4. Building A Trusted Software Supply Chain 4 4/28/2016
  • 5. Different Stakeholders, Different Priorities 5 4/28/2016 Where’s that release? Done! On to the next sprint. Now, where are we in that process?
  • 6. 6 4/28/2016 Building A Better Bridge Between Dev, Ops & Sec • Tooling needs to adopt the practice of the practitioner • A tool is not a process and a process is not a tool; learn to leverage both
  • 7. Two Philosophies • Support & guide • Objective information across the lifecycle • Each performs the task they are good at • Faster component selection and issue resolution • Bridges the developer “compliance” gap 7 4/28/2016 • Scan & scold • Reactive information late in the lifecycle • Creates rework and slows remediation • Hinders technology innovation • More expensive
  • 8. 8 4/28/2016 Communicate Expectations Determine lifecycle enforcement strategy: Allows developers time to research & fix or to request waivers Everything is documented on an internal WIKI Development CI Build Promotion to staging or release
  • 9. Fix the Red – Actionable? 9 4/28/2016
  • 10. Fix the Red – Actionable? 10 4/28/2016
  • 11. 11 4/28/2016 Building A Good Component Practice Phase 3 Reducing risk & enforcing compliance Phase 2 Creating policy & rating risk Phase 1 Understanding your environment
  • 14. 14 4/28/2016 Out-of-the-box Policies With Easy Customization Architecture Component License Security
  • 15. IQ Server Policy Definition 15 4/28/2016
  • 16. Tool Chain Integration – IDE & CI Server 16 4/28/2016
  • 17. 17 4/28/2016 ZTTR (Zero Time to Remediation) Empower Developers From The Start1
  • 18. 18 4/28/2016 Design A Frictionless Approach2
  • 19. 19 4/28/2016 Create A Software Bill Of Materials3
  • 20. Defining Meaningful Success Metrics 20 4/28/2016 http://www.aintitcool.com/node/44547
  • 21. It’s Not Always What You Measure… 21 4/28/2016 http://ronjeffries.com/articles/016-03/you-want/
  • 22. …It’s the Behavior that Results 22 4/28/2016 Manager: “Nathan, this isn’t fair. You’re just showing the number of stories, not how big they are.” Nathan: “That’s right.” Manager: “But that’s not fair!” Nathan: [silent] Manager: “All I’d have to do would be to divide up my stories into little bits and release those every month.” Nathan: [silent, smiling] Manager: “Oh.” • Soon, the manager was doing small stories, to the benefit of everyone. http://ronjeffries.com/articles/016-03/you-want/
  • 23. Success Metrics 23 4/28/2016 • Short Term – Time to Value • “By the end of the workshop, we configured ~80% of our policies. Just six business days after training, we have made the test environment available in our organization” • Long Term – Quality Metrics • MTTR • WIP • New violations delivered to production
  • 24. Q&A
  • 25. Wrap Up 25 4/28/2016 • Manage your Software Supply Chain • Collaborate with counterparts – BA/PM/Dev/QA/Ops/Sec. • Discuss mutual interdependence and shared objectives • Automated Real-Time Feedback is a win-win • http://bit.ly/app-check
  • 26. We’re here, engaged & READY TO HELP 26 Nexus Newsletter Nexus Live – Google Hangouts Cool Things in 2 Minutes Customer Success Team Training On-Site or OnlineOnline Knowledge BaseNexus Community Pages Books Online
  • 28. Chicago, IL April 27, 2016 Mentor’s View: Aligning your team and your powers for success Chris Carlucci, Customer Success Engineer, Sonatype

Editor's Notes

  • #2: Introduction Name CSE - Work with organizations to build better component practices such that they can improve their software supply chain management Today, I am going to.. =================
  • #4: In general, there are 2 main requirements when deploying software and this is especially true with component management Tooling - Non-negotiable, like any other practice, developers can’t succeed unless equipped with the right tools.  The major keys with tooling include: Integrate where developers work, not the other way around Needs to operate at the pace of development or it becomes a bottleneck Process - The process you put in place allows you to enable that tooling to developers (Eg education), set clear expectations (Eg What is required of me?) and at the end of the day monitor and track usage / progress So, when I walk into an organization.  The first goal is understanding where we are starting from: What is the culture? Education? Tooling – What are we transitioning from? Current processes – Have developers had to adhere to prior checks within the SDLC
  • #5: Initial success metrics. What does first value mean to you? Small/quick wins BOM Remediation Enforcement Bring in the right people Subject matter experts Organizational support – change of technology, process requires top down executive support. Ability to mandate usage? Enterprise success metrics. Provide examples Education How do developers get integrated How do they get educated What can they reference for assistance Who can they contact when encountering an issue Track – At the end of the day, someone needs to provide approval – What do they need to see?
  • #6: When bringing multiple groups together, we must understand and accept that they have different priorities. Establishing this and the interactions between them is key --------------------------------------------- People How many are developers? How many are managers? How many work in operations, tool chain? Governance? OSS How many people are familiar with the concept of dependencies? What languages?  Java, npm, NuGet? Tooling How many here use a repository manager? Process How many have a manual review process for component approvals? How many go straight to the internet for components? How many have application checks at release time?
  • #7: Successful tooling integrates where the developers are performing their work – IDE, CI, Repository Manager Tooling / Technology is not the sole answer – Process must be established around it to set expectations, train developers and track progress to continually make improvements
  • #8: All parties on the same playing field of information Empower developers to make better choices Initiate constructive conversations ------------------ https://www.linkedin.com/pulse/agile-transformation-what-went-wrong-pradeep-bindra Implement Agile in an Agile way. When leading organizations through the transformation from traditional software development to Agile, it is a great idea to start small. Identify only a few pilot teams that are ready to volunteer and are enthusiastic. This will not only help to focus on early, small successes in adapting Agile to the organization but it will also increase trust and help identify the barriers (organizational and personal) to fostering greater change. Starting small will help to quickly surface the delivery of business value, reduce risk, and prepare people to move the organization to greater levels of agility.
  • #9: You as the project team have the responsibility to ensure the tooling is generating valid issues Developers should remediate, not validate Lack of clarity leads to frustration, bottlenecks and lack of trust in the tooling ---------------------------- A developer’s options or path forward should be as obvious as possible What are the enforcement points? What do I HAVE to fix to be able to release to product? Ex. Fix the red violations Administration team should be easily accessible for questions ------------------ Limit the mandatory issues developers receive Too many issues results in tool antipathy A threat threshold should be defined Threat threshold should be communicated clearly
  • #10: Anyone who has ever used security or quality tooling.. Static Source Code Not every issue can be critical – Sensory overload How do you know where to start? Skepticism around the tool Cost of doing business
  • #11: This is more actionable Threat level denotes priority - Drives developer actions Advice: Fix the red Tip: Especially where expectations didn’t exist before – devs cannot immediately comply – pandora’s box – time period for grandfathering violations, cannot fix everything on day one
  • #12: This is the process that every organization goes through Discovery – Understand how my org builds and releases software. - Big need Inventory – I need to be able to identify all my applications and all the components within my applications. Do you know where they are? What they contain? Policy – Once inventory is collected, I need to identify the things that I care about Mitigation – Once you have identified the policy, you need to push this out to devs for mitigation Enforcement – This may be necessary to eliminate high risk in production application. Recommendation is to warn early and fail late, but even still, take care with this decision
  • #14: Question – What is the main purpose of a policy? Answer – To drive intended behavior no smoking? speed limit? – You are either following it or not – Yes or No don’t run with scissors password strength? Point - Policies don’t have to be these big, complicated things, they should be simple and concise rule(s) for defining guidelines around open source component consumption
  • #15: For Open Source Components, we generally see 4 main types of policy Security Legal Architecture Match State How do we decide on the exact guidelines – subject matter experts
  • #16: Policy characteristics Precise Contextual Actionable Continuous Fast
  • #21: Keep in mind Each organization is at a different starting point Different groups may sponsor the initiative, driving different directives In general, we see Most organizations begin with small goals, given the maturity of their open source supply chain Most organizations start with Auditing to better understand the scope of the problem Most organizations warn early, and fail late As always, some organizations have a compelling event as to why they purchased Eg Find struts
  • #23: Are you driving the intended behavior? Are developers making better choices? Is the software quality going up and productivity going up?
  • #26: Application Health Check is an easy no-cost way to run a report and get real results so that you can have better visibility into all of the components that make up your application. Your app does not leave your network. A one-way fingerprint is generated from the components in your app and compared against Sonatype’s Data Services to identify a Bill of Materials.
  • #29: Introduction Name CSE - Work with organizations to build better component practices such that they can improve their software supply chain management Background – Static Source Code Analysis Today, I am going to..