Wednesday, July 1, 2026
HomeSoftware EngineeringPrime 10 Weblog Posts of 2021

Prime 10 Weblog Posts of 2021

[ad_1]

Each January on the SEI Weblog, we current the ten most-visited posts of the earlier yr. This yr’s record of prime 10 is offered in reverse order and options posts printed between January 1, 2021, and December 31, 2021.

10. Prime 10 Concerns for Efficient Incident Administration Communications

by Brittany Manley

Communications are important to the general sustainability and success of cybersecurity facilities and incident administration groups, each in instances of disaster and through regular operations. As a result of significance of communications, and the truth that communications planning is commonly missed, the SEI developed the Information to Efficient Incident Administration Communications as a useful resource for cybersecurity facilities and incident response organizations trying to enhance their communications planning and actions. This weblog put up is tailored from that information and it offers 10 concerns for efficient communications planning, and concerns and finest practices for communications duties in help of incident response companies.

Cybersecurity facilities and incident response groups deal with mitigating threats by figuring out, defending, detecting, responding to, and recovering from cybersecurity incidents. These groups could also be accountable for many various kinds of communications, starting from communications with constituents to sharing data with most people and the media. How organizations plan for and handle these communications and the way they’re acquired will affect trustworthiness, status, and in the end the group’s capacity to carry out incident administration companies successfully. The information offers concerns for varied sorts of communications, together with constituent, media, and disaster communications. It addresses finest practices for the dissemination of well timed and correct data, together with organizational concerns, sorts of communication and content material, and examples of what ought to be included inside communications plans.
Learn the complete put up.

9. Advantages and Challenges of SOAR Platforms

by Angela Horneman and Justin Ray

Community and protection analysts are dealing with rising numbers of safety alerts and, on account of fielding these alerts, burnout. Darkish Studying reported that the common safety operations middle (SOC) receives 10,000 alerts every day from layer upon layer of monitoring and detection merchandise. Whereas the cyber risk panorama is marked by an upward trending variety of actors, community and protection analysts should additionally cope with ever-increasing numbers of false positives (typically at charges as excessive as 80 %). Resulting from useful resource constraints on already overwhelmed analysts, many alerts are ignored, and, in response to a current report, lower than 10 % of alerts are actively investigated.

Safety orchestration, automation, and response (SOAR) platforms, a time period first coined by Gartner, refers to “applied sciences that allow organizations to gather inputs monitored by the safety operations staff. For instance, alerts from the SIEM system and different safety applied sciences—the place incident evaluation and triage will be carried out by leveraging a mix of human and machine energy—assist outline, prioritize and drive standardized incident response actions. SOAR instruments enable a company to outline incident evaluation and response procedures in a digital workflow format.” It permits already overwhelmed community and protection analysts to compile threat-related information from varied disparate sources after which use machine studying to automate responses to low-level threats. SOAR was one of many preliminary merchandise aimed toward easing the burden not solely on safety operations middle (SOC) analysts, however on different safety professionals corresponding to safety data and occasion administration (SIEM) operators, risk hunters, and compliance managers. On this weblog put up, we introduce and analyze SOAR platforms, which assist analysts cope with alert fatigue.
Learn the complete put up.

8. Easy methods to Use CMMC Evaluation Guides

by Douglas Gardner

To obtain certification underneath the Cybersecurity Maturity Mannequin Certification (CMMC) 1.0 program, Division of Protection (DoD) contractors should efficiently full a third-party evaluation. The DoD has launched two CMMC evaluation guides, the elemental instruments for each assessors and contractors to judge adherence to the CMMC framework. This weblog put up is meant for DoD contractors in search of further clarification as they put together for a CMMC evaluation. It would stroll you thru the evaluation guides, present fundamental CMMC ideas and definitions, and introduce alternate descriptions of some practices. The objective is to assist these unfamiliar with cybersecurity requirements to raised perceive the CMMC practices and processes.

CMMC is a certification program to enhance supply-chain safety within the protection industrial base (DIB). Finally, the DoD would require that every one DIB corporations be licensed at one of many 5 CMMC ranges, which embody each technical safety controls and maturity processes specified by the Cybersecurity Maturity Mannequin framework.
Learn the complete put up.

7. Taking DevSecOps to the Subsequent Degree with Worth Stream Mapping

by Nanette Brown

This put up explores the connection between DevSecOps and worth stream mapping, each of that are rooted within the Lean strategy to methods and workflow. It additionally offers steerage on making ready to conduct worth stream mapping inside a software-intensive product improvement setting.

If the main target of post-waterfall software program engineering might be summed up in a single phrase, it might be move, which focuses on lowering the time for gadgets of buyer worth (e.g., options) to maneuver from idea to deployment. Lean software program improvement, DevSecOps, and worth stream administration all consciously orient their rules and practices round move optimization. Though Agile software program strategies don’t typically point out move explicitly, move optimization is implicit in Agile’s deal with the incremental supply of worth and the usage of empowered, cross-functional groups to reduce impediments and delays.

Move is an intuitively accessible idea. Rivers move until impeded by dams or rock formations. Our minds in a state of move are unimpeded, centered, and energized. Software program improvement just isn’t involved with the move of water or inner consciousness however fairly with the move of worth to prospects and finish customers. By specializing in move, we goal to attain worth as quickly as potential and to get rid of any impedance or friction. Iterative and incremental improvement, steady integration and supply, minimal viable product, and minimal viable functionality launch all have the speedy move of worth as their raison d’etre.

A deal with move underlies and unifies the matters mentioned on this put up. Worth streams and DevSecOps are rooted within the premise that organizational boundaries ought to be subsumed within the pursuit of move. Worth stream mapping offers a framework for figuring out current boundaries to move and designing a future state wherein worth flows extra freely.
Learn the complete put up.

6. Distant Works: Vulnerabilities and Threats to the Enterprise

by Nathaniel Richmond

Managing supply-chain dangers from the brand new coronavirus outbreak is personally vital to me. Whereas my first concern—like everybody else’s—is mitigating the direct public-health threat of the COVID-19 pandemic, I’ve a salient concern concerning the health-related dangers that might be launched if the worldwide manufacturing provide chain for medical gadgets is disrupted: I’m a Kind I diabetic who depends on a steady glucose monitor (CGM) system to watch my blood sugar and an insulin pump for insulin injections. On this weblog put up, I discover risk-management methods that distributors can use to arrange and account for disruptions to {hardware} and software program provide chains—disruptions that might have an effect on gadgets that finish customers depend on.
Learn the complete put up.

5. A Framework for DevSecOps Evolution and Reaching Steady-Integration/Steady-Supply (CI/CD) Capabilities

by Lyndsi Hughes and Vanessa Jackson

The advantages of working a improvement setting with continuous-integration and continuous-delivery (CI/CD) pipeline capabilities and DevSecOps practices are effectively documented. Leveraging DevSecOps practices and CI/CD pipelines permits organizations to answer safety and reliability occasions shortly and effectively and to provide resilient and safe software program on a predictable schedule and price range. Though the choice by administration to undertake this technique could also be straightforward, the preliminary implementation and ongoing enchancment of the methodology will be difficult and will end in incomplete adoption or ineffective implementation.

On this and a sequence of future weblog posts, we offer a brand new framework to information organizations within the planning and implementation of a roadmap to practical CI/CD pipeline capabilities.

This framework builds on well-established functions of DevSecOps rules and offers further steerage for making use of DevSecOps rules to infrastructure operations in an on-premises computing setting by offering an ordered strategy towards implementing essential practices within the phases of adoption, implementation, enchancment, and upkeep of that setting. The framework additionally focuses on the leverage of automation all through the method.
Learn the complete put up.

4. Architecting the Way forward for Software program Engineering: A Analysis and Growth Roadmap

by Anita Carleton, John Robert, Mark Klein, Doug Schmidt, Forrest Shull, John Foreman, Ipek Ozkaya, Robert Cunningham, Charlie Holland, Erin Harper, and Edward Desautels

Software program is significant to our nation’s international competitiveness, innovation, and nationwide safety. It additionally ensures our fashionable lifestyle and permits continued advances in protection, infrastructure, healthcare, commerce, training, and leisure. Because the DoD’s federally funded analysis and improvement middle (FFRDC) centered on enhancing the observe of software program engineering, the Carnegie Mellon College (CMU) Software program Engineering Institute (SEI) is main the group in making a multi-year analysis and improvement imaginative and prescient and roadmap for engineering next-generation software-reliant methods. This weblog put up describes that effort.

Software program Engineering as Strategic Benefit

In a 2020 Nationwide Academy of Science Examine on Air Power software program sustainment, the U.S. Air Power acknowledged that “to proceed to be a world-class preventing drive, it must be a world-class software program developer.” This idea clearly applies far past the Division of Protection. Software program methods allow world-class healthcare, commerce, training, vitality era, and extra. These methods that run our world are quickly changing into extra information intensive and interconnected, more and more make the most of AI, require larger-scale integration, and should be significantly extra resilient. Consequently, important funding in software program engineering R&D is required now to allow and guarantee future functionality.
Learn the complete put up.

3. Zero Belief Adoption: Managing Threat with Cybersecurity Engineering and Adaptive Threat Evaluation

by Geoff Sanders

Zero belief adoption challenges many organizations. It isn’t a particular know-how to undertake, however a safety initiative that an enterprise should perceive, interpret, and implement. Enterprise safety initiatives are by no means easy, and their objective to enhance cybersecurity posture requires the alignment of a number of stakeholders, methods, acquisitions, and exponentially altering know-how. This alignment is at all times a posh enterprise and requires cybersecurity technique and engineering to succeed.

On this and a sequence of future posts, we offer an outline of zero belief and administration of its threat with the SEI’s cybersecurity engineering evaluation framework. This adaptive framework incorporates a number of evaluation strategies that handle lifecycle challenges that organizations face on a zero-trust journey.
Learn the complete put up.

2. Necessities in Mannequin-Based mostly Programs Engineering (MBSE)

by Nataliya Shevchenko

Mannequin-based methods engineering (MBSE) is a formalized methodology that helps the necessities, design, evaluation, verification, and validation related to the event of advanced methods. MBSE in a digital-modeling setting offers benefits that document-based methods engineering can’t present. These benefits have led to elevated and rising adoption since MBSE can save prices by lowering improvement time and enhance the flexibility to provide safe and accurately functioning software program. The SEI CERT Division has begun researching how MBSE will also be used to mitigate safety dangers early within the system-development course of in order that methods are safe by design, in distinction to the frequent observe of including safety features later within the improvement course of.

Though MBSE doesn’t dictate any particular course of, any MBSE course of ought to cowl 4 methods engineering domains: necessities/capabilities, habits, structure/construction, and verification and validation. On this weblog put up, I describe how MBSE addresses the primary of those domains: necessities, which describe the issue(s) to deal with.
Learn the complete put up.

1. The Present State of DevSecOps Metrics

by Invoice Nichols

Within the BBC documentary sequence Connections, science historian James Burke traced how technical improvements construct on each other over time. New capabilities create new potentialities, new challenges, and new wants. This sample additionally applies to the evolution of software program engineering, the place adjustments in software program engineering practices are sometimes pushed by adjustments in underlying applied sciences. For instance, the observe of frequent compiling and testing of code was a legacy of the post-punchcard period within the Nineteen Eighties. When devoted desktop compilers elevated the comfort of compilation, it turned simpler for engineers to compile and check extra ceaselessly, which then turned a typical observe.

This evolution continues right this moment within the practices we affiliate with DevSecOps, corresponding to steady integration (CI), steady supply/deployment (CD), and infrastructure as code, all of that are made potential by enhancements in underlying know-how that automate the development-to-production pipeline. These DevSecOps practices will probably generate extra details about improvement and operational efficiency than has ever been available earlier than. On this weblog put up, I focus on the methods wherein DevSecOps practices yield precious details about software program efficiency that’s more likely to result in improvements in software program engineering metrics.
Learn the complete put up.

Wanting Forward in 2022

Within the coming months, search for posts highlighting our work in constructing a cybersecurity engineering technique, synthetic intelligence, digital engineering, and edge computing. We publish a brand new put up on the SEI Weblog each Monday morning.

[ad_2]

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments