#sdlc-governance

[ follow ]
#ai-governance
EU data protection
fromInfoQ
20 hours ago

How SBOMs and Engineering Discipline Can Help You Avoid Trivy's Compromise

SBOMs are essential for developers to enhance security and comply with new legislative requirements.
DevOps
fromMedium
1 day ago

Set it up once, test it properly, and let the system handle the rest.

Automating SSL certificate renewal prevents production outages and reduces stress during incidents.
#generative-ai
fromMarTech
7 hours ago
Marketing tech

A framework for auditing generative AI outputs pre-launch | MarTech

Marketing teams should use a four-stage audit framework for Generative AI outputs to ensure brand voice consistency and copyright compliance.
Software development
fromInfoWorld
4 days ago

How agile practices ensure quality in GenAI-assisted development

Generative AI enhances coding speed but increases technical debt without Agile practices like pair programming and automated tests.
Marketing tech
fromMarTech
7 hours ago

A framework for auditing generative AI outputs pre-launch | MarTech

Marketing teams should use a four-stage audit framework for Generative AI outputs to ensure brand voice consistency and copyright compliance.
Software development
fromInfoWorld
4 days ago

How agile practices ensure quality in GenAI-assisted development

Generative AI enhances coding speed but increases technical debt without Agile practices like pair programming and automated tests.
Business intelligence
fromEntrepreneur
1 hour ago

Stop Treating ESG Like a Costly Obligation - When Used Well, It Becomes a Growth Advantage

ESG identifies operational and financial risks, enhancing resilience and performance beyond mere compliance.
Healthcare
fromTheregister
10 hours ago

NHS pays 46K to prep next Microsoft licensing round

NHS England is investing £46,000 in benchmarking services to prepare for upcoming software licensing negotiations.
Web frameworks
fromInfoQ
3 days ago

Tiger Teams, Evals and Agents: The New AI Engineering Playbook

Sam Bhagwat is a co-founder and CEO of Mastra, an open source JavaScript/Typescript framework for building AI agents.
Careers
fromComputerWeekly.com
3 days ago

Businesses are paying the price for CISO burnout | Computer Weekly

Burnout among CISOs poses significant risks to businesses, driven by overwhelming responsibilities and rising cyber threats.
Agile
fromMedium
6 days ago

The Leap from Technical Project Management to AI Project Management: How to Make the Leap

Tech project managers must adapt to AI initiatives by embracing iterative science, prioritizing data quality, and fostering cross-functional collaboration.
Marketing
fromForbes
6 days ago

How To Serve Clients Amid Board Scrutiny And Investor Activism

Agency conversations with executives now focus on measurable business impact rather than just creative output.
Angular
fromInfoQ
1 week ago

A Better Alternative to Reducing CI Regression Test Suite Sizes

Reducing CI regression test suites can hide subtle bugs; a stochastic approach and leveraging redundancies improve test effectiveness and CI lab efficiency.
Business
fromFast Company
5 days ago

This is the biggest risk a company can take in the age of AI

Organizations that continue transformation during uncertainty outperform those that slow down, treating turbulence as an opportunity for growth.
#devops
DevOps
fromInfoWorld
6 days ago

What enterprise devops teams should learn from SaaS

Enterprise devops teams can enhance resiliency by adopting practices from SaaS providers, focusing on robust testing, monitoring, and seamless upgrades.
DevOps
fromMedium
1 day ago

Kubernetes Is Not DevOps : A Short Story

Understanding systems behind tools is crucial for effective DevOps engineering.
DevOps
fromInfoWorld
6 days ago

What enterprise devops teams should learn from SaaS

Enterprise devops teams can enhance resiliency by adopting practices from SaaS providers, focusing on robust testing, monitoring, and seamless upgrades.
Marketing tech
fromAcast
4 days ago

AI Governance Isn't a Barrier: It's Marketing's Growth Engine | Adspeak

AI is transforming marketing by enabling innovation through governance, clean data, and balancing automation with human creativity.
Data science
fromFast Company
3 days ago

Your AI initiative may be failing because you're measuring it like a legacy business

Leadership often misjudges AI initiatives by applying mature-business metrics too early, leading to premature project cancellations.
Careers
fromeLearning Industry
4 days ago

It Takes Two To Tango: Creating A Long-Lasting Relationship Between C-Suite And L&D

C-suite and L&D partnerships require alignment of expectations to ensure successful training development and business performance.
#ai-security
fromInfoWorld
5 days ago
Software development

Microsoft's new Agent Governance Toolkit targets top OWASP risks for AI agents

Artificial intelligence
fromTheregister
3 days ago

Project Glasswing and open source: The good, bad, and ugly

Project Glasswing aims to enhance open source software security with $100 million and the Mythos AI program to identify vulnerabilities.
Software development
fromInfoWorld
5 days ago

Microsoft's new Agent Governance Toolkit targets top OWASP risks for AI agents

Microsoft introduced the Agent Governance Toolkit to enhance AI agent security and mitigate OWASP's top 10 agentic AI threats.
Artificial intelligence
fromTheregister
3 days ago

Project Glasswing and open source: The good, bad, and ugly

Project Glasswing aims to enhance open source software security with $100 million and the Mythos AI program to identify vulnerabilities.
UX design
fromFast Company
1 week ago

3 things to consider when choosing a software development partner

Client assumptions in vendor selection significantly influence project outcomes, often more than technology choices.
#ai
DevOps
fromDevOps.com
3 days ago

CloudBees Delivers on AI Promise to Improve Application Testing - DevOps.com

CloudBees Smart Tests uses AI to prioritize tests, reducing CI/CD processing time significantly.
Software development
fromDevOps.com
6 days ago

If it Isn't Code, it's Just Advice - DevOps.com

AI coding agents struggle with third-party systems and dashboard configurations, limiting their effectiveness in automation and verification.
Software development
fromInfoQ
2 weeks ago

From Friction to Flow: How Great DevEx Makes Everything Awesome

AI improves some aspects of software development but also reveals persistent challenges, particularly in deployment times.
DevOps
fromDevOps.com
3 days ago

CloudBees Delivers on AI Promise to Improve Application Testing - DevOps.com

CloudBees Smart Tests uses AI to prioritize tests, reducing CI/CD processing time significantly.
Software development
fromDevOps.com
6 days ago

If it Isn't Code, it's Just Advice - DevOps.com

AI coding agents struggle with third-party systems and dashboard configurations, limiting their effectiveness in automation and verification.
Software development
fromInfoQ
2 weeks ago

From Friction to Flow: How Great DevEx Makes Everything Awesome

AI improves some aspects of software development but also reveals persistent challenges, particularly in deployment times.
fromSecurityWeek
3 days ago

MITRE Releases Fight Fraud Framework

"These incidents involve the intentional use of deceptive or illegal practices to fraudulently obtain money, assets, or information from individuals or institutions, and include actions carried out over cyber channels."
Information security
Marketing tech
fromDigiday
4 days ago

While AI is building the web faster than ever, accessibility can't be left behind

AI has accelerated marketing processes, but speed can compromise accessibility, impacting customer experience and conversion rates for people with disabilities.
#ultraplan
Software development
fromDevOps.com
5 days ago

Claude Code's Ultraplan Bridges the Gap Between Planning and Execution - DevOps.com

Ultraplan enhances coding workflows by moving planning to the cloud, allowing for better collaboration and review before code execution.
Software development
fromDevOps.com
5 days ago

Claude Code's Ultraplan Bridges the Gap Between Planning and Execution - DevOps.com

Ultraplan enhances coding workflows by moving planning to the cloud, allowing for better collaboration and review before code execution.
Podcast
fromSecuritymagazine
2 weeks ago

What Does It Take to Be an Outstanding CSO or CISO?

Outstanding security leaders often come from non-traditional backgrounds, with 40% of recent CSO-CISO Hall of Fame honorees starting in the private sector.
DevOps
fromInfoQ
3 days ago

CNCF and Kusari Partner to Strengthen Software Supply Chain Security Across Cloud-Native Projects

CNCF and Kusari collaborate to enhance software supply chain security for cloud-native projects using AI-powered tools.
Information security
fromTechRepublic
5 days ago

Why Operationalizing AI Security Is the Next Great Enterprise Hurdle

Security operations lag behind rapid tech advancements, leading to inefficiencies and risks in managing numerous security tools.
#genai
fromComputerworld
1 week ago
Data science

AI project 'failure' has little to do with AI

The reliability of genAI is compromised by various factors, necessitating independent verification of its outputs.
Software development
fromInfoQ
2 weeks ago

Architectural Governance at AI Speed

GenAI accelerates code production, challenging traditional oversight and necessitating a blend of centralized decision-making with automated governance for architectural cohesion.
Data science
fromComputerworld
1 week ago

AI project 'failure' has little to do with AI

The reliability of genAI is compromised by various factors, necessitating independent verification of its outputs.
Software development
fromInfoQ
2 weeks ago

Architectural Governance at AI Speed

GenAI accelerates code production, challenging traditional oversight and necessitating a blend of centralized decision-making with automated governance for architectural cohesion.
Online Community Development
fromInfoQ
3 weeks ago

Platform Engineering as a Practice of Sociotechnical Excellence

Platform engineering drives sociotechnical change by integrating social and technical systems within organizations for improved collaboration and reliability.
#devsecops
DevOps
fromDevOps.com
6 days ago

Why Most DevSecOps Pipelines Fail at Runtime Security (not Build Time) - DevOps.com

Runtime risk arises from configuration and infrastructure changes post-deployment, necessitating DevSecOps to enhance security earlier in the delivery process.
fromDevOps.com
2 months ago
Information security

Survey Surfaces More Focus on Software Security Testing and API Security - DevOps.com

DevOps
fromDevOps.com
6 days ago

Why Most DevSecOps Pipelines Fail at Runtime Security (not Build Time) - DevOps.com

Runtime risk arises from configuration and infrastructure changes post-deployment, necessitating DevSecOps to enhance security earlier in the delivery process.
fromDevOps.com
2 months ago
Information security

Survey Surfaces More Focus on Software Security Testing and API Security - DevOps.com

Software development
fromInfoWorld
6 days ago

Enterprise developers question Claude Code's reliability for complex engineering

Developers report declining effectiveness in debugging and complex tasks with coding assistants, citing issues with reasoning and quality regression after updates.
Information security
fromSecuritymagazine
5 days ago

Ransomware Response: How Businesses Regain Control Under Pressure

Ransomware attacks create urgent pressure, forcing quick decisions and impacting operations, legal obligations, and overall enterprise strategy.
Online learning
fromeLearning Industry
3 weeks ago

Can An LMS Really Reduce Compliance Risk Before It Happens?

A strategically positioned LMS reduces compliance risk by ensuring consistent policy communication across organizations and enabling rapid regulatory updates, transforming it from a reporting tool into a proactive risk management system.
DevOps
fromDevOps.com
1 week ago

Survey Surfaces Increased Reliance on Open Source Software to Build Apps - DevOps.com

Open source software adoption is prevalent, with 49% of IT professionals reporting increased usage, primarily due to cost savings and avoiding vendor lock-in.
Software development
fromTechzine Global
6 days ago

Why SAST is growing in importance in the age of AI-generated source code

Vibe coding is rapidly increasing, but trust in AI-generated code remains low, making SAST tools essential for security and error prevention.
Agile
fromeLearning Industry
4 weeks ago

Why Agile Transformations Fail Without L&D Rewiring Its Operating Model

Agile adoption is widespread but underperforming; the gap between intent and outcomes stems from execution capability deficits, not framework limitations or structural changes.
Software development
fromDevOps.com
1 week ago

Why Code Validation is the Next Frontier - DevOps.com

Shared staging environments are inadequate for modern development; isolated, on-demand setups are needed for effective validation.
Agile
fromInfoWorld
1 month ago

Save money by canceling more software projects, says survey

Enterprises should cancel underperforming projects more aggressively; those using scenario planning and ruthless viability assessment achieve better ROI outcomes.
DevOps
fromInfoWorld
2 weeks ago

How to build an enterprise-grade MCP registry

MCP registries are essential for integrating AI agents with enterprise systems, requiring semantic discovery, governance, and developer-friendly controls.
Software development
fromDevOps.com
1 week ago

The Trust Tax Framework: Measuring Developer Confidence in CI/CD Systems - DevOps.com

Test infrastructure credibility is crucial; developers lose trust when re-run rates exceed 30% and override rates surpass 5%.
Information security
fromComputerWeekly.com
2 weeks ago

Platformisation or platform theatre? Navigating cyber consolidation | Computer Weekly

Consolidation in enterprise security is necessary but can introduce risks like single points of failure and integration issues.
DevOps
fromInfoQ
2 weeks ago

Architecting Autonomy at Scale: Raising Teams Without Creating Dependencies

Aligning architectural decision authority to C4 abstraction levels clarifies ownership boundaries for distributed teams without needing a central approver.
DevOps
fromDevOps.com
2 weeks ago

Security as Code is Becoming the New Baseline: Continuous Compliance in DevOps - DevOps.com

Compliance must be integrated into the delivery pipeline as a continuous practice rather than a periodic checkpoint.
Software development
fromDevOps.com
2 weeks ago

The AIRE Gap: Why Organizations Are Buying AI SRE Tools They Aren't Ready to Use - DevOps.com

AI reliability engineering promises to enhance incident management, but many organizations are unprepared for its implementation and benefits.
Information security
fromThe Hacker News
4 weeks ago

Why Security Validation Is Becoming Agentic

Security validation tools operate in silos while attackers exploit interconnected systems, creating a structural blind spot that Agentic Exposure Validation can address through continuous, autonomous, context-aware assessment.
fromMedium
3 weeks ago

Mastering Azure Governance: Why It Matters and How to Get Started

Azure Governance is the set of policies, processes, and technical controls that ensure your Azure environment is secure, compliant, and well-managed. It provides a structured approach to organizing subscriptions, resources, and management groups, while defining standards for naming, tagging, security, and operational practices.
DevOps
Productivity
fromdzone.com
2 months ago

Eliminating Reporting Noise in Agile Teams

Unstructured proliferation of reports creates cognitive overload, wastes time, and undermines Agile teams' clarity, decision-making, and delivery.
DevOps
fromDevOps.com
3 weeks ago

Policy as Code for Cost Control, Not Just Compliance - DevOps.com

Policy as code prevents cloud cost waste by enforcing guardrails at infrastructure provisioning time, stopping small routine decisions from accumulating into significant overspend.
World politics
fromMedium
2 months ago

Beyond the waterfall state: why missions need a different decision-making architecture

Government needs architectures that combine stewardship of stable systems with agile approaches enabling divergent creativity, collective judgement, and experimentation to manage uncertainty.
#agile
Software development
fromdzone.com
3 weeks ago

Applying CI/CD Principles to Executive Reporting

Organizations operating with Agile engineering teams but Waterfall executive reporting create organizational latency that slows decision-making and resource allocation for critical infrastructure projects.
Information security
fromTechzine Global
1 month ago

When is an SBOM not an SBOM? CISA's Minimum Elements

CISA's new SBOM Minimum Elements establish baseline standards for software supply chain security, while EU regulations legally mandate SBOMs, creating a global baseline that organizations must meet to remain competitive.
Productivity
fromdzone.com
2 months ago

How Scrum Masters Boost Team Productivity

A Scrum Master improves team effectiveness by removing operational inefficiencies and focusing on delivering business value rather than raw productivity metrics like code or velocity.
Philosophy
fromMedium
1 month ago

Why code is not the source of truth

Design specifications and blueprints, not implementation code, are the authoritative source of truth; implementation is derived from and judged against originating design authority.
Agile
fromdzone.com
2 months ago

Why Agility Matters

Agility fails when organizations adopt rituals without enabling conditions; fix systemic conditions and test changes within your sphere of influence to achieve real agility.
fromSecurityWeek
1 month ago

How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development

This extends to the software development community, which is seeing a near-ubiquitous presence of AI-coding assistants as teams face pressures to generate more output in less time. While the huge spike in efficiencies greatly helps them, these teams too often fail to incorporate adequate safety controls and practices into AI deployments. The resulting risks leave their organizations exposed, and developers will struggle to backtrack in tracing and identifying where - and how - a security gap occurred.
Artificial intelligence
Software development
fromDevOps.com
1 month ago

Can QA Reignite its Purpose in the Agentic Code Generation Era? - DevOps.com

AI now generates 41% of all code with 84% of developers adopting it, requiring deterministic execution, isolated environments, and convergent correctness signals for effective agentic QA.
fromdzone.com
1 month ago

Agile's AI-Driven Paradigm Shift

"I've never felt this much behind as a programmer. The profession is being dramatically refactored as the bits contributed by the programmer are increasingly sparse and between. I have a sense that I could be 10X more powerful if I just properly string together what has become available over the last ~year and a failure to claim the boost feels decidedly like skill issue."
Artificial intelligence
fromFast Company
2 months ago

Why your AI project is about to get deprioritized (and how to save it)

Your AI pilot showed 94% accuracy improvements. The LLM is yielding solid results. You're getting defunded anyway. The reason? You solved a problem AI can solve. Your budget-holder needed you to solve theirs. Companies launch AI pilots that produce results, then stall at scale. The team's diagnosis: "They don't get it." What's really going on: These projects never earned budget-holder buy-in.
Artificial intelligence
Artificial intelligence
fromDevOps.com
1 month ago

Survey: Adoption of AI Software Testing Slowed by Trust Issues

AI is prioritized for testing but limited trust and maintenance burdens keep most organizations from embedding AI across core test workflows.
Information security
fromInfoWorld
1 month ago

Three web security blind spots in mobile DevSecOps pipelines

Mobile apps require fundamentally different security approaches than web applications because they operate as untrusted endpoints where attackers have physical access to the binary, making traditional web-centric security models inadequate.
fromMedium
2 months ago

Test smart: how to solve dilemmas as QA?

To find the typical example, just observe an average stand-up meeting. The ones who talk more get all the attention. In her article, software engineer Priyanka Jain tells the story of two colleagues assigned the same task. One posted updates, asked questions, and collaborated loudly. The other stayed silent and shipped clean code. Both delivered. Yet only one was praised as a "great team player."
Software development
fromThe Hacker News
2 months ago

Securing the Mid-Market Across the Complete Threat Lifecycle

For mid-market organizations, cybersecurity is a constant balancing act. Proactive, preventative security measures are essential to protect an expanding attack surface. Combined with effective protection that blocks threats, they play a critical role in stopping cyberattacks before damage is done. The challenge is that many security tools add complexity and cost that most mid-market businesses can't absorb. With limited budgets and lean IT and security teams, organizations often focus on detection and response.
Information security
Software development
fromInfoQ
1 month ago

Spec-Driven Development - Adoption at Enterprise Scale

Spec-Driven Development and clear intent articulation are essential for effective AI coding agents, requiring workflow integration, brownfield support, and context management for scalable adoption.
fromInfoQ
2 months ago

Developers Can Improve the ESG Aspects of Software By Tackling Early Ethical Debt

Olimpiu Pop: Hello everybody. I'm Olimpiu Pop, an InfoQ editor, and I have in front of me Erica Pisani, one of the track hosts of QCon London 2025, and a very important track in my opinion. One that is important in general, but even more important these days. And the name of the track was performance and sustainability, which seems to be two opposing words. So, Erica, please introduce yourself.
Software development
fromDbmaestro
4 years ago

Database DevOps - Where Do I Start? |

Integrating databases into the CI/CD process or the DevOps pipeline is overlooked in the current DevOps landscape. Most organizations have adapted automated DevOps pipelines to handle application code, deployments, testing, and infrastructure configurations. However, database development and administration are left out of the DevOps process and handled separately. This can lead to unforeseen bugs, production issues, and delays in the software development life cycle.
Software development
Software development
fromdzone.com
2 months ago

How Communication Profiling Stops Agile Delivery Breakdowns

Communication incompatibility is a systemic delivery risk; design Agile delivery systems to accommodate differing communication styles rather than only teaching individual communication skills.
Software development
fromTechRepublic
4 months ago

Avoid These Sprint Retrospective Mistakes (With Templates)

Sprint retrospectives should be structured as improvement-focused sessions to reflect on wins, identify obstacles, and define actionable steps for the next sprint.
[ Load more ]