<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on t0ul</title><link>https://t0ul.com/tags/security/</link><description>Recent content in Security on t0ul</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 25 Jan 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://t0ul.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>How I got my CISSP</title><link>https://t0ul.com/blog/how-i-got-my-cissp/</link><pubDate>Wed, 25 Jan 2023 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-i-got-my-cissp/</guid><description>&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;The Certified Information Systems Security Professional or CISSP is known for its rigorous exam and challenging requirement of needing at least 5 years of experience working in security-related roles.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m happy to say I was able to pass on the first attempt and would like to share my experience and study path with others interested in the CISSP.&lt;/p&gt;
&lt;h2 id="i-career-background"&gt;I. Career Background&lt;/h2&gt;
&lt;p&gt;DevSecOps engineer for 4 1/2 years building security features for a platform in AWS cloud with Python, Go, and Kubernetes which obtained the ISO 27001 &amp;amp; ISO 27002 type I and Type II. During that time, I also received the AWS security specialty certification. Then moved to a whole security infrastructure security analyst job for about 5 months before attempting the CISSP Exam.&lt;/p&gt;</description></item><item><title>DevSecOps Engineer Resume</title><link>https://t0ul.com/blog/devsecops-engineer-resume/</link><pubDate>Mon, 10 Oct 2022 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/devsecops-engineer-resume/</guid><description>&lt;p&gt;In this post, I provide my DevSecOps Engineer Resume as an example, and the tool I wield to make it competitive when applying to jobs.&lt;/p&gt;
&lt;h2 id="current-devsecops-engineer-resume"&gt;Current DevSecOps Engineer Resume&lt;/h2&gt;
&lt;p&gt;I use a plain text-style resume when applying online to jobs because of the Applicant Tracking System (ATS), which is a piece of software that scans most people&amp;rsquo;s resumes whenever they apply online.&lt;/p&gt;</description></item><item><title>How to Use Anchore Inline Docker Image Scan</title><link>https://t0ul.com/blog/how-to-use-anchore-inline-docker-image-scan/</link><pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-anchore-inline-docker-image-scan/</guid><description>&lt;h3 id="introduction"&gt;Introduction&lt;/h3&gt;
&lt;p&gt;Anchore is a tool that scans Docker images for common vulnerabilities and not so common vulnerabilities if you purchase the paid version. However, the free version is useful and should still be used on your team to avoid common vulnerabilities.&lt;/p&gt;
&lt;p&gt;Thankfully, the Anchore team is kind enough to have created an entire shell script to both install the Anchore Database locally and run the Anchore CLI all in one line.&lt;/p&gt;</description></item><item><title>How to use Kubebench to Add Security to a Kops Provisioned Kubernetes Cluster</title><link>https://t0ul.com/blog/how-to-use-kubebench-to-add-security-to-a-kops-provisioned-kubernetes-cluster/</link><pubDate>Mon, 17 Jun 2019 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-kubebench-to-add-security-to-a-kops-provisioned-kubernetes-cluster/</guid><description>&lt;p&gt;Kops is a popular opensource tool that makes it easier to provision and deploy Kubernetes clusters in Cloud Service Providers.&lt;/p&gt;
&lt;p&gt;However, the default provisioning may not adhere to the best practices as outlined by Kube-bench for Security, and kops probably cannot achieve a one-size-fits-all security solution as each user&amp;rsquo;s use of kops may vary.&lt;/p&gt;
&lt;p&gt;Yet, one should be aware of what default security choices kops makes on behalf of the user, which are generally well, thanks, kops team!&lt;/p&gt;</description></item><item><title>How to use Docker Bench Security for Container and Host Hardening</title><link>https://t0ul.com/blog/how-to-use-docker-bench-for-security/</link><pubDate>Wed, 17 Apr 2019 00:00:00 +0000</pubDate><guid>https://t0ul.com/blog/how-to-use-docker-bench-for-security/</guid><description>&lt;p&gt;Docker is the rage now in the field of containerization and, as a consequence, is a target for attack.&lt;/p&gt;
&lt;p&gt;Although Docker does have some security benefits out of the box upon installation enabled via the default settings, they may not be enough to prevent attacks. This article will focus on using &lt;a href="https://github.com/Docker/Docker-bench-security"&gt;Docker Bench for Security&lt;/a&gt; to aid in tweaking the settings of Docker in line with the standard best practices of using Docker.&lt;/p&gt;</description></item></channel></rss>