Jeff Barr, Vice President & Chief Evangelist at Amazon Web Services, has mentioned OpenSecOps Foundation & SOAR on LinkedIn:
Full post and comments here:
0 Comments
Embracing Transparency and CommunityToday, we're excited to announce a significant milestone for OpenSecOps: the complete transition of our platform to open source. This decision represents our commitment to transparency, community collaboration, and ensuring the long-term viability of these security tools. Why Open Source?Our journey towards open source began with several components already freely available on GitHub. The success of these tools – like our serverless log aggregation system and SSO configuration utilities – showed us the value of community engagement and transparent development. As economic conditions shifted in 2024, particularly affecting the specialised technical consulting market, we faced important decisions about the future of these security-critical platforms. After careful consideration of what would best serve our existing customers and the broader AWS security community, the path forward became clear: complete open source was the answer. Ensuring Continuity Through TransparencyThe primary motivation behind our open source transition is straightforward: ensuring continuity and security for organisations that depend on these tools. By open-sourcing our entire platform:
Security-First Open SourceUnlike many open source projects that prioritise rapid feature development, our approach is distinctly security-focused:
This security-first governance model reflects the reality that OpenSecOps components are deployed in financial services and other security-sensitive environments where stability and security are non-negotiable requirements. What's Now Available Our complete platform is now open source, including:
How to Get StartedGetting started with OpenSecOps is straightforward:
Looking Forward Going open source is just the beginning. We're committed to:
In ConclusionThe open source model offers the ideal path forward for these security platforms. It ensures transparency, continuity, and community engagement whilst maintaining the high security standards that our users require.
We believe that security tools should be accessible, transparent, and community-driven. By embracing open source, we're creating a foundation for more secure AWS environments across all organisations, regardless of size or industry. Join us on this journey as we build a more secure cloud future together. We see open source as a strength. It's no secret that part of our offerings is open source, written by us or other reputable developers. For instance, here's the new version of our serverless log aggregation system:
https://github.com/OpenSecOps-Org/Foundation-control-tower-log-aggregator The log aggregator is part of OpenSecOps Foundation and will massage your AWS log files to cut your log file storage costs in half, amongst other things. Suppose you use it with our open-source multi-account log aggregator, (https://github.com/OpenSecOps-Org/Foundation-CloudWatch2S3). In that case, you have a complete solution for automatically collecting CloudWatch logs from all accounts in an AWS organization and storing them centrally in a consistent format and structure along with all system logs. Best of all, it costs you absolutely nothing. You'll find all our open-source offerings here. Why do we do this? Because we like to get the initial complexities out of the way so we can assist our clients with the architecture that really matters. Thus, OpenSecOps Foundation has no license fee; we only charge for the time it takes us to install it. Now that's a value proposition you might want to consider. P.S.: Apart from our open source, you'll like our proprietary security aspects too, which include fully text-based configuration and a battle-tested system to prevent any escalation of privileges, amongst other things. Full details here. |
Archives
April 2025
Categories
All
|