<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sonatype Blog &#187; clm</title>
	<atom:link href="http://blog.sonatype.com/people/tag/clm-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sonatype.com/people</link>
	<description>Sonatype is transforming software development with tools, information and services that enable organizations to build better software, faster, using open-source components.</description>
	<lastBuildDate>Thu, 20 Jun 2013 03:49:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Only 1 Day Left!  Webinar:  Security At The Speed Of Development featuring Wendy Nather, 451 Research &amp; Ryan Berg, Sonatype</title>
		<link>http://blog.sonatype.com/people/2013/04/only-1-day-left-webinar-security-at-the-speed-of-development-featuring-wendy-nather-451-research-ryan-berg-sonatype/</link>
		<comments>http://blog.sonatype.com/people/2013/04/only-1-day-left-webinar-security-at-the-speed-of-development-featuring-wendy-nather-451-research-ryan-berg-sonatype/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 13:15:50 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[Component Lifecycle Management]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13294</guid>
		<description><![CDATA[We have a problem. Application development has become agile, component-based, and open source dependent. But security approaches haven&#8217;t kept up. Every day we&#8217;re forced to make the dangerous choice between speed and security, putting Development and Security at odds. There has to be a better way. Join Wendy Nather, Research Director, Security, at 451 Research [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.sonatype.com/people/2013/04/only-1-day-left-webinar-security-at-the-speed-of-development-featuring-wendy-nather-451-research-ryan-berg-sonatype/screen-shot-2013-04-29-at-8-46-31-am/" rel="attachment wp-att-13300"><img class="aligncenter size-full wp-image-13300" title="Screen shot 2013-04-29 at 8.46.31 AM" src="http://www.sonatype.com/people/wp-content/uploads/2013/04/Screen-shot-2013-04-29-at-8.46.31-AM.png" alt="" width="682" height="273" /></a></p>

<p style="text-align: left;">We have a problem. Application development has become agile, component-based, and open source dependent. But security approaches haven&#8217;t kept up. Every day we&#8217;re forced to make the dangerous choice between speed and security, putting Development and Security at odds. There has to be a better way.</p>

<p>Join <a href="https://451research.com/biography?eid=477" target="_blank">Wendy Nather</a>, Research Director, Security, at <a href="https://451research.com/" target="_blank">451 Research</a> tomorrow, Tuesday, April 30 from 11:00AM-11:45AM EDT (GMT-0400) to understand:</p>

<ul>
    <li>    The changes in application development that have left security behind.</li>
    <li>    Limitations of existing security approaches that could leave your organization exposed.</li>
    <li>    The new requirements that are driving security to align with application development.</li>
</ul>

<p>In addition, Sonatype CSO Ryan Berg will provide a brief overview of <a href="http://www.sonatype.com/Products/Why-CLM/Component-Lifecycle-Management" target="_blank">Sonatype CLM</a>, a new application security platform designed specifically for today&#8217;s applications and for managing the modern software supply chain.</p>

<p><a href="http://www.sonatype.com/Request/Webinar-Registration/Security-at-the-Speed-of-Development" target="_blank"><strong>Reserve Your Seat</strong></a></p>

<p><strong>If you register, you&#8217;ll also receive access to the recording after the event. So if something comes up and you can&#8217;t make it, you won&#8217;t miss out.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/only-1-day-left-webinar-security-at-the-speed-of-development-featuring-wendy-nather-451-research-ryan-berg-sonatype/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When Nexus Alone Is Not Enough &#8211; Webinar Recording Now Available!</title>
		<link>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/</link>
		<comments>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 21:35:16 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[Component Lifecycle Management]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13226</guid>
		<description><![CDATA[A big thanks goes out to everyone who was able to make it to our webinar yesterday. We appreciated all of your time, attention and great questions. If you weren&#8217;t able to make it, no worries &#8212; the recording is now available here. Please feel free to share this with your colleagues who are interested [...]]]></description>
				<content:encoded><![CDATA[<p style="text-align: left;">A big thanks goes out to everyone who was able to make it to our webinar yesterday. We appreciated all of your time, attention and great questions. If you weren&#8217;t able to make it, no worries &#8212; the recording is now available <a href="https://www.youtube.com/watch?v=DCPra4SnjJ8" target="_blank">here.</a></p>

<p style="text-align: left;">Please feel free to share this with your colleagues who are interested in learning how to get the most out of <a href="http://www.sonatype.com/Products/Nexus-Professional" target="_blank">Nexus</a>.</p>

<p style="text-align: left;">Have a great weekend everyone!</p>

<h4><a href="https://www.youtube.com/watch?v=DCPra4SnjJ8" target="_blank"><strong>Watch the replay.</strong></a></h4>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/when-nexus-alone-is-not-enough-webinar-recording-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Going to InfoSecurity Europe next week? We&#8217;ll see you there!</title>
		<link>http://blog.sonatype.com/people/2013/04/going-to-infosecurity-europe-next-week-well-see-you-there/</link>
		<comments>http://blog.sonatype.com/people/2013/04/going-to-infosecurity-europe-next-week-well-see-you-there/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 21:27:36 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[events]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13195</guid>
		<description><![CDATA[&#160; Sonatype is going to be at InfoSecurity Europe next week from Tuesday, April 23 to Thursday, April 25 in London. We&#8217;d love to show you what we&#8217;ve been working on. Be sure to swing by our booth (L94) and Nick, Wai Man and Savinder will be on-hand to help answer any of your questions. [...]]]></description>
				<content:encoded><![CDATA[<p>&nbsp;</p>

<p><a href="http://www.sonatype.com/people/2013/04/going-to-infosecurity-europe-next-week-well-see-you-there/screen-shot-2013-04-17-at-5-17-33-pm-2/" rel="attachment wp-att-13209"><img class="aligncenter size-full wp-image-13209" title="Screen shot 2013-04-17 at 5.17.33 PM" src="http://www.sonatype.com/people/wp-content/uploads/2013/04/Screen-shot-2013-04-17-at-5.17.33-PM1.png" alt="" width="355" height="230" /></a></p>

<p>Sonatype is going to be at <a href="http://www.infosec.co.uk/" target="_blank">InfoSecurity Europe</a> next week from Tuesday, April 23 to Thursday, April 25 in London. We&#8217;d love to show you what we&#8217;ve been working on. Be sure to swing by our booth (L94) and Nick, Wai Man and Savinder will be on-hand to help answer any of your questions. We’ll also be demoing <a href="http://www.sonatype.com/Products/Why-CLM/Component-Lifecycle-Management" target="_blank">CLM</a> and would love to get your feedback.</p>

<p>We&#8217;re looking forward to it and hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/going-to-infosecurity-europe-next-week-well-see-you-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Webinar: Security at the Speed of Development with Wendy Nather, 451 Research</title>
		<link>http://blog.sonatype.com/people/2013/04/new-webinar-blowing-up-old-thinking-security-at-the-speed-of-development-with-wendy-nather-451-research/</link>
		<comments>http://blog.sonatype.com/people/2013/04/new-webinar-blowing-up-old-thinking-security-at-the-speed-of-development-with-wendy-nather-451-research/#comments</comments>
		<pubDate>Mon, 15 Apr 2013 13:34:41 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13151</guid>
		<description><![CDATA[Tuesday, April 30, 2013 &#8211; 11:00AM-11:45AM EDT (GMT-0400) We have a problem. Application development has become agile, component-based, and open-source-dependent. We&#8217;re delivering more software faster than ever before, but security approaches haven&#8217;t kept up. Every day we&#8217;re forced to make the dangerous choice between speed and security, putting Development and Security at odds. There has [...]]]></description>
				<content:encoded><![CDATA[<h4></h4>

<h4>Tuesday, April 30, 2013 &#8211; 11:00AM-11:45AM EDT (GMT-0400)</h4>

<p>We have a problem. Application development has become agile, component-based, and open-source-dependent. We&#8217;re delivering more software faster than ever before, but security approaches haven&#8217;t kept up. Every day we&#8217;re forced to make the dangerous choice between speed and security, putting Development and Security at odds. There has to be a better way.</p>

<p>Join <a href="https://451research.com/biography?eid=477" target="_blank">Wendy Nather</a>, Research Director, Security, at <a href="https://451research.com/" target="_blank">451 Research</a> and Sonatype CSO, Ryan Berg on Tuesday, April 30 at 11:00AM EDT (GMT-0400) to understand the challenges that are driving new approaches to application security. You&#8217;ll also hear how how some leading application security organizations have partnered with application development to achieve both speed and security using component lifecycle management.</p>

<p>If you <a href="http://www.sonatype.com/Request/Webinar-Registration/Blowing-Up-Old-Thinking-Security-at-the-Speed-of-Development" target="_blank">register</a>, you&#8217;ll also receive access to the recording after the event. So if something comes up and you can&#8217;t make it, you won&#8217;t miss out.</p>

<h4><strong><a href="http://www.sonatype.com/Request/Webinar-Registration/Blowing-Up-Old-Thinking-Security-at-the-Speed-of-Development" target="_blank">Reserve Your Seat</a></strong></h4>

<p><a href="http://www.sonatype.com/people/2013/04/new-webinar-blowing-up-old-thinking-security-at-the-speed-of-development-with-wendy-nather-451-research/screen-shot-2013-04-15-at-7-26-16-am/" rel="attachment wp-att-13155"><img class="aligncenter size-full wp-image-13155" title="Screen shot 2013-04-15 at 7.26.16 AM" src="http://www.sonatype.com/people/wp-content/uploads/2013/04/Screen-shot-2013-04-15-at-7.26.16-AM.png" alt="" width="729" height="491" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/04/new-webinar-blowing-up-old-thinking-security-at-the-speed-of-development-with-wendy-nather-451-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Webinar &#8211; When Nexus is Not Enough: Manage Your Components Beyond the Repository</title>
		<link>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/</link>
		<comments>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/#comments</comments>
		<pubDate>Wed, 27 Mar 2013 14:27:41 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Nexus]]></category>
		<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[Sonatype webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=13075</guid>
		<description><![CDATA[At the end of April we&#8217;ll be announcing a whole new product line, Sonatype CLM, to help development groups make the best component choices. CLM (Component Lifecycle Management) extends your investment in Nexus to help inform and manage the entire software lifecycle &#8212; from design to production. We want to give you a sneak preview. [...]]]></description>
				<content:encoded><![CDATA[<p>At the end of April we&#8217;ll be announcing a whole new product line, Sonatype CLM, to help development groups make the best component choices.<a title="CLM Overview" href="http://www.sonatype.com/Products/Why-CLM/Component-Lifecycle-Management" target="_blank"> CLM (Component Lifecycle Management)</a> extends your investment in Nexus to help inform and manage the entire software lifecycle &#8212; from design to production.</p>

<p>We want to give you a sneak preview. On Thursday, April 18, 2013 from 11:00AM-11:30AM EDT (GMT-0400), Brian Fox will demo Sonatype CLM, and show you how it will help you develop faster, and still meet your company&#8217;s requirements for security and licensing. Plus, we&#8217;ll provide some tips on how you can take advantage of Nexus-only features like procurement and staging.</p>

<p>If you <a title="Webinar Registration" href="http://goo.gl/xZco4" target="_blank">register</a>, you&#8217;ll also receive access to the recording after the event. So if something comes up and you can&#8217;t make it, you won&#8217;t miss out.</p>

<h4><a title="Webinar Registration" href="http://goo.gl/xZco4" target="_blank"><strong>Reserve Your Seat</strong></a></h4>

<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/03/new-webinar-when-nexus-is-not-enough-manage-your-components-beyond-the-repository/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open Source &#8211; It&#8217;s not just about Linux, Apache HTTP &amp; MySQL</title>
		<link>http://blog.sonatype.com/people/2013/02/open-source-its-not-just-about-linux-apache-http-mysql/</link>
		<comments>http://blog.sonatype.com/people/2013/02/open-source-its-not-just-about-linux-apache-http-mysql/#comments</comments>
		<pubDate>Wed, 06 Feb 2013 02:13:05 +0000</pubDate>
		<dc:creator>Mark Troester</dc:creator>
				<category><![CDATA[Sonatype]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[clm]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12826</guid>
		<description><![CDATA[Although the hype of open source has been eclipsed by the cloud, mobile and big data, you could argue that open source remains the biggest productivity driver for IT. If you ask most people what technologies they think about when it comes to open source, they&#8217;ll probably mention Linux, or the Apache HTTP Server. Or [...]]]></description>
				<content:encoded><![CDATA[<p>Although the hype of open source has been eclipsed by the cloud, mobile and big data, you could argue that open source remains the biggest productivity driver for IT. If you ask most people what technologies they think about when it comes to open source, they&#8217;ll probably mention Linux, or the Apache HTTP Server. Or if they are thinking data, they&#8217;ll mention MySQL, or big data technologies like Hadoop. There are entire stacks of open source infrastructure technologies like <a href="http://en.wikipedia.org/wiki/LAMP_(software_bundle)">LAMP</a> and vendors like <a href="http://www.redhat.com" target="_blank">RedHat</a>, <a href="http://www.cloudera.com/content/cloudera/en/home.html" target="_blank">Cloudera</a>, and <a href="http://www.zend.com/en/" target="_blank">Zend</a> have stepped into help organizations manage open source infrastructure.</p>

<p>But what about the components that developers use to build applications? Many organizations that we talk to assemble their applications from open source components. They no longer write a lot of custom code, they stitch together components from various sources &#8211; in many cases 80-90% of modern applications are made up of components. This may seem surprising until you think of the various types of components that are used to develop  applications: utility classes, logging, caching, database access, testing frameworks, web frameworks, collection handling, etc. Why develop those feature from scratch when you can reuse components freely available on the Web?</p>

<p>So why compare Linux, Apache HTTP Server, and MySQL with open source components like junit, commons-collections, log4j? I think it helps illustrate the need for a dramatically different management approach.</p>

<p>When it comes to major decisions like operating systems, web/application servers &amp; databases, many organizations&#8230;</p>

<ul>
    <li><strong>Architecture Review </strong>-  conduct a comprehensive technology selection process driven by the architecture team… .vs. OSS components that are often selected by individual developers.</li>
    <li><strong>Vendor Selection</strong> - go through a deliberate vendor selection process, including RFI/RFP, POCs, etc… vs. OSS components where the project team is not vetted.</li>
    <li><strong>License Indemnification</strong> &#8211; protected from potential license issues via vendor indemnification&#8230; vs. OSS components with transitive dependencies on components with problematic licenses.</li>
    <li><strong>Contractual Procurement</strong> - officially contract and procure software through purchasing departments… vs. OSS components that are &#8220;free&#8221;.</li>
    <li><strong>Production Monitoring</strong> - monitor as part of an overall enterprise level <a href="http://en.wikipedia.org/wiki/Business_activity_monitoring">BAM</a> strategy… vs. OSS components that are often hidden in plain site (organizations don&#8217;t even know what they have).</li>
    <li><strong>Financial Budget</strong> - built into the regular IT budgeting cycle… vs. OSS components &#8211; again, aren&#8217;t they &#8220;free&#8221;.</li>
    <li><strong>Updates/Patches</strong> - update periodically via a pre-planned patch / update process… vs. OSS components where regular updates are not even considered.</li>
</ul>

<p>Although organizations probably don&#8217;t think risk management per se when making major open source infrastructure decisions, that really drives their decision process &#8211; minimize risk by selecting infrastructure software that is reliable, easily maintained and cost effective.</p>

<p>Shouldn&#8217;t you be doing the same at the application level? With components making up the bulk of your applications, it makes sense to manage the components in a systematic fashion. But you can&#8217;t use the same process for OSS components as you do for operating systems, databases, etc.</p>

<p>How to start? We call it <a href="http://www.sonatype.com/Products/Why-Sonatype/Component-Lifecycle-Management">Component Lifecycle Management</a>. Stay tuned as we introduce this concept over the coming weeks and months.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/02/open-source-its-not-just-about-linux-apache-http-mysql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Us: SANS Webcast &#8211; The Hidden Risk of Component Based Software Development</title>
		<link>http://blog.sonatype.com/people/2013/01/join-us-sans-webcast-the-hidden-risk-of-component-based-software-development/</link>
		<comments>http://blog.sonatype.com/people/2013/01/join-us-sans-webcast-the-hidden-risk-of-component-based-software-development/#comments</comments>
		<pubDate>Wed, 30 Jan 2013 15:07:21 +0000</pubDate>
		<dc:creator>Emily Blades</dc:creator>
				<category><![CDATA[CLM]]></category>
		<category><![CDATA[Webinar]]></category>
		<category><![CDATA[clm]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.sonatype.com/people/?p=12781</guid>
		<description><![CDATA[Sonatype has teamed up with SANS institute to bring you this informative webcast: Best Practices for Managing Software Development Risks Eighty percent of a typical application is assembled from open source and proprietary components. Development teams turn to components to gain efficiencies and speed innovation. While the promise of components is significant, organizations must mitigate [...]]]></description>
				<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-12800" style="padding-bottom: 20px;" title="blog_header_SANS" src="http://www.sonatype.com/people/wp-content/uploads/2013/01/blog_header_SANS.png" alt="Best Practices for Managing Software Development Risks: Wednesday, February 6th" width="700" height="200" /></p>

<p><strong>Sonatype has teamed up with SANS institute to bring you this informative webcast: Best Practices for Managing Software Development Risks
</strong></p>

<p>Eighty percent of a typical application is assembled from open source and proprietary components. Development teams turn to components to gain efficiencies and speed innovation. While the promise of components is significant, organizations must mitigate risk by properly managing components.</p>

<p>How do you accomplish this given the volume, complexity and diversity of today’s components?</p>

<p><a title="SANS Webcast Registration" href="http://goo.gl/DtfuW" target="_blank">Join us</a> on Wednesday, February 6th from 1:00PM-2:00PM EST (GMT-0500) as Ryan Berg, Sonatype CSO, discusses how you can realize the benefits of component-based software development while mitigating security, licensing and quality risks.</p>

<div class="span-8"><a class="btn" title="SANS Webcast Registration" href="http://goo.gl/DtfuW"><span>Reserve Your Seat</span></a></div>

<hr class="space" />
]]></content:encoded>
			<wfw:commentRss>http://blog.sonatype.com/people/2013/01/join-us-sans-webcast-the-hidden-risk-of-component-based-software-development/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
