PERHAPS A GIFT VOUCHER FOR MUM?: MOTHER'S DAY

Close Notification

Your cart does not contain any items

DevSecOps

A leader’s guide to producing secure software without compromising flow, feedback and continuous...

Glenn Wilson

$42.95   $36.11

Paperback

Not in-store but you can order this
How long will it take?

QTY:

English
Rethink Press
10 December 2020
A structured approach to integrating security capabilities into your engineering process is an essential requirement for producing secure software without compromising the integrity of the DevOps framework.

DevSecOps provides a clear path to building systems and protocols that promotes taking ownership of software security and supports the DevOps philosophy. Learn how to:

· Establish a security-first culture within your DevOps teams

· Produce high-quality, secure software at pace

· Automate integrated security testing

· Use feedback loops to continuously improve the security of your products

· Measure security within your value streams

By:  
Imprint:   Rethink Press
Country of Publication:   United Kingdom
Dimensions:   Height: 216mm,  Width: 140mm,  Spine: 14mm
Weight:   312g
ISBN:   9781781335024
ISBN 10:   1781335028
Pages:   278
Publication Date:  
Audience:   General/trade ,  Professional and scholarly ,  ELT Advanced ,  Undergraduate
Format:   Paperback
Publisher's Status:   Active
Foreword Introduction 1 DevOps Explained The three ways The five ideals Conclusion 2 Security Explained Types of attacks Adversaries and their weapons Conclusion 3 DevSecOps Security implied in DevOps Points of contention between DevOps and security teams A layered approach to effective DevSecOps Three layers overview Conclusion 4 Layer 1: Security Education Importance of security education Security champions Gamified learning Instructor-led training Self-paced learning Pair programming and peer reviews Informal security knowledge sharing Experimentation Certification Avoiding entropy Conclusion 5 Layer 2: Secure By Design The importance of good design principles Threat modelling Clean code Naming conventions and formatting Common weakness lists Core application security design principles Microservices Container technologies Securing the pipeline Conclusion 6 Layer 3: Security Automation The importance of security automation Application security testing Mobile security testing Runtime application self-protection Software composition analysis Unit testing Infrastructure as code testing Container image scanning Dynamic threat analysis Network scanning Some testing cannot be automated Monitoring and alerting Vulnerability management Conclusion 7 Laying The Foundation Increase DevSecOps maturity Start reducing technical debt Introduce an education programme Implement security design principles Implement security test automation Measure and adjust DevSecOps starts with people Conclusion 8 Summary References Further Reading Acknowledgements The Author

Glenn Wilson is the Chief Technology Officer and Founder of Dynaminet, a consultancy company that specialises in DevSecOps and Agile security. He is an experienced development and security professional who has worked for over twenty years in the IT industry across multiple sectors. Visit https://dynaminet.com

See Also