Security Software Development: Assessing and Managing Security Risks
暫譯: 安全軟體開發:評估與管理安全風險
Ashbaugh, Cissp
- 出版商: Auerbach Publication
- 出版日期: 2019-09-05
- 售價: $2,810
- 貴賓價: 9.5 折 $2,670
- 語言: 英文
- 頁數: 321
- 裝訂: Quality Paper - also called trade paper
- ISBN: 0367386607
- ISBN-13: 9780367386603
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
相關主題
商品描述
Threats to application security continue to evolve just as quickly as the systems that protect against cyber-threats. In many instances, traditional firewalls and other conventional controls can no longer get the job done. The latest line of defense is to build security features into software as it is being developed.
Drawing from the author's extensive experience as a developer, Secure Software Development: Assessing and Managing Security Risks illustrates how software application security can be best, and most cost-effectively, achieved when developers monitor and regulate risks early on, integrating assessment and management into the development life cycle. This book identifies the two primary reasons for inadequate security safeguards: Development teams are not sufficiently trained to identify risks; and developers falsely believe that pre-existing perimeter security controls are adequate to protect newer software. Examining current trends, as well as problems that have plagued software security for more than a decade, this useful guide:
- Outlines and compares various techniques to assess, identify, and manage security risks and vulnerabilities, with step-by-step instruction on how to execute each approach
- Explains the fundamental terms related to the security process
- Elaborates on the pros and cons of each method, phase by phase, to help readers select the one that best suits their needs
Despite decades of extraordinary growth in software development, many open-source, government, regulatory, and industry organizations have been slow to adopt new application safety controls, hesitant to take on the added expense. This book improves understanding of the security environment and the need for safety measures. It shows readers how to analyze relevant threats to their applications and then implement time- and money-saving techniques
商品描述(中文翻譯)
應用程式安全的威脅持續演變,速度與保護網路威脅的系統一樣迅速。在許多情況下,傳統的防火牆和其他常規控制措施已無法滿足需求。最新的防線是將安全功能內建於正在開發的軟體中。
根據作者作為開發者的豐富經驗,《安全軟體開發:評估與管理安全風險》說明了當開發者在早期監控和調節風險,並將評估與管理整合進開發生命週期時,如何以最佳且最具成本效益的方式實現軟體應用程式安全。本書指出了安全防護不足的兩個主要原因:開發團隊未經充分訓練以識別風險;以及開發者錯誤地認為現有的邊界安全控制足以保護較新的軟體。本書檢視了當前趨勢以及困擾軟體安全超過十年的問題,並提供了以下有用的指導:
- 概述並比較各種評估、識別和管理安全風險與漏洞的技術,並提供逐步指導如何執行每種方法
- 解釋與安全過程相關的基本術語
- 詳述每種方法的優缺點,逐階段幫助讀者選擇最適合其需求的方案
儘管軟體開發經歷了數十年的驚人增長,許多開源、政府、監管和行業組織在採用新的應用安全控制方面仍然緩慢,對承擔額外費用感到猶豫。本書增進了對安全環境及安全措施需求的理解。它向讀者展示如何分析其應用程式相關的威脅,並實施節省時間和金錢的技術。