Implementing DevSecOps Practices: Supercharge your software security with DevSecOps excellence
暫譯: 實施 DevSecOps 實踐:以 DevSecOps 卓越提升您的軟體安全性

Sehgal, Vandana Verma

  • 出版商: Packt Publishing
  • 出版日期: 2023-12-22
  • 售價: $1,540
  • 貴賓價: 9.5$1,463
  • 語言: 英文
  • 頁數: 258
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 1803231491
  • ISBN-13: 9781803231495
  • 相關分類: Excel資訊安全
  • 海外代購書籍(需單獨結帳)

買這商品的人也買了...

相關主題

商品描述

Get to grips with application security, secure coding, and DevSecOps practices to implement in your development pipeline


Key Features:


  • Understand security posture management to maintain a resilient operational environment
  • Master DevOps security and blend it with software engineering to create robust security protocols
  • Adopt the left-shift approach to integrate early-stage security in DevSecOps
  • Purchase of the print or Kindle book includes a free PDF eBook


Book Description:


DevSecOps is built on the idea that everyone is responsible for security, with the goal of safely distributing security decisions at speed and scale to those who hold the highest level of context. This practice of integrating security into every stage of the development process helps improve both the security and overall quality of the software. This book will help you get to grips with DevSecOps and show you how to implement it, starting with a brief introduction to DevOps, DevSecOps, and their underlying principles.


After understanding the principles, you'll dig deeper into different topics concerning application security and secure coding before learning about the secure development lifecycle and how to perform threat modeling properly. You'll also explore a range of tools available for these tasks, as well as best practices for developing secure code and embedding security and policy into your application. Finally, you'll look at automation and infrastructure security with a focus on continuous security testing, infrastructure as code (IaC), protecting DevOps tools, and learning about the software supply chain.


By the end of this book, you'll know how to apply application security, safe coding, and DevSecOps practices in your development pipeline to create robust security protocols.


What You Will Learn:


  • Find out how DevSecOps unifies security and DevOps, bridging a significant cybersecurity gap
  • Discover how CI/CD pipelines can incorporate security checks for automatic vulnerability detection
  • Understand why threat modeling is indispensable for early vulnerability identification and action
  • Explore chaos engineering tests to monitor how systems perform in chaotic security scenarios
  • Find out how SAST pre-checks code and how DAST finds live-app vulnerabilities during runtime
  • Perform real-time monitoring via observability and its criticality for security management


Who this book is for:


This book is for DevSecOps engineers and application security engineers. Developers, pentesters, and information security analysts will also find plenty of useful information in this book. Prior knowledge of the software development process and programming logic is beneficial, but not required.

商品描述(中文翻譯)

掌握應用程式安全性、安全編碼及 DevSecOps 實踐,以便在您的開發流程中實施

主要特點:


  • 了解安全態勢管理,以維持韌性的運營環境

  • 精通 DevOps 安全,並將其與軟體工程結合,創建穩健的安全協議

  • 採用左移方法,將早期安全整合進 DevSecOps

  • 購買印刷版或 Kindle 書籍可獲得免費 PDF 電子書

書籍描述:

DevSecOps 的理念是每個人都對安全負責,目標是在速度和規模上安全地分配安全決策給那些擁有最高上下文的人。將安全整合到開發過程的每個階段的做法有助於提高軟體的安全性和整體質量。本書將幫助您掌握 DevSecOps,並展示如何實施,首先簡要介紹 DevOps、DevSecOps 及其基本原則。

在了解這些原則後,您將深入探討有關應用程式安全性和安全編碼的不同主題,然後學習安全開發生命週期及如何正確執行威脅建模。您還將探索可用於這些任務的一系列工具,以及開發安全代碼和將安全性及政策嵌入應用程式的最佳實踐。最後,您將關注自動化和基礎設施安全,重點是持續安全測試、基礎設施即代碼 (IaC)、保護 DevOps 工具,以及了解軟體供應鏈。

在本書結束時,您將知道如何在開發流程中應用應用程式安全性、安全編碼和 DevSecOps 實踐,以創建穩健的安全協議。

您將學到什麼:


  • 了解 DevSecOps 如何統一安全與 DevOps,彌補重要的網路安全差距

  • 發現 CI/CD 管道如何整合安全檢查以自動檢測漏洞

  • 理解為何威脅建模對於早期識別和採取行動的漏洞至關重要

  • 探索混沌工程測試,以監控系統在混亂安全情境中的表現

  • 了解 SAST 如何預檢代碼,以及 DAST 如何在運行時發現實時應用漏洞

  • 通過可觀察性進行實時監控及其對安全管理的重要性

本書適合誰:

本書適合 DevSecOps 工程師和應用程式安全工程師。開發人員、滲透測試人員和資訊安全分析師也會在本書中找到大量有用的信息。對於軟體開發過程和編程邏輯的先前知識是有益的,但不是必需的。