Cloud Native Software Security Handbook: Unleash the power of cloud native tools for robust security in modern applications
暫譯: 雲原生軟體安全手冊:釋放雲原生工具在現代應用程式中強健安全的力量
Shah, Mihir
- 出版商: Packt Publishing
- 出版日期: 2023-08-25
- 售價: $1,860
- 貴賓價: 9.5 折 $1,767
- 語言: 英文
- 頁數: 372
- 裝訂: Quality Paper - also called trade paper
- ISBN: 1837636982
- ISBN-13: 9781837636983
-
相關分類:
資訊安全
海外代購書籍(需單獨結帳)
商品描述
Master widely used cloud-native platforms like Kubernetes, Calico, Kibana, Grafana, Anchor, and more to ensure secure infrastructure and software development
Key Features
- Learn how to select cloud-native platforms and integrate security solutions into the overall system
- Leverage cutting-edge tools and platforms and use them, securely, at a global scale in production
- Discover the laws and regulations that you should be aware of to avoid federal prosecution
Book Description
For a Cloud security engineer, it is crucial to think beyond the few managed services provided by the cloud vendor and truly use the plethora of cloud-native tools available for developers and security professionals, which allow for providing security solutions at scale. In this book, we cover technologies for securing the infrastructure, containers, and runtime environments using vendor-agnostic cloud-native tools under the CNCF.
The book begins by introducing the what and whys of the cloud-native environment along with a primer about the platforms that we would be exploring ongoing in the book. We then progress in the book as one would in the development phase of an application. We continue by exploring the System design choices and security trade-offs and then secure application coding techniques that every developer should be mindful of. As we move into more advanced topics, we look into the security architecture of the system and threat modelling practices, and we conclude by explaining the laws and guidelines regulating security practices in the cloud native space while exploring some real-world repercussions that companies have faced in the past due to a company's immature security practices.
By the end of the book, you'll find yourself better positioned in creating secure safe code and system designs.
What you will learn
- Learn security concerns and challenges for cloud-based app development
- Explore various tools for securing config, networks, and runtime
- Implementing threat modeling for risk mitigation strategies
- Implement various security solutions for the CI/CD pipeline
- Discover best practices for logging, monitoring, and alerting
- Understand regulatory compliance product impact on cloud security
Who This Book Is For
The target audience for the book would be developers, security professionals, and DevOps teams who are involved in designing, developing, and deploying cloud-native applications. It is intended for those with a technical background who want to gain a deeper understanding of cloud-native security and learn about the latest tools and technologies for securing cloud-native infrastructure and runtime environments. Having prior experience with cloud vendors and their managed services would be a plus to leveraging all the tools and platforms explained in this book.
商品描述(中文翻譯)
掌握廣泛使用的雲原生平台,如 Kubernetes、Calico、Kibana、Grafana、Anchor 等,以確保安全的基礎設施和軟體開發
主要特點
- 學習如何選擇雲原生平台並將安全解決方案整合到整體系統中
- 利用尖端工具和平台,並在全球範圍內安全地使用它們於生產環境中
- 了解應注意的法律法規,以避免聯邦起訴
書籍描述
對於雲安全工程師來說,超越雲供應商提供的少數管理服務,真正利用可供開發人員和安全專業人員使用的眾多雲原生工具,對於提供可擴展的安全解決方案至關重要。在本書中,我們將涵蓋使用 CNCF 下的供應商無關雲原生工具來保護基礎設施、容器和運行時環境的技術。
本書首先介紹雲原生環境的基本概念及其重要性,並簡要介紹我們將在書中探討的平台。接著,我們將按照應用程式開發階段的進展來進行本書的內容。我們將探討系統設計選擇和安全權衡,然後介紹每位開發人員應注意的安全應用程式編碼技術。隨著我們進入更高級的主題,我們將研究系統的安全架構和威脅建模實踐,最後解釋雲原生領域中規範安全實踐的法律和指導方針,同時探討一些公司因為不成熟的安全實踐而面臨的現實後果。
在本書結束時,您將能夠更好地創建安全的代碼和系統設計。
您將學到的內容
- 了解雲端應用程式開發的安全問題和挑戰
- 探索各種工具以保護配置、網路和運行時
- 實施威脅建模以制定風險緩解策略
- 為 CI/CD 管道實施各種安全解決方案
- 發現日誌記錄、監控和警報的最佳實踐
- 理解合規性對雲安全的影響
本書適合的讀者
本書的目標讀者為開發人員、安全專業人員和 DevOps 團隊,這些人員參與設計、開發和部署雲原生應用程式。適合那些具有技術背景的人,想要深入了解雲原生安全並學習最新的工具和技術,以保護雲原生基礎設施和運行時環境。擁有雲供應商及其管理服務的先前經驗將有助於充分利用本書中解釋的所有工具和平台。
目錄大綱
- Understanding Cloud Native Architecture
- Secure System Design using Cloud Native
- Application Development practices in Cloud Native world
- Developing a Secure Coding Culture
- Threat Modeling for Cloud Native
- Securing the Infrastructure
- Cloud Security Operations
- DevSecOps Practices for Cloud Native
- Legal and Compliance Issues
- Cloud Native Vendor Management and Security Certifications
目錄大綱(中文翻譯)
- Understanding Cloud Native Architecture
- Secure System Design using Cloud Native
- Application Development practices in Cloud Native world
- Developing a Secure Coding Culture
- Threat Modeling for Cloud Native
- Securing the Infrastructure
- Cloud Security Operations
- DevSecOps Practices for Cloud Native
- Legal and Compliance Issues
- Cloud Native Vendor Management and Security Certifications