Hands-On Security in DevOps: Ensure continuous security, deployment, and delivery with DevSecOps

Portada
Packt Publishing Ltd, 2018 M07 30 - 356 páginas

Protect your organization's security at all levels by introducing the latest strategies for securing DevOps

Key FeaturesIntegrate security at each layer of the DevOps pipelineDiscover security practices to protect your cloud services by detecting fraud and intrusionExplore solutions to infrastructure security using DevOps principlesBook Description

DevOps has provided speed and quality benefits with continuous development and deployment methods, but it does not guarantee the security of an entire organization. Hands-On Security in DevOps shows you how to adopt DevOps techniques to continuously improve your organization’s security at every level, rather than just focusing on protecting your infrastructure.

This guide combines DevOps and security to help you to protect cloud services, and teaches you how to use techniques to integrate security directly in your product. You will learn how to implement security at every layer, such as for the web application, cloud infrastructure, communication, and the delivery pipeline layers. With the help of practical examples, you’ll explore the core security aspects, such as blocking attacks, fraud detection, cloud forensics, and incident response. In the concluding chapters, you will cover topics on extending DevOps security, such as risk assessment, threat modeling, and continuous security.

By the end of this book, you will be well-versed in implementing security in all layers of your organization and be confident in monitoring and blocking attacks throughout your cloud services.

What you will learnUnderstand DevSecOps culture and organizationLearn security requirements, management, and metricsSecure your architecture design by looking at threat modeling, coding tools and practicesHandle most common security issues and explore black and white-box testing tools and practicesWork with security monitoring toolkits and online fraud detection rulesExplore GDPR and PII handling case studies to understand the DevSecOps lifecycleWho this book is for

Hands-On Security in DevOps is for system administrators, security consultants, and DevOps engineers who want to secure their entire organization. Basic understanding of Cloud computing, automation frameworks, and programming is necessary.

 

Contenido

Preface
1
DevSecOps Drivers and Challenges
7
Security Goals and Metrics
28
Security Assurance Program and Organization
48
Security Requirements and Compliance
65
Case Study Security Assurance Program
79
Security Architecture and Design Principles
90
Threat Modeling Practices and Secure Design
106
Security Automation with the CI Pipeline
199
Incident Response
211
Security Monitoring
227
Security Assessment for New Releases
238
Threat Inspection and Intelligence
248
Business Fraud and Service Abuses
262
GDPR Compliance Case Study
274
DevSecOps Challenges Tips and FAQs
286

Secure Coding Best Practices
120
Case Study Security and Privacy by Design
137
SecurityTesting Plan and Practices
152
Whitebox Testing Tips
169
Security Testing Toolkits
184
Assessments
313
Other Books You May Enjoy
320
Index
323
Derechos de autor

Otras ediciones - Ver todas

Términos y frases comunes

Acerca del autor (2018)

Tony Hsu is a senior security architect with over 20 years of experience in security services technology. He has rich experience with Secure Software Development LifeCycle (SSDLC), is deeply involved with security activities such as security requirements planning, threat modeling, secure architecture and design review, secure code review, automated security testing, and cloud services security monitoring. He is also in-house SDL trainer. He is also a co contributor on OWASP projects such as OWASP testing guide, proactive control guide, and deserialization security cheatsheet.

Información bibliográfica