<output id="qn6qe"></output>

    1. <output id="qn6qe"><tt id="qn6qe"></tt></output>
    2. <strike id="qn6qe"></strike>

      亚洲 日本 欧洲 欧美 视频,日韩中文字幕有码av,一本一道av中文字幕无码,国产线播放免费人成视频播放,人妻少妇偷人无码视频,日夜啪啪一区二区三区,国产尤物精品自在拍视频首页,久热这里只有精品12

      Securing Your DevOps Pipelines - 1

      Securing Your DevOps Pipelines

      • Background on DevOps
      • Security in DevOps or DevSecOps
      • DevSecOps Tools
      • Setting up a DevSecOps Pipeline
      • Final Security Checks

      Background on DevOps

      1.1 Understand where DevOps came from

      Long development cycles lead to cascading problems

      • Security issues
      • Feature conflicts
      • QA bottleneck
      • Scope creep
      • Overlapping development

      Business needed to speed up deploy cycles.

      • Develop -->QA Bugs-->Back to develop-->Add more features

      The process needed to be reproducible.

      Needed to handle a number of steps.

      • Build artifact
      • Run unit tests
      • Report failed tests
      • Set environment variables
      • Deploy to QA
      • Run integration tests
      • Deploy to staging
      • Clear cache
      • Deploy to feature environment
      • Deploy to production

      1.2 Learn how DevOps Works

      Plan

      Gather all of the feature requirements.

      Code

      Implement the code to add the feature to the application.

      Build

      Create the application build files.

      Test

      Run unit tests, do quality assurance (QA), and run integration tests.

      Release

      Tag a release of the approved feature implementation.

      Deploy

      Ship the approved feature implementation to production.

      Operate

      Keep the application running for end users and customers.

      Monitor

      Watch for any changes in the application's functionality.

      1.3 DevOps versus Waterfall

      Everything needs to be finished before deploying.

      Incremental release make it less likely for bugs to get to production.

      Harder to make changes when feedback comes.

      Allow stakeholders to test out functionality as it is completed.

      Can make code changes take months to release.

      Able to release code changes multiple times per day.

      New code slowly gets added to the initial request.

      Controls scope creep.

      Security gets left until the very end.

      Security can be added in a number of places.

      Security in DevOps or DevSecOps

      2.1 Show where security comes in

      Previously at the end of the waterfall

      • Feature development, QA, build candidate
      • Security testing
      • Deployment

      Happens at each stage in the pipeline

      • Feature development
      • Security testing
      • QA
      • Security testing

      Detecting issues early shortens development.

      image-20251022165413876

      Easier to include before issues arise.

      2.2 Learn how issues get to production

      Time restrictions

      Hard to get answers

      • What stages should run in parallel?
      • What are the auth methods for services?
      • Which CLI tools should be used?

      Unfamiliar with tools

      • Google Cloud
      • Docker
      • AWS
      • Kubernetes
      • Azure
      • Redis

      Unfamiliar with pipelines

      2.3 Learn the OWAPS 10 Top security risks

      image-20251022170304465

      https://owasp.org/www-project-top-ten/assets/images/mapping.png

      Broken Access Control

      Bypass access control checks by adding parameters to the URL.

      APIs with missing access controls for POST, PUT and DELETE requests

      Not following the principle of least privilege.

      Cryptographic Failures

      Data transmitted in clear text

      Use of deprecated dash functions such as MD5 or SHA1

      Have crypto keys checked into source code repositories.

      Injection

      No validation on user input.

      Malicious data gets used in SQL queries

      Scripts get add to and executed on a web page

      Insecure Design

      Missing or ineffective control design.

      Security isn't addressed in user stories.

      Certain user flow logic is weak.

      Security Misconfiguration

      Default user names and passwords are still in place for services.

      Unnecessary features are installed that open access to restricted data.

      Too much information is shared with users in error messages.

      Vulnerable and Outdated Components

      Current versions of the libraries used are behind the newest versions.

      Compatibility with different libraries goes unchecked

      Libraries are installed from unreliable sources.

      2.4 Understand how attackers gain unauthorized access to apps

      They use a number of free and paid tools.

      They check for app and system misconfigurations.

      They look for secrets in your version control.

      They check for extra open ports.

      They look for vulnerabilities in your packages.

      2.5 Learn the basics of DevSecOps access to apps

      Adds automated security best practices to DevOps

      image-20251022172456254

      Keeps security considerations front of mind for each pipeline stage.

      Spreads the responsibility of how security is addressed.

      image-20251022172759846

      2.6 Use DevSecOps to mitigate risks

      Detect common security vulnerabilities automatically.

      Monitoring sends alerts to the right teams.

      image-20251022173132444

      Get feedback faster when new risks are noted.

      Lots of tools available.

      DAST, OAST, SAST, IAST, Cloud security, Issue tracking

      posted @ 2025-10-22 18:36  晨風_Eric  閱讀(3)  評論(0)    收藏  舉報
      主站蜘蛛池模板: 中文字幕亚洲人妻一区| 久久婷婷成人综合色| 精品无码久久久久国产电影| 国产乱人伦无无码视频试看| 亚洲av色在线观看国产| 日本欧美大码a在线观看| 亚洲欧美人成人让影院| 喷潮出白浆视频在线观看| 临泉县| 国产AV巨作丝袜秘书| 国产亚洲精品久久久久秋霞| 嫩草成人AV影院在线观看| 成人网站网址导航| 最新精品露脸国产在线| 国产成人8X人网站视频| 美女无遮挡免费视频网站| 亚洲国产精品国自拍av| 亚洲av无码片在线播放| 丰满的人妻hd高清日本| 日韩中文字幕av有码| 国产精品免费看久久久| 亚洲精品中文字幕码专区| 99久久久国产精品消防器材| 高清无码18| 欧美极品色午夜在线视频| 会昌县| 亚洲第一国产综合| 青青青青国产免费线在线观看| 日日爽日日操| 成人精品区| 亚洲国产成人久久一区久久| 九九综合va免费看| 日韩精品亚洲专在线电影| 天堂网亚洲综合在线| 色综合激情丁香七月色综合| 狠狠婷婷色五月中文字幕| 金沙县| 欧美综合区自拍亚洲综合绿色| 亚洲国产在一区二区三区| 日韩乱码人妻无码中文字幕视频 | 宿州市|