从反模式到最佳实践:DevSecOps 自动化和安全实用指南.pdf

编号:981439 PDF 33页 595.79KB 下载积分:VIP专享
下载报告请您先登录!

从反模式到最佳实践:DevSecOps 自动化和安全实用指南.pdf

1、From Anti-Patterns to Best PracticesA Practical Guide to DevSecOps Automation and Security1(FUD)Fear 2Uncertainty Doubt Computer Security is about humans 3$id https:/ integration standards project co-leadOpenCRE.org maintainerFounder of 4ItineraryObservability1.Shifting left badly2.Offering bad secu

2、rity servicesReporting3.Misusing Source of Truth dashboards4.Security alphabet soupMeasuring5.Bad metrics5 DontAutorun free/vendor tools(Shift Left)Outsource tool&result management to your teamsForce strict SLAs for teams(unless required for regulation)6 ExampleUse Code Scanning per day per teamBloc

3、k teams that fail X number of Code Scan runsDemand everyone fix Critical Code Scan findings after 3 days7Observability8 Why Noise Alert fatigue Lack of context Humans focus on delivery,they should not focus on security alerts9 Do Add context to your tools Dare to ignore findings automatically Dare t

4、o fix automatically(beyond dependabot)10 Do Add context to your tools Dare to ignore findings automatically Dare to fix automatically(beyond dependabot)11 Example Tag teams per scope/deployment setup(internal/external)Ignore noisy tools/rules Vertex API-Code-Bison model-“please generate a fix for co

5、ntext”12 Dont Automagically run centrally configured,immutable scans“somewhere else”and give teams only the reports with things to fix.13 ExampleRun open source container image scanning toolTeams get results for their production images when they releaseReleases blocked on Critical findings14“Secure

6、Baseline”!=“Secure”Noise Cryptic Messages Lack of Context Lack of Information Why 15 Provide everyone with an immutable baseline.“As a minimum we care about”Let teams/champions decide what their particular team/scenario needs and customize both scanning and reporting Do16 Sane,distroless(or minimal)

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(从反模式到最佳实践:DevSecOps 自动化和安全实用指南.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠