Friday, September 29, 2017

Agile Application Security book

This is the first post in a while. I've been busy working on a bunch of projects. One of them is now finally complete: a book on Agile Application Security for O'Reilly, with Laura Bell, Michael Brunton-Spall, and Rich Smith.

In this book we try to build bridges between the security community and Agile teams, by taking advantage of our different experiences and viewpoints:

  • Rich's extensive experience as a pen tester, and running the security team at Etsy.
  • Michael's experience in hyperdrive Agile development, DevOps and security at The Guardian and the UK Digital Service.
  • Laura's work as a software developer and application security cat herder with large and small organizations in many different stages on their journeys to Agile adoption.
  • My work in development and operations in enterprise financial technology.

This is a unique book that looks at Agile from a security perspective, and security from an Agile perspective.

We explain the driving ideas and key problems in security, and the core enabling practices in Agile that help teams succeed, and how security programs can leverage Agile ideas and practices. How to deal with important risks and problems, and how to scale.

We look in detail at security practices and tools in an Agile context: threat and risk management, how to think about security in requirements, secure coding and code reviews, security testing in Continuous Integration and Continuous Deployment, what scanning can and cannot do for you, building hardened infrastructure and running secure systems, and putting all of this together into automated pipelines and feedback loops.

We also step through regulatory compliance and how to achieve continuous compliance; and how to get value from working with outsiders, including auditors, pen testers and bug bounty programs. We end with how to build an agile security culture and how to break down walls between engineers and security.

It was a unique opportunity to work with experts around the world: Michael in the UK, Laura in New Zealand, Rich in the US. Challenging, exhausting, and a great learning experience.

Our hope is that it offers value to developers who work in Agile environments and are new to security; to people in the security community who want to understand how security can keep up with high-velocity Agile and DevOps teams; and even to people who are expert in both.


cassy said...

It is a great chance I had to read your amazing article for sure I have cached for future reading. Kindly keep updating us on new articles. Are you health conscious? Have you suffered from the negative effect of water quality? then Best Whole House Sediment Water Filter System is for you, For best experience in water purification.

Andrew303john said...

Finance Assignment Help

We at bring to you the most significant Finance assignment writing service at the best cost. With long stretches of understanding we are prepared to give assignment help over the globe.You will be guided here with a portion of the information of Finance assignment which could assist you in deciding writing a Finance assignment. Nonetheless we uneuqivocally prescribe you to benefit Managerial accounting assignment help from our specialist to find out about marketing and its scope.

SoftHost said...

Você está procurando planos personalizados de hospedagem de janelas para o site da sua empresa? Em caso afirmativo, a Soft Host é uma empresa líder de Revenda Windowsem que sua pesquisa termina. Somos um provedor líder de hospedagem de janelas, que oferece planos ilimitados e acessíveis que podem combinar perfeitamente com suas necessidades e objetivos de negócios.

digitalmarketingcompanyinchennai said...

Good post... Now everything has become digital cause people want to get everything instantly Marketing also becomes easy and less cost which is called digital marketing.
digital marketing company, digital Marketing Agency in Chennai, SEO company in chennai

BATU said...

nice article very useful your post Thank you so much

BATU said...

thanks for the great article to become a expert

BATU said...

Amazing writing skills shown

Ascent Fund Services said...

Ascent is an experienced and self-determining Alternative Investment Fund Administrator, providing tailored solutions for different fund segments such as private equity funds, Hedge funds, and unit trust funds.

assignmentauthors said...

Quality services has been a major choice of action by various institutions and organization both governmental and non-governmental. product description writer

Unknown said...

If you're looking to lose weight then you need to jump on this totally brand new custom keto meal plan diet.

To create this keto diet service, licensed nutritionists, fitness trainers, and cooks have joined together to provide keto meal plans that are efficient, suitable, cost-efficient, and delightful.

From their first launch in January 2019, thousands of individuals have already transformed their figure and health with the benefits a professional keto meal plan diet can offer.

Speaking of benefits: clicking this link, you'll discover 8 scientifically-proven ones provided by the keto meal plan diet.

Quicken support said...

When you update your bank account in Quicken, at that point of time there is a chance of encountering Quicken Error cc-503. To learn how to solve it, simply read the blog-post. We have put much effort to provide easy guide so you can effortlessly annihilate.
Quicken Error OL-293-A
Quicken Error OL-294-A
Quicken error OL--1-B
quicken error ol-221-a|
Quicken Error CC-502

Euni said...

Thank you for bringing to a halt my long search topic. I really benefited from your content. If you are experiencing trouble striking a balance between your busy academic life and handling your online classes, you can get help from a professional who will take online classes on your behalf. It doesn’t matter the kind of help you need, whether it is passing your exam, finishing your assignments or even the entire classwork, you can get help here at Online Class Help .

Dona Hadley said...

Excellent article. Very interesting to read. I really love to read such a nice article. Thanks! keep rocking. We also provide college-level accounting help. Hire our experts for getting accounting and homework done. Kindly visit our site my accounting.

hulucomactivateroku said...

Adding the Hulu app on Roku
Follow the specified guidelines to add the Hulu app on Roku:
Initially, select the Roku channel store using the enhanced remote and explore through it to find out where Hulu is present
Secondly, you must type the channel's name in the search box and add the channel to your account after you choose the "Add channel" option
As the streaming service gets added, it is essential that the Hulu activation process can be done by using the Hulu activation code
Avail this service for a trial period and get the job done in a short time.

For more of your queries on Hulu Activation on Roku visit +1-844-885-8900.

Ryan phillip said...

Almost everyone who loves to stream a lot of content knows that Amazon Fire TV stick is one of the most delicate devices ever available in the digital arena. PBS is one such channel on Amazon that is notable for its programs that involve toddlers. Known by the name “Public Broadcasting corporation,” it is known to be one of the largest networks in the USA. Streaming this channel in the Amazon Fire TV Stick would resemble a bolt from the sky as children can get to know what education looks like in real. Instead of making academics too dull and exhausted, PBS kids follow its approach and empowers young minds through cartoons and games! For more info on PBS Kids on Amazon Firestick call us at +1-844-879-5200

Site Meter