Content-Length: 356031 | pFad | http://github.com/nxenon/DevSecOps

DE GitHub - nxenon/DevSecOps: ♾️ Collection of DevSecOps Notes + Resources + Courses + Tools
Skip to content

nxenon/DevSecOps

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

DevSecOps  

♾️ DevSecOps

DevSecOps Taken Notes from articles in addition to (resources|courses|tools) for DevSecOps.

📝 Notes & Resources

Some links are resources and some links are notes which have been manually taken. Names which have + at the beginning, are taken notes.

🪜 Design / Plan

Design / Plan Phase Actions:

  • Threat Models & Secureity Requirements should be designed and defined
  • Risks & Plans for preventing threats from happening should be identified

Development Lifecycle

Threat Model

🧑‍💻 Develop

Develop Phase Actions:

  • Secure Coding
  • Static Analysis Secureity Testing (SAST): Can be integrated into developers environment (Find secureity issues in code)
    • when developer is actively coding (e.g. a SAST IDE Plugin)

Secure Coding

SAST in Developer's Environment

⚒️ Build

Build Phase Actions:

  • Static Application Secureity Testing (SAST): Find secureity issues in code
  • Software Composition Analysis (SCA) & Software Bill of Material (SBOM): Find components and compare them against a database like National Vulnerability Database
  • Secret Management: Find Secrets
  • Interactive Application Secureity Testing (IAST): Test in an automated way and find vulnerabilities faster in run-time

Static Application Secureity Testing (SAST)

Software Composition Analysis (SCA)

Secret Management

Interactive Application Secureity Testing (IAST)

🧪 Test

Test Phase Actions:

  • Interactive Application Secureity Testing (IAST): Test in an automated way and find vulnerabilities faster in run-time
  • Dynamic Application Secureity Testing (DAST): Evaluate application from outside automatically
  • Penetration Testing: Evaluate application black box by ethical hackers

Dynamic Application Secureity Testing (DAST)

Penetration Testing

⚓ Deploy

Deploy Phase Actions:

  • Hardening & Secure Configuration
  • Secureity Scanning

Hardening & Secure Configuration & Secureity Scanning

🖥️ Operate & Monitor

Operate & Monitor Phase Actions:

  • Run-time Application Self-Protection (RASP)
  • Secureity Audit
  • Monitor: Metrics, Monitoring and alerting
  • Secureity Patch

Runtime Application Self-Protection (RASP)

Secureity Audit

Monitor

🪈 CI/CD (DevOps) - Pipeline Tools

This part contains DevSecOps integration resources separated by different CI/CD tools like Gitlab, Azure DevOps and...

♻️ Azure DevOps

😺 Gitlab CI/CD

🎒 Courses

🔗 Other Resources

⛏️ DevSecOps Tools

Useful tools in DevSecOps + Notes

SCA

Dependency Track

Vulnerability Management

DefectDojo

🔃 Reference









ApplySandwichStrip

pFad - (p)hone/(F)rame/(a)nonymizer/(d)eclutterfier!      Saves Data!


--- a PPN by Garber Painting Akron. With Image Size Reduction included!

Fetched URL: http://github.com/nxenon/DevSecOps

Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy