000 02865cam a2200229 i 4500
008 211007s2022 xx o 000 0 eng d
020 _a9781032151205
040 _cTBS
041 _aeng
050 4 _aQA76.9.A25
100 _aMerkow, Mark S.
_923376
_eauthor
245 1 0 _aPractical security for agile and DevOps
_c/ Mark S. Merkow, CISSP, CISM, CSSLP.
250 _aFirst edition.
260 _aBoca Raton, FL : CRC Press, Taylor and Francis, 2022.
300 _axxv, 209 pages : illustrations, graphs, tables (black and white) ; 26 cm.
504 _aIncludes bibliographical references and index.
505 _aToday’s software development practices shatter old security practices — Deconstructing Agile and Scrum — Learning is FUNdamental! — Product backlog development — Building security in — Secure design considerations — Security in the design sprint — Defensive programming — Testing part 1 : static code analysis — Testing part 2 : penetration testing/dynamic analysis/IAST/RASP — Securing DevOps — Metrics and models for AppSec maturity — Frontiers for AppSe — AppSec is a marathon—Not a sprint! — Appendix A : security acceptance criteria — Appendix B : resources for AppSec — Appendix C : answers to chapter quick check questions.
520 _aThis textbook was written from the perspective of someone who began his software security career in 2005, long before the industry began focusing on it. This is an excellent perspective for students who want to learn about securing application development. After having made all the rookie mistakes, the author realized that software security is a human factors issue rather than a technical or process issue alone. Throwing technology into an environment that expects people to deal with it but failing to prepare them technically and psychologically with the knowledge and skills needed is a certain recipe for bad results. Practical Security for Agile and DevOpsis a collection of best practices and effective implementation recommendations that are proven to work. The text leaves the boring details of software security theory out of the discussion as much as possible to concentrate on practical applied software security that is useful to professionals. It is as much a book for students’ own benefit as it is for the benefit of their academic careers and organizations. Professionals who are skilled in secure and resilient software development and related tasks are in tremendous demand. This demand will increase exponentially for the foreseeable future. As students integrate the text’s best practices into their daily duties, their value increases to their companies, management, community, and industry.
650 0 _aComputer security
_92657
650 0 _aAgile software development
_911082
942 _2lcc
999 _c3567
_d3567