Implementing DevSecOps Practices: Understand application security testing and secure coding by integrating SAST and DAST
Imported Edition - Ships in 18-21 Days
Free Shipping in India on orders above Rs. 500
Imported Edition - Ships in 18-21 Days
Free Shipping in India on orders above Rs. 500
Integrate Shift-Left Security, automation, IaC, and compliance into every stage of development, ensuring strong application security and continuous protection for modern software with DevSecOps best practices
Key Features
- Understand security posture management to maintain a resilient operational environment
- Master DevOps security and blend it with software engineering to create robust security protocols
- Adopt the left-shift approach to integrate early-stage security in DevSecOps
- Purchase of the print or Kindle book includes a free PDF eBook
Book Description
DevSecOps is built on the idea that everyone is responsible for security, with the goal of safely distributing security decisions at speed and scale to those who hold the highest level of context. This practice of integrating security into every stage of the development process helps improve both the security and overall quality of the software. This book will help you get to grips with DevSecOps and show you how to implement it, starting with a brief introduction to DevOps, DevSecOps, and their underlying principles.
After understanding the principles, you'll dig deeper into different topics concerning application security and secure coding before learning about the secure development lifecycle and how to perform threat modeling properly. You'll also explore a range of tools available for these tasks, as well as best practices for developing secure code and embedding security and policy into your application. Finally, you'll look at automation and infrastructure security with a focus on continuous security testing, infrastructure as code (IaC), protecting DevOps tools, and learning about the software supply chain.
By the end of this book, you'll know how to apply application security, safe coding, and DevSecOps practices in your development pipeline to create robust security protocols.
What you will learn
- Find out how DevSecOps unifies security and DevOps, bridging a significant cybersecurity gap
- Discover how CI/CD pipelines can incorporate security checks for automatic vulnerability detection
- Understand why threat modeling is indispensable for early vulnerability identification and action
- Explore chaos engineering tests to monitor how systems perform in chaotic security scenarios
- Find out how SAST pre-checks code and how DAST finds live-app vulnerabilities during runtime
- Perform real-time monitoring via observability and its criticality for security management
Who this book is for
This book is for individuals new to DevSecOps and want to implement its practices successfully and efficiently. DevSecOps Engineers, Application Security Engineers, Developers, Pentesters, and Security Analysts will find plenty of useful information in this book. Prior knowledge of the software development process and programming logic is beneficial, but not mandatory.
Table of Contents
- Introducing DevSecOps
- DevSecOps Principles
- Understanding the Security Posture
- Understanding Observability
- Understanding Chaos Engineering
- Continuous Integration and Continuous Deployment
- Threat Modeling
- Software Composition Analysis (SCA)
- Static Application Security Testing (SAST)
- Infrastructure-as-Code (IaC) Scanning
- Dynamic Application Security Testing (DAST)
- Setting Up a DevSecOps Program with Open Source Tools
- Licenses Compliance, Code Coverage, and Baseline Policies
- Setting Up a Security Champions Program
- Case Studies
- Conclusion
Sehgal, Vandana Verma: - Vandana Verma Sehgal is a seasoned cybersecurity professional with over 17 years of experience. She specializes in DevSecOps and has a diverse background in vulnerability management, SOC, infrastructure, application, and cloud security. She is a speaker and trainer, having presented at events like Global OWASP AppSec, BlackHat, and Grace Hopper. Vandana actively contributes to the cybersecurity community as a member of the OWASP Global Board of Directors and Black Hat Asia Review Board and is deeply involved in diversity initiatives like InfosecGirls, WoSec, and null. She has earned numerous awards, including Cyber Security Woman of the Year 2020 and Application Security Influencer 2020 in India. Her passion for diversity and inclusion drives initiatives like InfosecGirls, WoSec, and InfosecKids, inspiring and empowering the next generation of security professionals.
• Author(s): Clear | James • Publisher: Penguin • Publisher Imprint: Penguin Random House • Subject: General Books
• Author(s): Jeff Kinney • Publisher: Penguin Random House Children's UK • Publisher Imprint: Penguin Random House Children's UK • BISAC: Comics & Graphic Novels - Humorous
• Author(s): Ichiro Kishimi • Publisher: GROVE ATLANTIC • Publisher Imprint: Allen & Unwin • BISAC: Personal Growth - SuccessIchiro Kishimi lives in Kyoto. He writes, lectures and teaches in psychiatric clinics as a certified counsellor and c...
View full details• Author(s): Chetan Bhagat • Publisher: HarperCollins Publishers India • Publisher Imprint: HarperCollins Publishers India • BISAC: GeneralFrom India's top-selling writer Chetan Bhagat comes a powerful new love story that will make you laugh, cry...
View full details• Author(s): Brianna Wiest • Publisher: Manjul Publishing • Publisher Imprint: Amaryllis • BISAC: Body Mind And SpiritThis is a book about self-sabotage. Why we do it, when we do it, and how to stop doing it—for good. Coexisting but conflicting n...
View full details• Author(s): Morgan Housel • Publisher: Pan Macmillan • Publisher Imprint: Pan Macmillan • BISAC: Finance - Wealth ManagementA third book from the International bestselling author of The Psychology of Money and Same as Ever, lessons on harnessing...
View full details• Author(s): Arundhati Roy• Publisher: PRH INDIA LOCAL PRINT• Publisher Imprint: Penguin Hamish Hamilton• BISAC: Literary FiguresArundhati Roy’s first work of memoir, this is a soaring account, both intimate and inspiring, of how the author became...
View full details• Author(s): Acharya Prashant • Publisher: HarperCollins Publishers India • Publisher Imprint: HarperCollins Publishers India • BISAC: GeneralIn a world where vagueness is mistaken for depth and obscurity passes for wisdom, Truth without Apology ...
View full details• Author(s): Sudha Murthy • Publisher: India Puffin • Publisher Imprint: India Puffin • BISAC: Short StoriesWho can resist a good story, especially when it's being told by Grandma? From her bag emerges tales of kings and cheats, monkeys and mic...
View full details• Author(s): Satoshi Yagisawa • Publisher: Bonnier Books Ltd • Publisher Imprint: Bonnier Books Ltd
• Author(s): Newport, Cal • Publisher: Little, Brown Book Group • Publisher Imprint: Piatkus
• Author(s): Shrijeet Shandilya • Publisher: Ebury Press • Publisher Imprint: Ebury Press • BISAC: Romance - GeneralIn the electric haze of college life, three friends are bound by laughter, late-night talks and unspoken promises. But when two of...
View full details• Author(s): Dan Brown • Publisher: Transworld Publishers Ltd • Publisher Imprint: Transworld Publishers Ltd • BISAC: Thrillers - EspionageDan Brown is the bestselling author of Digital Fortress, Deception Point, Angels and Demons, The Da Vinci C...
View full details• Author(s): Sudha Murty • Publisher: India Puffin • Publisher Imprint: India Puffin • BISAC: Action & Adventure - General
Rich Dad Poor Dad: What the Rich Teach Their Kids about Money That the Poor and Middle Class Do Not!
• Publisher: Penguin • Publisher Imprint: Penguin Random House • Subject: General Books • BISAC: Personal Finance - GeneralApril of 2022 marks a 25-year milestone for the personal finance classic Rich Dad Poor Dad that still ranks as the #1 Pers...
View full details• Author(s): Dale Carnegie | Napoleon Hill • Publisher: Fingerprint • Publisher Imprint: Fingerprint • Subject: General Books
• Author(s): Freida Mcfadden • Publisher: Penguin Select Print • Publisher Imprint: Penguin Select Publishing"Multi-Million Copy Bestselling Series •Now Being Made Into a Major Motion Picture Starring Sydney Sweeney and Amanda Seyfried #1 New Yor...
View full details• Author(s): Wonder House Books • Publisher: Wonder House Books • Publisher Imprint: Wonder House Books • BISAC: Comics & Graphic Novels - Fairy Tales, Folklore, Legends & MTimeless Wisdom, Talking Animals & Life Lessons for Young Min...
View full details• Author(s): Viktor E. Frankl • Publisher: Random House • Publisher Imprint: Random Hou • Subject: Medical, Nursing and Health Sciences
• Author(s): Madhavi Bharadwaj • Publisher: PRH India • Publisher Imprint: Penguin Ebury Press • BISAC: Parenting - MotherhoodWelcome to the wild, messy, wonderful world of parenting--where the nights are long, the diapers are explosive, and unso...
View full details• Author(s): Vir Das • Publisher: HarperCollins Publishers India • Publisher Imprint: HarperCollins Publishers India • BISAC: Entertainment & Performing ArtsComedian and actor Vir Das is beloved (by some, tolerated by others, blocked by a few...
View full details• Author(s): Eric Carle • Publisher: Penguin Books, Limited (UK) • Publisher Imprint: Penguin Books, Limited (UK) • BISAC: Animals - Butterflies, Moths & CaterpillarsEric Carle's The Very Hungry Caterpillar is a perennial favourite with child...
View full details• Author(s): Prajakta Koli • Publisher: Harper Fiction India • Publisher Imprint: Harper Fiction India • BISAC: Romance - ContemporaryWinner of the Amazon India Popular Choice Debut Book 2025 Award. From one of India's most-loved creators comes s...
View full details