Главная
Study mode:
on
1
Intro
2
Core Team
3
Development Trends (Cisco)
4
Security Testing is Hard
5
Deployment Models
6
Architecture: General
7
AWS Demo Network
8
Norad Terminology
9
Architecture: Public Scan
10
Architecture: Relay
11
Relay Connectivity Requirements
12
Enterprise (Dev-Box too)
13
Security Tests: Overview
14
Security Tests: Creation
15
Security Tests: Dockerfile
16
Security Tests: manifest.yml
17
Security Tests: Documentation NORAD
18
Security Tests: Readme.md
19
Security Tests: Wrapper Script
20
Security Tests: Unit Testing
21
Security Tests: Unit Test Targets
22
Test Content Examples
23
Security Tests: Serverspec
24
Documentation: API
25
Documentation: Relay
26
Open Source
Description:
Learn about scaling security assessment in DevOps environments through this conference talk from AppSecUSA 2016. Explore the challenges of integrating security testing into rapid development cycles and discover Norad, a distributed security testing framework. Understand how Norad automates multiple security tools, aggregates results, and provides an SDK for community-developed test content. Gain insights into the framework's design philosophy, architecture, and practical usage. Delve into topics such as testability, scalability, and accessibility of security requirements in modern software development. Follow along as speakers from Cisco demonstrate how to address security gaps in continuous deployment scenarios and empower engineers with accessible security tools and results.

Scaling Security Assessment for DevOps - Norad Framework Introduction

OWASP Foundation
Add to list