Главная
Study mode:
on
1
Intro
2
Julien Vehent
3
Vulnerabilities by type
4
Bug Bounty payouts
5
A DevOps pipeline
6
Test Driven Security
7
Define a Security baseline
8
1. Writing a Security checklist
9
Test the baseline
10
2.1 ZAP Baseline scanning
11
2.2 Static code analysis
12
2.3 Security group testing
13
2.3 Security testing
14
2.4 TLS Quality
15
Gating prod deploys
16
Does it work?
Description:
Explore Test Driven Security in the DevOps pipeline through this 42-minute conference talk from AppSecUSA 2017. Learn how to implement a baseline of security controls and test them continuously within the deployment process. Discover the benefits of writing security tests first, including clarified expectations, specific and testable controls, high reusability, and real-time detection of security regressions. Gain insights into practical examples such as implementing Content Security Policy, CSRF token requirements, and SSH root login restrictions. Understand how this approach, similar to Test Driven Development, can help catch vulnerabilities early and improve overall security posture. Follow along as the speaker, Julien Vehent, Firefox Operations Security Lead at Mozilla, shares his expertise in web application security and services architecture.

Test Driven Security in the DevOps Pipeline

OWASP Foundation
Add to list