1 option
Crafting Secure Software : An Engineering Leader's Guide to Security by Design / Greg Bulmash and Thomas Segura.
- Format:
- Book
- Author/Creator:
- Bulmash, Greg, author.
- Segura, Thomas, author.
- Language:
- English
- Subjects (All):
- Software engineering.
- Computer software--Security measures.
- Computer software.
- Physical Description:
- 1 online resource (157 pages)
- Edition:
- First edition.
- Place of Publication:
- Birmingham, England : Packt Publishing Ltd., [2024]
- Biography/History:
- Bulmash Greg: Greg Bulmash is a karaoke king who started blogging before blog was a word. He's picked up both developer certifications and press accreditations, been invited as a speaker to tech conferences on three continents and led a CoderDojo chapter that put on around 150 free STEM education events for Seattle area children. At GitGuardian, he's produced expert-oriented company blogs, externally placed articles, and cartoons for content marketing and thought leadership on cybersecurity best practices, secrets management, software supply chain security, cybersecurity legislation & regulation. Segura Thomas: Thomas Segura is a seasoned technical writer and former DevOps engineer passionate about bridging the gap between security teams and developers. After developing microservices for smart grids at a major energy company, Thomas joined GitGuardian, a leading code security innovator, in 2021. As a technical content writer, he produces in-depth material on application and cloud security best practices. His notable works include the "State of Secrets Sprawl" report and the Secrets Management Maturity Model. Thomas's insights have been featured on Hacker News, DevOps, and HelpNetSecurity. Through his writing, he shapes the conversation around modern software security, emphasizing collaboration between development and security teams.
- Summary:
- Gain a solid understanding of the threat landscape and discover best practices to protect your software factory throughout the SDLC, with valuable insights from security experts at GitGuardianKey FeaturesDevelop a strong security posture by grasping key attack vectors in the SDLCImplement industry-leading best practices to protect software from evolving threatsUtilize legislative and regulatory landscapes to mitigate compliance-related costsBook DescriptionDrawing from GitGuardian's extensive experience in securing millions of lines of code for organizations worldwide, Crafting Secure Software takes you on an exhaustive journey through the complex world of software security and prepares you to face current and emerging security challenges confidently. Authored by security experts, this book provides unique insights into the software development lifecycle (SDLC) and delivers actionable advice to help you mitigate and prevent risks. From securing code-writing tools and secrets to ensuring the integrity of the source code and delivery pipelines, you’ll get a good grasp on the threat landscape, uncover best practices for protecting your software, and craft recommendations for future-proofing against upcoming security regulations and legislation. By the end of this book, you’ll have gained a clear vision of the improvements needed in your security posture, along with concrete steps to implement them, empowering you to make informed decisions and take decisive action in safeguarding your software assets.What you will learnGet to grips with security trends and GitGuardian's role in modern softwareAnalyze major security breaches and their impact on the industryDevelop a threat model tailored to your business and risk appetiteImplement security measures across your entire SDLCSecure secrets within codebases, configurations, and artifactsDesign and maintain secure build pipelines and deployment setupsNavigate security compliance, including current and future lawsPrepare for future security with AI-generated code integrationWho this book is forThis book is an essential read for security and IT leaders navigating the complexities of modern software development. The book is also useful for chief security officers (CSOs), chief information security officers (CISOs), security architects, DevOps professionals, and IT decision makers. A basic understanding of software engineering, version control, and build and delivery mechanisms is needed. This guide will empower you to comprehend and mitigate threats in today's dynamic software factories, regardless of your technical depth.
- Contents:
- Cover
- Table of Contents
- Preface
- Chapter 1: Introduction to the Security Landscape
- The evolving application security landscape
- Security awareness
- Regulatory compliance and legal considerations
- Who are the threat actors?
- Supply chain attack case: SolarWinds
- Where GitGuardian stands in the landscape
- Summary
- Chapter 2: The Software Supply Chain and the SDLC
- What is the software supply chain?
- What is the software development life cycle?
- The intersection of SDLC and SSC
- SDLC stages and SSC considerations
- Trustworthiness in the software supply chain
- Common supply chain attack vectors and defenses
- Compromise of third-party components
- Supply chain poisoning via updates
- Insufficient security practices in development and operations
- Code repository tampering
- Threat modeling
- Decompose the application
- Determine and rank threats
- Risk assessment
- Integrating risk assessment to rank the threats
- Threat modeling and risk assessment: How do they differ?
- Real-world SSC attacks
- PHP: No harm, but foul
- 3CX: Compromised build servers deliver malware to hundreds of thousands
- Log4j: The undependable dependency
- left-pad: Many introduced to supply chain attacks
- Chapter 3: Securing Your Code-Writing Tools
- Securing your IDE
- Issues with the IDE itself
- Issues with IDE plugins
- Use case: Hardening Visual Studio Code
- Securing your VCS and SCM
- Access and rights
- Integrating security tools
- Securing built-in CI/CD tools
- Be sure and intentional about "which" does "what
- Use secrets management
- Mask confidential information
- Benefits and dangers of LLM-generated code
- IP concerns and lack of provenance
- Challenges and risks of using AI-generated code
- Sensitive data leakage
- Chapter 4: Securing Your Secrets
- What are secrets?.
- One service, multiple secrets
- Secrets in code
- How do secrets end up in code?
- How do you detect secrets in code?
- How do you remediate a leaked secret?
- Common mistakes in remediating leaked secrets
- Considerations in the revoke and reissue workflow
- How do you prevent secrets in code?
- Secrets in tools
- How do secrets end up in tools?
- How do you detect secrets in tools?
- How do you prevent secrets in tools?
- Secrets in artifacts
- How do secrets end up in artifacts?
- How do you detect secrets in artifacts?
- How do you prevent secrets in artifacts?
- The importance of identity and access management (IAM)
- Machine identities
- Chapter 5: Securing Your Source Code
- Package managers and repositories
- How are they made vulnerable?
- Testing SAST, DAST, and SCA
- Why testing is important
- Understanding SAST
- Understanding DAST
- Understanding SCA
- Scanning for secrets
- Creating and reading an SBOM
- What is an SBOM, and why you need one
- SBOM formats
- How to use an SBOM from a supplier
- How to create an SBOM for your customers
- Think like a hacker: Ethical hacking
- What makes ethical hacking "ethical"?
- Offering a "bug bounty"
- Chapter 6: Securing Your Delivery
- What are build pipelines?
- Why secure CI/CD pipelines?
- Where are the threats to build pipelines?
- Securing build pipelines
- Stage 1: Git workflow
- Stage 2: Build configuration
- Securing containers and artifacts
- Securing build steps
- The SLSA framework
- Artifact signing
- Leveraging Sigstore in cloud pipelines
- Securing your delivery
- Project Spinnaker
- Securing deployments
- Infrastructure as code
- Identity, secrets, and access management
- Managing human and machine identities.
- Proactively detecting and rotating exposed secrets
- Using honeytokens to detect intrusions and leaked secrets
- Zero-trust networking
- Chapter 7: Security Compliance and Certification
- What are legislators and regulators concerned about?
- Security
- Data privacy
- Transparency and control
- What are they demanding, and how can you address it?
- Protect your code and systems access
- Monitor employee communications and activity
- Observe best physical security practices
- Encrypt everything
- Disclosure, consent, and control
- Transparency
- Security frameworks
- NIST CSF
- NIST SSDF
- OWASP
- PCI DSS
- SLSA
- Proving you're taking the right steps: Certification
- Proving it to customers and partners
- Proving it to regulators
- Chapter 8: Best Practices to Drive Security Buy-In
- Best practices to create a robust security defense
- Get a clear picture of the current state
- Don't rely on compliance with security standards and regulations
- Leverage real threats for strategic improvements
- Understand and engage your stakeholders
- Assess security awareness
- Communicate effectively
- Foster a security culture
- Align security goals with business outcomes
- ROI in cybersecurity
- Annualized Loss Expectancy
- Key takeaways
- Success stories
- A top US telecom provider reduced real-time secret incidents by 72%
- An e-commerce company cut risk by 75% and boosted security team productivity by 50%
- Appendix: Glossary of Acronyms and Abbreviations
- Index
- Other Books You May Enjoy.
- Notes:
- Description based on publisher supplied metadata and other sources.
- Description based on print version record.
- ISBN:
- 9781835885079
- 1835885071
- OCLC:
- 1464607448
The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.