My Account Log in

1 option

Crafting Secure Software : An Engineering Leader's Guide to Security by Design / Greg Bulmash and Thomas Segura.

Ebook Central College Complete Available online

View online
Format:
Book
Author/Creator:
Bulmash, Greg, author.
Segura, Thomas, author.
Language:
English
Subjects (All):
Software engineering.
Computer software--Security measures.
Computer software.
Physical Description:
1 online resource (157 pages)
Edition:
First edition.
Place of Publication:
Birmingham, England : Packt Publishing Ltd., [2024]
Biography/History:
Bulmash Greg: Greg Bulmash is a karaoke king who started blogging before blog was a word. He's picked up both developer certifications and press accreditations, been invited as a speaker to tech conferences on three continents and led a CoderDojo chapter that put on around 150 free STEM education events for Seattle area children. At GitGuardian, he's produced expert-oriented company blogs, externally placed articles, and cartoons for content marketing and thought leadership on cybersecurity best practices, secrets management, software supply chain security, cybersecurity legislation & regulation. Segura Thomas: Thomas Segura is a seasoned technical writer and former DevOps engineer passionate about bridging the gap between security teams and developers. After developing microservices for smart grids at a major energy company, Thomas joined GitGuardian, a leading code security innovator, in 2021. As a technical content writer, he produces in-depth material on application and cloud security best practices. His notable works include the "State of Secrets Sprawl" report and the Secrets Management Maturity Model. Thomas's insights have been featured on Hacker News, DevOps, and HelpNetSecurity. Through his writing, he shapes the conversation around modern software security, emphasizing collaboration between development and security teams.
Summary:
Gain a solid understanding of the threat landscape and discover best practices to protect your software factory throughout the SDLC, with valuable insights from security experts at GitGuardianKey FeaturesDevelop a strong security posture by grasping key attack vectors in the SDLCImplement industry-leading best practices to protect software from evolving threatsUtilize legislative and regulatory landscapes to mitigate compliance-related costsBook DescriptionDrawing from GitGuardian's extensive experience in securing millions of lines of code for organizations worldwide, Crafting Secure Software takes you on an exhaustive journey through the complex world of software security and prepares you to face current and emerging security challenges confidently. Authored by security experts, this book provides unique insights into the software development lifecycle (SDLC) and delivers actionable advice to help you mitigate and prevent risks. From securing code-writing tools and secrets to ensuring the integrity of the source code and delivery pipelines, you’ll get a good grasp on the threat landscape, uncover best practices for protecting your software, and craft recommendations for future-proofing against upcoming security regulations and legislation. By the end of this book, you’ll have gained a clear vision of the improvements needed in your security posture, along with concrete steps to implement them, empowering you to make informed decisions and take decisive action in safeguarding your software assets.What you will learnGet to grips with security trends and GitGuardian's role in modern softwareAnalyze major security breaches and their impact on the industryDevelop a threat model tailored to your business and risk appetiteImplement security measures across your entire SDLCSecure secrets within codebases, configurations, and artifactsDesign and maintain secure build pipelines and deployment setupsNavigate security compliance, including current and future lawsPrepare for future security with AI-generated code integrationWho this book is forThis book is an essential read for security and IT leaders navigating the complexities of modern software development. The book is also useful for chief security officers (CSOs), chief information security officers (CISOs), security architects, DevOps professionals, and IT decision makers. A basic understanding of software engineering, version control, and build and delivery mechanisms is needed. This guide will empower you to comprehend and mitigate threats in today's dynamic software factories, regardless of your technical depth.
Contents:
Cover
Table of Contents
Preface
Chapter 1: Introduction to the Security Landscape
The evolving application security landscape
Security awareness
Regulatory compliance and legal considerations
Who are the threat actors?
Supply chain attack case: SolarWinds
Where GitGuardian stands in the landscape
Summary
Chapter 2: The Software Supply Chain and the SDLC
What is the software supply chain?
What is the software development life cycle?
The intersection of SDLC and SSC
SDLC stages and SSC considerations
Trustworthiness in the software supply chain
Common supply chain attack vectors and defenses
Compromise of third-party components
Supply chain poisoning via updates
Insufficient security practices in development and operations
Code repository tampering
Threat modeling
Decompose the application
Determine and rank threats
Risk assessment
Integrating risk assessment to rank the threats
Threat modeling and risk assessment: How do they differ?
Real-world SSC attacks
PHP: No harm, but foul
3CX: Compromised build servers deliver malware to hundreds of thousands
Log4j: The undependable dependency
left-pad: Many introduced to supply chain attacks
Chapter 3: Securing Your Code-Writing Tools
Securing your IDE
Issues with the IDE itself
Issues with IDE plugins
Use case: Hardening Visual Studio Code
Securing your VCS and SCM
Access and rights
Integrating security tools
Securing built-in CI/CD tools
Be sure and intentional about "which" does "what
Use secrets management
Mask confidential information
Benefits and dangers of LLM-generated code
IP concerns and lack of provenance
Challenges and risks of using AI-generated code
Sensitive data leakage
Chapter 4: Securing Your Secrets
What are secrets?.
One service, multiple secrets
Secrets in code
How do secrets end up in code?
How do you detect secrets in code?
How do you remediate a leaked secret?
Common mistakes in remediating leaked secrets
Considerations in the revoke and reissue workflow
How do you prevent secrets in code?
Secrets in tools
How do secrets end up in tools?
How do you detect secrets in tools?
How do you prevent secrets in tools?
Secrets in artifacts
How do secrets end up in artifacts?
How do you detect secrets in artifacts?
How do you prevent secrets in artifacts?
The importance of identity and access management (IAM)
Machine identities
Chapter 5: Securing Your Source Code
Package managers and repositories
How are they made vulnerable?
Testing SAST, DAST, and SCA
Why testing is important
Understanding SAST
Understanding DAST
Understanding SCA
Scanning for secrets
Creating and reading an SBOM
What is an SBOM, and why you need one
SBOM formats
How to use an SBOM from a supplier
How to create an SBOM for your customers
Think like a hacker: Ethical hacking
What makes ethical hacking "ethical"?
Offering a "bug bounty"
Chapter 6: Securing Your Delivery
What are build pipelines?
Why secure CI/CD pipelines?
Where are the threats to build pipelines?
Securing build pipelines
Stage 1: Git workflow
Stage 2: Build configuration
Securing containers and artifacts
Securing build steps
The SLSA framework
Artifact signing
Leveraging Sigstore in cloud pipelines
Securing your delivery
Project Spinnaker
Securing deployments
Infrastructure as code
Identity, secrets, and access management
Managing human and machine identities.
Proactively detecting and rotating exposed secrets
Using honeytokens to detect intrusions and leaked secrets
Zero-trust networking
Chapter 7: Security Compliance and Certification
What are legislators and regulators concerned about?
Security
Data privacy
Transparency and control
What are they demanding, and how can you address it?
Protect your code and systems access
Monitor employee communications and activity
Observe best physical security practices
Encrypt everything
Disclosure, consent, and control
Transparency
Security frameworks
NIST CSF
NIST SSDF
OWASP
PCI DSS
SLSA
Proving you're taking the right steps: Certification
Proving it to customers and partners
Proving it to regulators
Chapter 8: Best Practices to Drive Security Buy-In
Best practices to create a robust security defense
Get a clear picture of the current state
Don't rely on compliance with security standards and regulations
Leverage real threats for strategic improvements
Understand and engage your stakeholders
Assess security awareness
Communicate effectively
Foster a security culture
Align security goals with business outcomes
ROI in cybersecurity
Annualized Loss Expectancy
Key takeaways
Success stories
A top US telecom provider reduced real-time secret incidents by 72%
An e-commerce company cut risk by 75% and boosted security team productivity by 50%
Appendix: Glossary of Acronyms and Abbreviations
Index
Other Books You May Enjoy.
Notes:
Description based on publisher supplied metadata and other sources.
Description based on print version record.
ISBN:
9781835885079
1835885071
OCLC:
1464607448

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account