ABSTRACT

This textbook was written from the perspective of someone who began his software security career in 2005, long before the industry began focusing on it. This is an excellent perspective for students who want to learn about securing application development. After having made all the rookie mistakes, the author realized that software security is a human factors issue rather than a technical or process issue alone. Throwing technology into an environment that expects people to deal with it but failing to prepare them technically and psychologically with the knowledge and skills needed is a certain recipe for bad results.

Practical Security for Agile and DevOps is a collection of best practices and effective implementation recommendations that are proven to work. The text leaves the boring details of software security theory out of the discussion as much as possible to concentrate on practical applied software security that is useful to professionals. It is as much a book for students’ own benefit as it is for the benefit of their academic careers and organizations. Professionals who are skilled in secure and resilient software development and related tasks are in tremendous demand. This demand will increase exponentially for the foreseeable future. As students integrate the text’s best practices into their daily duties, their value increases to their companies, management, community, and industry.

The textbook was written for the following readers:

  • Students in higher education programs in business or engineering disciplines
  • AppSec architects and program managers in information security organizations
  • Enterprise architecture teams with a focus on application development
  • Scrum Teams including:
    • Scrum Masters
    • Engineers/developers
    • Analysts
    • Architects
    • Testers

  • DevOps teams
  • Product owners and their management
  • Project managers
  • Application security auditors
  • Agile coaches and trainers
  • Instructors and trainers in academia and private organizations

chapter Chapter 2|11 pages

Deconstructing Agile and Scrum

chapter Chapter 3|12 pages

Learning Is FUNdamental!

chapter Chapter 4|18 pages

Product Backlog Development— Building Security In

chapter Chapter 5|14 pages

Secure Design Considerations

chapter Chapter 6|16 pages

Security in the Design Sprint

chapter Chapter 7|16 pages

Defensive Programming

chapter Chapter 8|18 pages

Testing Part 1: Static Code Analysis

chapter Chapter 10|11 pages

Securing DevOps

chapter Chapter 11|20 pages

Metrics and Models for AppSec Maturity

chapter Chapter 12|15 pages

Frontiers for AppSec

chapter Chapter 13|6 pages

AppSec Is a Marathon—Not a Sprint!