Crafting Secure Software: An engineering leader’s guide to security by design

Crafting Secure Software: An engineering leader's guide to security by design

Crafting Secure Software: An engineering leader’s guide to security by design

Author: Greg Bulmash (Author), Thomas Segura (Author)

ASIN: ‎ B0DG2JY2JK

Publisher finelybook 出版社:‏ Packt Publishing‎

Edition 版本:‏ ‎ N/A

Publication Date 出版日期:‏ ‎ 2024-09-12

Language 语言: ‎ English

Print Length 页数: ‎ 156 pages

ISBN-13: ‎ 9781835885062

Book Description

Gain a solid understanding of the threat landscape and discover best practices to protect your software factory throughout the SDLC, with valuable insights from security experts at GitGuardian

Key Features

  • Develop a strong security posture by grasping key attack vectors in the SDLC
  • Implement industry-leading best practices to protect software from evolving threats
  • Utilize legislative and regulatory landscapes to mitigate compliance-related costs

Book Description

Drawing from GitGuardian’s extensive experience in securing millions of lines of code for organizations worldwide, Crafting Secure Software takes you on an exhaustive journey through the complex world of software security and prepares you to face current and emerging security challenges confidently.

Authored by security experts, this book provides unique insights into the software development lifecycle (SDLC) and delivers actionable advice to help you mitigate and prevent risks. From securing code-writing tools and secrets to ensuring the integrity of the source code and delivery pipelines, you’ll get a good grasp on the threat landscape, uncover best practices for protecting your software, and craft recommendations for future-proofing against upcoming security regulations and legislation.

By the end of this book, you’ll have gained a clear vision of the improvements needed in your security posture, along with concrete steps to implement them, empowering you to make informed decisions and take decisive action in safeguarding your software assets.

What you will learn

  • Get to grips with security trends and GitGuardian’s role in modern software
  • Analyze major security breaches and their impact on the industry
  • Develop a threat model tailored to your business and risk appetite
  • Implement security measures across your entire SDLC
  • Secure secrets within codebases, configurations, and artifacts
  • Design and maintain secure build pipelines and deployment setups
  • Navigate security compliance, including current and future laws
  • Prepare for future security with AI-generated code integration

Who this book is for

This book is an essential read for security and IT leaders navigating the complexities of modern software development. The book is also useful for chief security officers (CSOs), chief information security officers (CISOs), security architects, DevOps professionals, and IT decision makers. A basic understanding of software engineering, version control, and build and delivery mechanisms is needed. This guide will empower you to comprehend and mitigate threats in today’s dynamic software factories, regardless of your technical depth.

Table of Contents

  1. Introduction to the Security Landscape
  2. The Software Supply Chain and the SDLC
  3. Securing Your Code-Writing Tools
  4. Securing Your Secrets
  5. Securing Your Source Code
  6. Securing Your Delivery
  7. Security Compliance and Certification
  8. Best Practices to Drive Security Buy-In

Review

“Crafting Secure Software really helps you build a comprehensive checklist of security risks and best practices that you should consider when writing software. Its recommendations go beyond the code itself to ensure you are thinking about the entire pipeline that produces your application.”

C.J. May, Senior IT Security Analyst at Vermeer Corporation, Technical Content Writer at GitGuardian

A wholly remarkable book. I have known the author, Thomas Segura, professionally and personally, for three years, and it has always been a pleasure to converse and collaborate with him. Over the past decade, I’ve worked on DevOps/DevSecOps for numerous Fortune 500 companies and tech startups, and I consider myself an expert on the subject matter. Nevertheless, conversations with Thomas always spark new thoughts in me, and I always have something new to learn from him, be it security best practices or security posture in general. This book is a distillation of Thomas’s years of expertise on the whole secure software development lifecycle (SSDLC). Speaking from experience, hand on heart, not even the best teams have adopted all the best practices from this book. Yep, it’s that good —it’s north-star good, navigating you through the complexities of secure software development. If you are looking for a comprehensive guide on SSDLC, look no further: This is the definitive book.

Tiexin Guo, Open Source Developer at Canonical (Ubuntu), and CNCF ambassador

“An indispensable resource for anyone looking to implement security measures throughout the SDLC.

I loved the book’s in-depth coverage of real-world case studies, taking you from theory to actual news headlines. By dissecting these incidents, the authors provide readers with a practical understanding of how breaches occur and the severe implications of weak security practices, making it a strategic guide for anyone looking to defend against ever-evolving cyber threats. The book’s accessible language and actionable insights make it suitable for both technical and non-technical audiences, ensuring that security becomes a shared responsibility across teams. It’s a must-read for security architects, DevOps professionals, and IT leaders responsible for safeguarding software assets.”

Dwayne McDaniel, Developer Advocate at GitGuardian

About the Author

Greg Bulmash is a karaoke king who started blogging before “blog” was a word. He’s picked up both developer certifications and press accreditations, been invited as a speaker to tech conferences on three continents and led a CoderDojo chapter that put on around 150 free STEM education events for Seattle area children. At GitGuardian, he’s produced expert-oriented company blogs, externally placed articles, and cartoons for content marketing and thought leadership on cybersecurity best practices, secrets management, software supply chain security, cybersecurity legislation & regulation.

Thomas Segura is a seasoned technical writer and former DevOps engineer passionate about bridging the gap between security teams and developers. After developing microservices for smart grids at a major energy company, Thomas joined GitGuardian, a leading code security innovator, in 2021. As a technical content writer, he produces in-depth material on application and cloud security best practices. His notable works include the “State of Secrets Sprawl” report and the Secrets Management Maturity Model. Thomas’s insights have been featured on Hacker News, DevOps, and HelpNetSecurity. Through his writing, he shapes the conversation around modern software security, emphasizing collaboration between development and security teams.

相关文件下载地址

PDF, EPUB | 7 MB | 2024-12-26

打赏
未经允许不得转载:finelybook » Crafting Secure Software: An engineering leader’s guide to security by design

评论 抢沙发

觉得文章有用就打赏一下

您的打赏,我们将继续给力更多优质内容

支付宝扫一扫

微信扫一扫