YoVDO

Are You Deploying and Operating with Security in Mind?

Offered By: Devoxx via YouTube

Tags

Devoxx Courses Risk Mitigation Courses Security Testing Courses Container Security Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the critical aspects of deploying and operating with security in mind in this 48-minute Devoxx conference talk. Delve into the current threat landscape, focusing on container technology and Java applications, and learn effective strategies to mitigate risks. Gain insights into the impact of security throughout the software creation and delivery lifecycle, understand how container technology alters security requirements, and discover important open-source tools for code scanning and dependency verification. Learn when to implement these tools and follow guidelines for secure software development. Examine topics such as container runtime security, privileges and capabilities, metadata labeling, and security testing in build pipelines. Understand the importance of addressing non-functional requirements and the concept of delaying them to the 'Last Responsible Moment'.

Syllabus

Intro
Containers: Expectations versus reality
Cybercrime is the most profitable type of crime
This is a major vulnerability
Apache struts 2 - the Equifax affair
Container technology 101
Container runtime security 101
Laying the (runtime) foundations
Privileges and Capabilities
Metadata - Adding Labels at build time
Metadata - Adding Labels at runtime
External registry with metadata support
Testing security in the build pipeline
Security Visibility: Basic (Java) Code Scanning
Dependency Scanning
Static Image Scanning
Delaying NFRs to the 'Last Responsible Moment'


Taught by

Devoxx

Related Courses

Maintaining Deployment Security in Microsoft Azure
Pluralsight
Microsoft Azure Security Engineer: Configure Advanced Security for Compute
Pluralsight
Microsoft Azure Security Technologies (AZ-500) Cert Prep: 2 Implement Platform Protection
LinkedIn Learning
Securing Containers and Kubernetes Ecosystem
LinkedIn Learning
Performing DevSecOps Automated Security Testing
Pluralsight