YoVDO

Scaling Security Assessment for DevOps - Norad Framework Introduction

Offered By: OWASP Foundation via YouTube

Tags

DevOps Courses Software Development Courses Continuous Integration Courses Cloud Security Courses Automated testing Courses Containerization Courses Security Assessment Courses API Documentation Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Learn about scaling security assessment in DevOps environments through this conference talk from AppSecUSA 2016. Explore the challenges of integrating security testing into rapid development cycles and discover Norad, a distributed security testing framework. Understand how Norad automates multiple security tools, aggregates results, and provides an SDK for community-developed test content. Gain insights into the framework's design philosophy, architecture, and practical usage. Delve into topics such as testability, scalability, and accessibility of security requirements in modern software development. Follow along as speakers from Cisco demonstrate how to address security gaps in continuous deployment scenarios and empower engineers with accessible security tools and results.

Syllabus

Intro
Core Team
Development Trends (Cisco)
Security Testing is Hard
Deployment Models
Architecture: General
AWS Demo Network
Norad Terminology
Architecture: Public Scan
Architecture: Relay
Relay Connectivity Requirements
Enterprise (Dev-Box too)
Security Tests: Overview
Security Tests: Creation
Security Tests: Dockerfile
Security Tests: manifest.yml
Security Tests: Documentation NORAD
Security Tests: Readme.md
Security Tests: Wrapper Script
Security Tests: Unit Testing
Security Tests: Unit Test Targets
Test Content Examples
Security Tests: Serverspec
Documentation: API
Documentation: Relay
Open Source


Taught by

OWASP Foundation

Related Courses

Software as a Service
University of California, Berkeley via Coursera
Software Testing
University of Utah via Udacity
The Hardware/Software Interface
University of Washington via Coursera
Software Debugging
Saarland University via Udacity
Introduction to Systematic Program Design - Part 1
The University of British Columbia via Coursera