/secdevops

SevDevOps tools and resources

Creative Commons Zero v1.0 UniversalCC0-1.0

Contributing

Send a pull request :)

SevDevOps tools & resources

Culture & Training

Presentations

Conferences

Design & Development

SDLC

Secure coding practices

Agile threat modelling

Secure architecture

Build

  • Automated static analysis (unsafe functions and more)
  • Supply chain vulnerability management (controlling and monitoring your upstream dependencies)

Testing

  • Automated security testing (file access/permissions, port scans, web testing through proxy, fuzzing etc)

Operations

  • Automated use of encryption
  • Automated centralised collection of logs and metrics
  • Automated management of security policies (e.g. firewalls, HIDS)
  • Continuous patching
  • Automated identity and access management