Book description
Securing DevOps explores how the techniques of DevOps and security should be applied together to make cloud services safer. This introductory book reviews the latest practices used in securing web applications and their infrastructure and teaches you techniques to integrate security directly into your product. You'll also learn the core concepts of DevOps, such as continuous integration, continuous delivery, and infrastructure as a service.
About the Technology
An application running in the cloud can benefit from incredible efficiencies, but they come with unique security threats too. A DevOps team’s highest priority is understanding those risks and hardening the system against them.
About the Book
Securing DevOps teaches you the essential techniques to secure your cloud services. Using compelling case studies, it shows you how to build security into automated testing, continuous delivery, and other core DevOps processes. This experience-rich book is filled with mission-critical strategies to protect web applications against attacks, deter fraud attempts, and make your services safer when operating at scale. You’ll also learn to identify, assess, and secure the unique vulnerabilities posed by cloud deployments and automation tools commonly used in modern infrastructures.
What's Inside
- An approach to continuous security
- Implementing test-driven security in DevOps
- Security techniques for cloud services
- Watching for fraud and responding to incidents
- Security testing and risk assessment
About the Reader
Readers should be comfortable with Linux and standard DevOps practices like CI, CD, and unit testing.
About the Author
Julien Vehent is a security architect and DevOps advocate. He leads the Firefox Operations Security team at Mozilla, and is responsible for the security of Firefox’s high-traffic cloud services and public websites.
Quotes
Provides both sound ideas and real-world examples. A must-read.
- Adrien Saladin, PeopleDoc
Makes a complex topic completely approachable. Recommended for DevOps personnel and technology managers alike.
- Adam Montville, Center for Internet Security
Practical and ready for immediate application.
- Yan Guo, Eventbrite
An amazing resource for secure software development—a must in this day and age—whether or not you’re in DevOps.
- Andrew Bovill, Next Century
Publisher resources
Table of contents
- Securing DevOps
- Copyright
- dedication
- contents
- front matter
- 1 Securing DevOps
- Part 1. Case study: applying layers of security to a simple DevOps pipeline
- 2 Building a barebones DevOps pipeline
- 3 Security layer 1: protecting web applications
- 4 Security layer 2: protecting cloud infrastructures
- 5 Security layer 3: securing communications
- 6 Security layer 4: securing the delivery pipeline
- Part 2. Watching for anomalies and protecting services against attacks
- 7 Collecting and storing logs
- 8 Analyzing logs for fraud and attacks
- 9 Detecting intrusions
- 10 The Caribbean breach: a case study in incident response
- Part 3. Maturing DevOps security
- 11 Assessing risks
- 12 Testing security
- 13 Continuous security
- Index
- Lists
Product information
- Title: Securing DevOps
- Author(s):
- Release date: August 2018
- Publisher(s): Manning Publications
- ISBN: 9781617294136
You might also like
book
Hands-On Security in DevOps
Protect your organization's security at all levels by introducing the latest strategies for securing DevOps Key …
book
Kubernetes Security
Kubernetes has fundamentally changed the way DevOps teams create, manage, and operate container-based applications, but as …
book
Kubernetes Security and Observability
Securing, observing, and troubleshooting containerized workloads on Kubernetes can be daunting. It requires a range of …
book
Serverless Security: Understand, Assess, and Implement Secure and Reliable Applications in AWS, Microsoft Azure, and Google Cloud
Apply the basics of security in serverless computing to new or existing projects. This hands-on guide …