Development security operations best practices¶
Development Security Operations (DevSecOps) integrates security into the entire software development lifecycle (SDLC), ensuring that security is not an afterthought but a continuous process. It combines DevOps agility with proactive security measures to reduce vulnerabilities while maintaining rapid deployment cycles.
Best practices
- Systems engineering: Where the magic (and the mayhem) happens
- Notes from the security trenches: A SysEngineer’s ongoing journey
- The story sofar
- Growing list of challenges
- SSDLC methodologies
- Implementing SSDLC
- Risk assessment
- Privacy Impact Assessment (PIA)
- Threat modelling
- Secure coding
- Security-testing plan and practices
- Security automation
- Shared responsibility
- Securing virtual machines
- Securing managed database services
- Securing containers
- Securing serverless/function as a service
- Securing object storage
- Securing block storage
- Securing file storage
- Securing the container storage interface
- Securing virtual networking
- Securing VPN services
- Securing DDoS protection services
- Identity management
- From code to cloud without the exploits: A CI/CD security fairy tale
- AWS Security: Protecting Your Cloud Kingdom from Barbarians (and Dave)
- Azure Security: Defending Microsoft’s Mansion from Uninvited Guests
- GCP Security: Keeping Google’s Playground from turning into a Hackfest
- On-Prem “Cloud” Security: Playing Sysadmin on Nightmare Mode
Last update:
2025-05-12 14:39