SKU/Artículo: AMZ-B0FH5F3L3M

DevSecOps Implementation : Enterprise Guide | Build 50 Security Pipelines | Including Continuous Security.

Disponibilidad:
Fuera de stock
Peso con empaque:
0.36 kg
Devolución:
No
Condición
Nuevo
Producto de:
Amazon

Sobre este producto
  • Foundations of DevSecOps: This section introduces the core principles of DevSecOps, emphasizing the "shift-left" security philosophy, which prioritizes early vulnerability detection. It explores the differences between DevOps, SecOps, and DevSecOps, and highlights business benefits such as reduced compliance costs, enhanced customer trust, and faster delivery cycles. Chapter 2 provides a 2025 market analysis, discussing trends like cloud-native architectures, AI-driven security, and metrics like Mean Time to Restore (MTTR).
  • Designing Secure Pipelines: Focused on practical implementation, this part details the anatomy of a security pipeline, covering Source Control Management (SCM), CI/CD, and monitoring components. It introduces 50 modular, scalable security pipelines, categorized into code security, build and dependency security, Infrastructure as Code (IaC) security, runtime and monitoring security, and compliance and audit pipelines. Tools like Jenkins, GitLab, GitHub Actions, and security scanners such as Snyk, Checkov, and Falco are explored with actionable templates.
  • The 50 Security Pipelines: This section is the heart of the book, offering detailed configurations for 50 plug-and-play pipelines. These include Static Application Security Testing (SAST), Software Composition Analysis (SCA), IaC scanning, container security, and compliance checks for standards like GDPR, PCI DSS, and SOC 2. Each pipeline is designed to be adaptable across platforms like Jenkins, GitLab, and Azure DevOps, with use cases for cloud-native and regulated industries.
  • Advanced DevSecOps Practices: This part addresses scaling DevSecOps across enterprises, with strategies for multi-team coordination, governance, and centralized tooling. It includes case studies, such as a global bank’s transformation, demonstrating how to achieve daily secure releases and compliance. AI-driven pipelines, leveraging tools like AWS SageMaker and Google Vertex AI, are also covered, showcasing automation of threat detection and pipeline optimization
  • Practical Tutorials: Step-by-step guides, such as building a secure CI/CD pipeline with GitLab and tools like Semgrep and Snyk, enable hands-on learning.
  • Case Studies: Real-world examples, including a serverless e-commerce platform and a global bank’s transformation, illustrate successful DevSecOps adoption.
  • Comprehensive Toolset: The book covers a wide array of tools—SonarQube, Trivy, HashiCorp Vault, and more—with use cases for finance, healthcare, and government sectors.
  • Compliance Focus: Detailed pipelines for GDPR, PCI DSS, HIPAA, and NIST compliance, with automated audit trails and reporting.
  • Appendices and Resources: A glossary of DevSecOps terms, tool descriptions, and additional resources like conferences (KubeCon, OWASP AppSec Days) and communities (DevSecOps World Slack) provide ongoing learning support.

Producto prohibido

Este producto no está disponible

Este producto viaja de USA a tus manos en
Medios de pago Aceptamos múltiples medios de pago para tu comodidad

Compra protegida

Disfruta de una experiencia de compra segura y confiable