서브메뉴
검색
Security As Code
Security As Code
상세정보
- 자료유형
- 전자책 국외
- 최종처리일시
- 20260202073946.0
- ISBN
- 9781098127435 (electronic bk.)
- ISBN
- 9781098127466
- 서명/저자
- Security As Code
- 판사항
- 1st ed.
- 형태사항
- 1 online resource (122 pages)
- 내용주기
- 완전내용Cover -- Copyright -- Table of Contents -- Preface -- Who Is This Book For? -- What Do You Need To Get Started? -- What's in This Book? -- Conventions Used in This Book -- Using Code Examples -- O'Reilly Online Learning -- How to Contact Us -- Acknowledgments -- Chapter 1. Introduction to DevSecOps -- Before DevOps: The Software Development Life Cycle -- What Is DevSecOps? -- Introducing Automatoonz -- Cloud Infrastructure: Secure by Default -- Move Fast, Secure Fast: The Importance of Automation -- DevSecOps Culture -- Summary -- Chapter 2. Setting Up Your Environment -- What You'll Need -- Installing and Verifying Your Setup -- Installing the AWS CLI -- Installing the Docker Engine -- Checking Your Python Version -- Installing Git -- Installing Kubernetes -- Creating Your First Bare-Bones Pipeline -- Summary -- Chapter 3. Securing Your Infrastructure -- What Makes Infrastructure Secure? -- Hands Off! Preventing Unwanted Access with IAM Permissions -- Detecting Misconfigurations -- Identifying a Standard -- Threat Modeling -- Security Controls -- Better Than a Cure: Implementing Preventive Controls -- Implementation -- Summary -- Chapter 4. Logging and Monitoring -- What Are Logging and Monitoring-and Why Do They Matter? -- Attack Styles -- Advanced Persistent Threat Attacks -- Ransomware Strains -- Passive and Active Attacks -- Log Types -- Log Storage -- Detecting Anomalies -- Remediation with AWS Config -- Correlating User Activity with CloudTrail -- Network Monitoring with an Amazon VPC -- Summary -- Chapter 5. Controlling Access Through Automation -- The Principle of Least Privilege -- Fine-Tuning Access Controls -- Use a Tagging System -- Clarify Team Responsibilities -- Prevent and Detect -- The IAM Pipeline -- Summary -- Chapter 6. Fault Injection Test -- Distributed Systems -- Adaptive Security Controls -- The True Cost of Downtime.
- 내용주기
- 완전내용Methods for Minimizing Downtime -- Chaos Engineering -- Basic Principles -- Advanced Principles -- Chaos Engineering in AWS Environments -- Chaos Engineering at Automatoonz -- AWS Fault Injection Simulator Experiment Examples -- Kubernetes Pod Stress Testing -- Throttling EC2 API Calls -- Stress Testing the CPU on an EC2 Instance -- Terminating an EC2 Instance -- Removing Ingress and Egress Rules from a Security Group -- Detaching an EBS Volume from an EC2 Instance -- Summary -- Chapter 7. People and Processes -- People: Team Structures and Roles -- Security Engineers -- Developers -- Compliance Team -- Product Manager -- Team Structure -- Processes: Practices and Communication -- Communicate to the Right People, Consistently -- Make Product Owners Accountable for Their Security Findings -- Build Threat Modeling into Your Processes -- Build Roadmaps to Reach Your DevSecOps Goals -- What Next? -- Summary -- Index -- About the Authors -- Colophon.
- 기타저자
- Chu, Virginia.
- 기타형태저록
- Print version / Das, B. K. SarthakSecurity As Code. Sebastopol : O'Reilly Media, Incorporated,c2023. 9781098127466
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008260202s2023 xx o 0 eng d■001EBC30308630
■003MiAaPQ
■00520260202073946.0
■006m o d |
■007cr cnu||||||||
■020 ▼a9781098127435▼q(electronic bk.)
■020 ▼z9781098127466
■035 ▼a(MiAaPQ)EBC30308630
■035 ▼a(Au-PeEL)EBL30308630
■035 ▼a(OCoLC)1369651406
■040 ▼aMiAaPQ▼beng▼erda▼epn▼cMiAaPQ▼dMiAaPQ
■1001 ▼aDas, B. K. Sarthak.
■24510▼aSecurity As Code
■250 ▼a1st ed.
■264 1▼aSebastopol▼bO'Reilly Media, Incorporated▼c2023.
■264 4▼c?023.
■300 ▼a1 online resource (122 pages)
■336 ▼atext▼btxt▼2rdacontent
■337 ▼acomputer▼bc▼2rdamedia
■338 ▼aonline resource▼bcr▼2rdacarrier
■5050 ▼aCover -- Copyright -- Table of Contents -- Preface -- Who Is This Book For? -- What Do You Need To Get Started? -- What's in This Book? -- Conventions Used in This Book -- Using Code Examples -- O'Reilly Online Learning -- How to Contact Us -- Acknowledgments -- Chapter 1. Introduction to DevSecOps -- Before DevOps: The Software Development Life Cycle -- What Is DevSecOps? -- Introducing Automatoonz -- Cloud Infrastructure: Secure by Default -- Move Fast, Secure Fast: The Importance of Automation -- DevSecOps Culture -- Summary -- Chapter 2. Setting Up Your Environment -- What You'll Need -- Installing and Verifying Your Setup -- Installing the AWS CLI -- Installing the Docker Engine -- Checking Your Python Version -- Installing Git -- Installing Kubernetes -- Creating Your First Bare-Bones Pipeline -- Summary -- Chapter 3. Securing Your Infrastructure -- What Makes Infrastructure Secure? -- Hands Off! Preventing Unwanted Access with IAM Permissions -- Detecting Misconfigurations -- Identifying a Standard -- Threat Modeling -- Security Controls -- Better Than a Cure: Implementing Preventive Controls -- Implementation -- Summary -- Chapter 4. Logging and Monitoring -- What Are Logging and Monitoring-and Why Do They Matter? -- Attack Styles -- Advanced Persistent Threat Attacks -- Ransomware Strains -- Passive and Active Attacks -- Log Types -- Log Storage -- Detecting Anomalies -- Remediation with AWS Config -- Correlating User Activity with CloudTrail -- Network Monitoring with an Amazon VPC -- Summary -- Chapter 5. Controlling Access Through Automation -- The Principle of Least Privilege -- Fine-Tuning Access Controls -- Use a Tagging System -- Clarify Team Responsibilities -- Prevent and Detect -- The IAM Pipeline -- Summary -- Chapter 6. Fault Injection Test -- Distributed Systems -- Adaptive Security Controls -- The True Cost of Downtime.
■5058 ▼aMethods for Minimizing Downtime -- Chaos Engineering -- Basic Principles -- Advanced Principles -- Chaos Engineering in AWS Environments -- Chaos Engineering at Automatoonz -- AWS Fault Injection Simulator Experiment Examples -- Kubernetes Pod Stress Testing -- Throttling EC2 API Calls -- Stress Testing the CPU on an EC2 Instance -- Terminating an EC2 Instance -- Removing Ingress and Egress Rules from a Security Group -- Detaching an EBS Volume from an EC2 Instance -- Summary -- Chapter 7. People and Processes -- People: Team Structures and Roles -- Security Engineers -- Developers -- Compliance Team -- Product Manager -- Team Structure -- Processes: Practices and Communication -- Communicate to the Right People, Consistently -- Make Product Owners Accountable for Their Security Findings -- Build Threat Modeling into Your Processes -- Build Roadmaps to Reach Your DevSecOps Goals -- What Next? -- Summary -- Index -- About the Authors -- Colophon.
■588 ▼aDescription based on publisher supplied metadata and other sources.
■590 ▼aElectronic reproduction. Ann Arbor, Michigan : ProQuest Ebook Central, 2026. Available via World Wide Web. Access may be limited to ProQuest Ebook Central affiliated libraries.
■655 4▼aElectronic books.
■7001 ▼aChu, Virginia.
■77608▼iPrint version▼aDas, B. K. Sarthak▼tSecurity As Code▼dSebastopol : O'Reilly Media, Incorporated,c2023▼z9781098127466
■7972 ▼aProQuest (Firm)
■85640▼uhttps://ebookcentral.proquest.com/lib/baekseok-ebooks/detail.action?docID=30308630▼zClick to View


