Ref: https://www.mnemonic.no/globalassets/security-report/integrating-security-controls-within-a-devops-pipeline.pdf
Tasks | Tool | More .. | |
|
| Cics controls Mozilla risk assessment and Mirosoft threat modeling Atlassian Crucible and GitLab | Paved road Rapid risk Assessment Code reviews |
|
| SAST: Checkmarx and Semmle. Bandit (Python) and gosec (Go) | Static application static testing Dependency Analysis/software components Security Unit tests( high risk code) |
|
Security attacks
| Burp Suite Gauntlt, utilising external tools such as sslyze, nmap, and sqlmap | Dynamic application security test Penetration testing Automated security attacks |
|
| Sysdig/Falco, or Palo Alto Prisma | Run time protection Secret management Continuous security monitoring |
No comments:
Post a Comment