Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Wilson, Glenn

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A leadership playbook for embedding security into DevOps without strangling delivery speed, aimed at engineering managers, security leads, and anyone accountable for shipping software that is both fast and safe. 【Book Arc】 - **Opening (~0%–10%)**: Sets the problem — DevOps has outpaced security, and traditional central security teams now act as bottlenecks. Introduces the case for a cultural shift rather than a tooling purchase. - **Early (~10%–32%)**: Grounds the reader in DevOps ideals (locality, flow, joy, psychological safety) and core security concepts — attack types, adversaries, and the CIA triad — while challenging the myth that DevOps practices are inherently secure. - **Middle (~39%–48%)**: Begins the three-layer framework with Layer 1: Security Education. Covers why education matters, how to time it to real needs, and the pivotal role of security champions embedded in delivery teams. - **Late (~48%–70%)**: Continues through the remaining layers — securing the delivery pipeline (infrastructure as code, container scanning, pipeline reliability) and the spectrum of security testing techniques, including what cannot be automated. - **Ending (~70%–100%)**: Lays out a practical foundation programme: increasing DevSecOps maturity, reducing technical debt, running an education programme, applying security design principles, automating security tests, and measuring progress. 【Key Takeaways】 - **Security is not an automatic byproduct of DevOps** (Early): The book's central argument is that code reviews, automated testing, and continuous delivery help but do not guarantee security. Teams must adopt an explicit security mindset or risk vulnerable software reaching customers. - **The CIA triad is the organising lens for threat understanding** (Early): Confidentiality, integrity, and availability — plus trust as an overarching concern — frame how attacks are categorised and how defences should be prioritised. - **Security champions are the scalable answer to the talent shortage** (Middle): Rather than hiring scarce security engineers, identify enthusiastic developers within teams, give them time and resources, and let them raise the security bar through peer reviews and threat modelling. - **Education must be timed to real work** (Middle): Training is forgotten quickly unless it coincides with a technical or business trigger — a new tool, a recurring vulnerability, a release cycle — making continuous education part of the delivery rhythm. - **The delivery pipeline itself is an attack surface** (Late): Securing the pipeline — infrastructure as code, container images, network configuration — matters as much as securing the application, because a compromised pipeline undermines everything downstream. - **Not all testing can be automated** (Late): Regulatory and industry constraints mean traditional penetration testing and human judgement remain necessary, even as teams push for automation-first security testing. - **Maturity is built in layers, not bought in one go** (Ending): The closing programme — reduce technical debt, educate, apply design principles, automate tests, measure and adjust — gives leaders a sequenced path rather than a big-bang transformation. - **Psychological safety underpins secure delivery** (Early): A blame culture drives problems underground; teams that can surface and fix issues without fear are more likely to catch security weaknesses early. 【Reading Tips】 - **Deep-read the early chapters on DevOps ideals and the CIA triad** if you are new to security; skim if you already work in security and jump to the three-layer framework. - **Treat the middle chapters on security education and champions as the actionable core** — these are the levers a leader can pull immediately without new headcount. - **Use the closing programme chapter as a checklist**: map each activity (technical debt reduction, design principles, test automation) against your team's current maturity and pick two or three starting points. - **Watch for the distinction between what can and cannot be automated** in testing — this is where leaders often over-promise to stakeholders. - **Read with your security and delivery leads**: the book's value is in sparking the conversation between the two groups, not in prescribing a single toolchain. 【Coverage Limits】 The excerpts cover the book's framing, the three-layer framework, security education, and the closing programme, but do not provide detailed chapter-level content on pipeline security tooling or specific testing techniques. Some middle and late sections are represented only by chapter headings and brief fragments.
Page 11
o, the third layer discusses the different security testing techniques which can be deployed as part of your DevSecOps practice. Automating the deployment an...
View in text
Excerpt 2
over a period of time, or a denial of service (DoS) attack. There are many attack scenarios, each with a specific goal. You may not always be the intended ta...
View in text
Excerpt 3
tices, although they help. In reality, security needs to be addressed explicitly by DevOps teams to ensure that the applications and services they produce ar...
View in text
Excerpt 4
tanding how to tackle certain types of vulnerabilities. For example, a dashboard could indicate the number of vulnerabilities identified and fixed by each en...
View in text
Excerpt 5
solution is to ensure code changes being reviewed are small. As Giray Özil pointed out (and repeated in The DevOps Handbook ), ‘Ask a programmer to review te...
View in text
Excerpt 6
e tends to zero, the greater the risk to your organisation. Knowledge is not lost exclusively through members leaving the team; it can also diminish over tim...
View in text
Excerpt 7
o help organisations improve the security of their software. It runs a number of community-led projects categorised by maturity, including maintaining top-te...
View in text
Excerpt 8
entication and authorisation provide a mechanism to protect resources, accountability offers reassurance that the actions of principals can be traced and tha...
View in text
Tags
AI categories
DevOpsCybersecuritySoftware
Publisher: Rethink Press
Publish Year: 2020
Language: English
Pages: 171
File Format: PDF
File Size: 3.1 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…