Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ AppSec Bites Part 1: Balancing Speed and Thorough AppSec Coverage

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š AppSec Bites Part 1: Balancing Speed and Thorough AppSec Coverage


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: veracode.com

A joint blog post from Veracode and ThreadFix

In today???s world, speed wins. Just take Amazon for example. You can place an order with the click of a button and have it delivered to your door in under twenty-four hours. Retailers that can???t compete with Amazon???s speed are falling behind. The same level of speed and efficiency is expected with technology. Companies are in a race to deliver new and innovative technology first. But aside from speed, companies are also concerned about the security of their software. It does you no good to release new software first only to have it compromised.

So therein lies the dilemma ??๏ฝฆ How do you release software fast while still implementing a comprehensive application security (AppSec) program? One of the most widely recognized solutions is moving security practices left. What that means is that instead of implementing AppSec scans right before production, which can be time-consuming, many organizations are starting their scans during the development phase.

But not every scan type can be conducted early in the software development lifecycle. Scans like penetration tests or dynamic analysis are best performed in runtime. Does that mean you should neglect dynamic analysis or penetration tests? In part 1 of the AppSec Bites podcast series, Tim Jarrett, Director of Product Management at Veracode, argues ???no.??? Dynamic analysis and penetration tests find flaws that earlier scans ??? like static analysis ??? can???t find. So, it???s worth taking a little extra time to run those scans.

What are some ways you can save time on AppSec scans? If you have scans that can be effectively implemented early, implement them early. If you don???t currently automate your AppSec scans, automate them. And lastly, consider leveraging Veracode???s sandbox capabilities for developers. As Kyle Pippin, Director of Product Management at ThreadFix states, ???The sandbox allows developers to get hands-on with risks before they get promoted to the security team. It enables developers to fix the low-hanging fruit.???

So, the overall takeaway is that speed and security are a balancing act. You need to consider the risks involved with your application, set expectations with the developers on what flaws should be prioritized, and decide on what scan types make sense. Weigh the tradeoff of time and security for each application and follow best practices for speed to market, like shifting security left as much as possible, automating scans, and leveraging developer sandboxes.

For more information on finding the balance between speed and AppSec coverage, check out part 1 of our recent podcast series with ThreadFix.

...



๐Ÿ“Œ AppSec Bites Part 1: Balancing Speed and Thorough AppSec Coverage


๐Ÿ“ˆ 119.07 Punkte

๐Ÿ“Œ AppSec Bites Part 3: Has the New Virtual Reality Created Opportunities for AppSec?


๐Ÿ“ˆ 50.23 Punkte

๐Ÿ“Œ AppSec Bites Part 2: Top 3 Things to Consider When Maturing Your AppSec Programs


๐Ÿ“ˆ 50.23 Punkte

๐Ÿ“Œ AppSec Bites Part 4: What Do Teams Implementing DevOps Practices Need to Know?


๐Ÿ“ˆ 38.94 Punkte

๐Ÿ“Œ What's New in Lighthouse v0.9: Python 3, custom coverage formats, coverage cross-refs, themes & more


๐Ÿ“ˆ 32.91 Punkte

๐Ÿ“Œ How to Use the new Sitemap Index Coverage to Improve Your Site's Index Coverage


๐Ÿ“ˆ 32.91 Punkte

๐Ÿ“Œ How to Use the new Sitemap Index Coverage to Improve Your Site's Index Coverage


๐Ÿ“ˆ 32.91 Punkte

๐Ÿ“Œ How to Use the new Sitemap Index Coverage to Improve Your Site's Index Coverage


๐Ÿ“ˆ 32.91 Punkte

๐Ÿ“Œ Code coverage vs. test coverage in Python


๐Ÿ“ˆ 32.91 Punkte

๐Ÿ“Œ Thorough and Consistent Post-Incident Activity Strengthens Security Posture


๐Ÿ“ˆ 27.16 Punkte

๐Ÿ“Œ Verizon 2020 DBIR: More Extensive, More Detailed and More Thorough Than Ever


๐Ÿ“ˆ 27.16 Punkte

๐Ÿ“Œ A Thorough Guide to Redis Data Persistence: Mastering AOF and RDB Configuration


๐Ÿ“ˆ 27.16 Punkte

๐Ÿ“Œ Balancing Efficiency and Recall in Language Models: Introducing BASED for High-Speed, High-Fidelity Text Generation


๐Ÿ“ˆ 27.01 Punkte

๐Ÿ“Œ Congress chews up Zuckerberg, day two: A far more thorough mastication


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Unpatched iOS Vulnerability Stops VPNs From Thorough Traffic Encryption


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Complete & thorough guide on how to get started with WireGuard VPN (Linux, macOS, Windows, iOS, & Android)


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Being Thorough or Working Fast: Which Matters Most in Security? - Paul Battista - BH20 #2


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ What Is Cyber Security? A Thorough Definition | UpGuard


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ What Is Cybersecurity Risk? A Thorough Definition | UpGuard


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ CCleaner Crashes on Windows 10: 5 Thorough Ways to Fix it


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Bing's new Deep Search uses GPT-4 to get you more thorough search results


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Thorough sweep of gift computer?


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ Seeking More Thorough Information on Command Options


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ HBase Vs MongoDB โ€“ A Thorough Comparison Between NoSQL Databases


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ This Machine Learning Paper from DeepMind Presents a Thorough Examination of Asynchronous Local-SGD in Language Modeling


๐Ÿ“ˆ 25.37 Punkte

๐Ÿ“Œ 75% of AppSec practitioners see a growing cultural divide between AppSec and developers


๐Ÿ“ˆ 24.36 Punkte

๐Ÿ“Œ A virtual conference that highlights real AppSec success stories from leaders in the industry: Shift AppSec


๐Ÿ“ˆ 22.57 Punkte

๐Ÿ“Œ OWASP Appsec Tutorial Series - Episode 1: Appsec Basics


๐Ÿ“ˆ 22.57 Punkte

๐Ÿ“Œ [APPSEC-1972/APPSEC-2103] Admin password change did not force the logout of the admin user


๐Ÿ“ˆ 22.57 Punkte

๐Ÿ“Œ [APPSEC-1947/APPSEC-1945] Cross-site scripting in RMA functionality


๐Ÿ“ˆ 22.57 Punkte

๐Ÿ“Œ More UPNP woes: crashable library bites routers and software


๐Ÿ“ˆ 22.5 Punkte

๐Ÿ“Œ AsSalt-ed at the weekend: Miscreants roast Ghost and LineageOS totters as Salt bug bites


๐Ÿ“ˆ 22.5 Punkte

๐Ÿ“Œ Tokyo Game Show : And another one bites the dust


๐Ÿ“ˆ 22.5 Punkte

๐Ÿ“Œ Another One Bites the Dust: Cisco Discontinues Its $1B Cloud Initiative as AWS, Azure and Others Expand


๐Ÿ“ˆ 22.5 Punkte

๐Ÿ“Œ Another One Bites the Dust: Cisco Discontinues Its $1B Cloud Initiative as AWS, Azure and Others Expand


๐Ÿ“ˆ 22.5 Punkte











matomo