security-handbook

DevSecOps

DevSecOPS (Development Security Operations)

“DevSecOps is about built-in security, not security that functions as a perimeter around apps and data.

“Environment and data security

[What is DevSecOps Red Hat](https://www.redhat.com/en/topics/devops/what-is-devsecops)

The secure development machine

Developers → Process → Tools → Run time

Responsibilities

Advantages

Good Practices

Code Analysis

Interactive Application Testing (IAST)

IAST

White-box Testing

What is white-box testing

Static Application Security Testing (SAST)

SAST

Black-box Testing

What is black-box testing

Dynamic Application Security Testing (DAST)

DAST

Fuzzing

Fuzzing

Pen Testing (penetration testing)