SlideShare a Scribd company logo
Dev Workstation Build Server
Centralize Report (Vulnerability Management) Server
SCM
Static Code Analysis
(SAST)
Dynamic Testing
(DAST)
Interactive Testing
(IAST)
Open Source Component Security
Manual Penetration Testing – Out of Band
Scope: Application and Network layer – White/Black box
Defect
Management
AUTOMATION
INTEGRATION POINTS
SECURITYASSURANCEMODEL
Legend
Black Box: Development Stack
Blue Box: Automation - Integration
Red Box: Security Tools and Controls
Infrastructure Scanning

More Related Content

PDF
WhiteList Checker: An Eclipse Plugin to Improve Application Security
PPTX
5 things i wish i knew about sast (DSO-LG July 2021)
PDF
K8S Certifications - Exam Cram
PDF
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
PDF
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
PPTX
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
PPTX
Extract Oct 2019: DSO-LG Rolling Slides
PPTX
Sept 2019 - DSO-LG Tooling Examples
WhiteList Checker: An Eclipse Plugin to Improve Application Security
5 things i wish i knew about sast (DSO-LG July 2021)
K8S Certifications - Exam Cram
DSO-LG 2021 Reboot: Policy As Code (Anders Eknert)
DSO-LG March 2018: The mechanics behind how attackers exploit simple programm...
DSO-LG Oct 2019: Modern Software Delivery: Supply Chain Security Critical (Ch...
Extract Oct 2019: DSO-LG Rolling Slides
Sept 2019 - DSO-LG Tooling Examples

More from Michael Man (15)

PPTX
DevSecOps Manchester - May 2019
PDF
Chris Rutter: Avoiding The Security Brick
PPTX
Extract: DevSecOps - London Gathering (March 2019)
PDF
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
PDF
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
PDF
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
PDF
August 2018: DevSecOps - London Gathering
PPTX
DevSecOps - London Gathering : June 2018
PDF
Continuous Security: From tins to containers - now what!
PDF
The mechanics behind how attackers exploit simple programming mistakes ...
PDF
Secret Management Journey - Here Be Dragons aka Secret Dragons
PDF
DevSecOps The Evolution of DevOps
PDF
Dynaminet -DevSecOps
PPTX
DevSecOps: Test Automation
PPTX
Project management experience security in agile 1309
DevSecOps Manchester - May 2019
Chris Rutter: Avoiding The Security Brick
Extract: DevSecOps - London Gathering (March 2019)
Control Plane: Security Rationale for Istio (DevSecOps - London Gathering, Ja...
Matt Turner: Istio, The Packet's-Eye View (DevSecOps - London Gathering, Janu...
Control Plane: Continuous Kubernetes Security (DevSecOps - London Gathering, ...
August 2018: DevSecOps - London Gathering
DevSecOps - London Gathering : June 2018
Continuous Security: From tins to containers - now what!
The mechanics behind how attackers exploit simple programming mistakes ...
Secret Management Journey - Here Be Dragons aka Secret Dragons
DevSecOps The Evolution of DevOps
Dynaminet -DevSecOps
DevSecOps: Test Automation
Project management experience security in agile 1309
Ad

Recently uploaded (20)

PPTX
Tartificialntelligence_presentation.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
A comparative analysis of optical character recognition models for extracting...
PPTX
A Presentation on Touch Screen Technology
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
1 - Historical Antecedents, Social Consideration.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
August Patch Tuesday
PPTX
Chapter 5: Probability Theory and Statistics
PPTX
cloud_computing_Infrastucture_as_cloud_p
PPTX
1. Introduction to Computer Programming.pptx
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Hindi spoken digit analysis for native and non-native speakers
Tartificialntelligence_presentation.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia
A comparative analysis of optical character recognition models for extracting...
A Presentation on Touch Screen Technology
A comparative study of natural language inference in Swahili using monolingua...
Assigned Numbers - 2025 - Bluetooth® Document
Enhancing emotion recognition model for a student engagement use case through...
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Heart disease approach using modified random forest and particle swarm optimi...
OMC Textile Division Presentation 2021.pptx
1 - Historical Antecedents, Social Consideration.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
August Patch Tuesday
Chapter 5: Probability Theory and Statistics
cloud_computing_Infrastucture_as_cloud_p
1. Introduction to Computer Programming.pptx
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Group 1 Presentation -Planning and Decision Making .pptx
TLE Review Electricity (Electricity).pptx
Hindi spoken digit analysis for native and non-native speakers
Ad

DevSecOps March 2018 - Extract

  • 1. Dev Workstation Build Server Centralize Report (Vulnerability Management) Server SCM Static Code Analysis (SAST) Dynamic Testing (DAST) Interactive Testing (IAST) Open Source Component Security Manual Penetration Testing – Out of Band Scope: Application and Network layer – White/Black box Defect Management AUTOMATION INTEGRATION POINTS SECURITYASSURANCEMODEL Legend Black Box: Development Stack Blue Box: Automation - Integration Red Box: Security Tools and Controls Infrastructure Scanning