Introduction
Risks are everywhere
()
What you should know
()
How modern web applications are deployed
()
DevOps best practices
()
Security challenges in a DevOps world
()
Everything you could possibly scan
()
What you'll actually want to do
()
Challenge: Diagram a workflow
()
Solution: Diagram a workflow
()
1. Code Security
Challenges with securing code
()
Static application security testing (SAST)
()
Software bill of materials (SBOM)
()
Software composition analysis (SCA)
()
Secret scanning
()
Infrastructure as code scanning
()
Challenge: Run your own scan
()
Solution: Run your own scan
()
2. Container Security
Challenges with securing supply chains
()
Secure software development lifecycle (SSDLC)
()
Container vulnerability scanning
()
Securing DevOps runners
()
Approaches to container scanning
()
Challenge: Compare container base images
()
Solution: Compare container base images
()
3. Runtime Security
Securing applications at runtime
()
Dynamic application security testing (DAST)
()
Cloud security posture management (CSPM)
()
Emerging runtime security: CADR and beyond
()
Challenge: Tell the attack story
()
Solution: Tell the attack story
()
4. Remediating Findings
Getting it all done
()
Operationalizing remediation programs
()
What buy-in do you need?
()
Point solutions vs. all-in-one platforms
()
Challenge: Prioritize and remediate
()
Solution: Prioritize and remediate
()
Conclusion
Continuing on with application security
()