Since we have covered the security requirements and security assurance program in previous chapters, in this chapter, we will discuss two case studies looking at the security assurance program and security practices in the DevOps process. Microsoft SDL and SAMM were introduced to apply to the security assurance program. In addition to the process, the non-technical parts, security training, and culture are also critical to the success of the security program. We will also give an example of how security tools and web security framework can help during the whole DevOps process.
In this chapter, we will learn about the following topics:
- Microsoft SDL and SAMM
- Security training and awareness
- Security culture
- Baking security tools into DevOps
- Web security frameworks