Now that we have finished looking at security monitoring, we are going to learn about security assessment for new releases in this chapter. Cloud services may have frequent releases and updates. It's a challenge for the development, operations, and security teams to release their work within a short time frame and to finish the minimum required security testing before releases. In this chapter, we will look at the security review policies and the suggested checklist and testing tools for every release. For testing integration, the BDD security framework and other integrated security testing framework will also be introduced in this chapter.
These are the main topics that will be covered in this chapter:
- Security review policies
- Security checklist and tools
- BDD security framework
- Consolidated testing results