...
首页> 外文期刊>International journal of secure software engineering >Where to Integrate Security Practices on DevOps Platform
【24h】

Where to Integrate Security Practices on DevOps Platform

机译:在DevOps平台上将安全实践集成到何处

获取原文
获取原文并翻译 | 示例
           

摘要

"Software security" often evokes negative feelings amongst software developers because this term is associated with additional programming effort, uncertainty and road blocker activity on rapid development and release cycles. The Secure DevOps movement attempts to combat the toxic environment surrounding software security by shifting the paradigm from following rules and guidelines to creatively determining solutions for tough security problems (Taschner, 2015). Secure software should be focused on a proactive approach that limits the attack surface and produces reliable software. Secure DevOps developers want their software to bend but not break, which means the software absorbs attacks and continues to function. The burgeoning concepts of DevOps include a number of concepts that can be applied to increase the security of developed applications. Applying these and other DevOps principles can have a big impact on creating an environment that is resilient and secure. Specifically, this paper clearly explains how to address security concerns in the early stages of the development lifecycle and leverage that knowledge throughout the SDLC.
机译:“软件安全性”通常会引起软件开发人员的消极情绪,因为该术语与快速开发和发布周期中的额外编程工作,不确定性和路障活动有关。安全DevOps运动试图通过将范式从遵循的规则和准则转变为创造性地确定解决棘手的安全问题的解决方案,以应对围绕软件安全的有害环境(Taschner,2015年)。安全软件应集中在一种主动方法上,该方法可以限制攻击范围并产生可靠的软件。安全的DevOps开发人员希望其软件能够弯曲但不会损坏,这意味着该软件可以吸收攻击并继续运行。 DevOps的新兴概念包括许多可用于提高已开发应用程序安全性的概念。应用这些原则和其他DevOps原则可能会对创建具有弹性和安全性的环境产生重大影响。具体而言,本文清楚地说明了如何在开发生命周期的早期阶段解决安全问题,并在整个SDLC中利用这些知识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号