Digital Library

Learning DevSecOps (Michelle Ribeiro)(Z-Library)

Share E-Book

Learning DevSecOps (Michelle Ribeiro)(Z-Library)

Author

Rating No ratings yet

Log in to rate

DevOps
Language English

Learn how to implement continuous security throughout your entire software development and delivery pipeline. With this hands-on book, developers, SREs, tech leads, and security engineers will learn how to combine their security process with their DevOps culture. You'll gain a thorough understanding of the best DevSecOps practices, from the construction of safer container images to the hardening of orchestrators to methods for securing your cloud environment. Michelle Ribeiro, CEO of SPIRITSEC, shows you how to introduce security into DevOps culture, methodologies and tools. You'll learn how to take advantage of contrasting security and DevOps cultures to build an effective DevSecOps program. You'll also explore the four Cs of the cloud-native security model: code, container, cloud, and cluster security by following coded examples. Get a review of the current threat environment to learn why security is becoming part of the DevOps movement Build an effective DevSecOps program by bridging the gap between the InfoSec and DevOps cultures Integrate security into the rapid-release cycles typical of modern software application development and delivery Secure your code, containers, clusters, and the cloud Avoid common DevSecOps mistakes by looking at case studies from Netflix, Facebook, and HSBC

Format EPUB
Size 3.6 MB
316
Views

AI Guide

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

Full assistant
AI guide
【One-Line Pitch】 A practical guide to weaving continuous security into every stage of a DevOps pipeline, written for developers, SREs, tech leads, and security engineers who want to stop treating security as a gate at the end. If your team ships fast but still bolts on security late, this book shows how to make it everyone's job. 【Book Arc】 - **Opening (~0%–9%)**: Frames DevSecOps as a cultural change, not a tool, and introduces the "three faces" model — introducing security into DevOps culture, methodologies, and tools. - **Early (~9%–33%)**: Traces the evolution from waterfall to Agile/DevOps, explains why security must join the rapid-release cycle, and lays out the 4Cs (code, container, cluster, cloud) plus common misconceptions. - **Middle (~33%–52%)**: Tackles the hard human problem — bridging InfoSec and DevOps cultures — covering trust vs. zero-trust tension, value streams, blameless collaboration, and where test automation (SAST, dependency scanning, DAST) fits. - **Late (~52%+)**: Moves into hands-on securing of the 4Cs — safer container images, orchestrator hardening, and cloud environment security — with coded examples. - **Ending**: Reinforces lessons through case studies from Netflix, Facebook, and HSBC, showing common DevSecOps mistakes and how mature organizations avoid them. 【Key Takeaways】 - **DevSecOps is an evolution of DevOps, not a replacement** (Early): Without a functioning DevOps culture and maturity, DevSecOps cannot take root — the book stresses "no DevSecOps without DevOps." - **The 4Cs give you a mental model for cloud-native security** (Early): Code, container, cluster, and cloud security form four layers; on-premise teams can swap "cloud" for "computer." - **Culture is the hardest part, not tooling** (Middle): InfoSec's zero-trust instincts clash with DevOps' trust-based, blameless culture; leaders must reframe security as an enabler and distribute decision-making. - **Security must shift left into the CI/CD pipeline** (Middle): SAST, dependency scanning, and DAST automate protection at each stage, giving fast feedback so developers fix issues themselves. - **Compliance as code and application security are only pieces** (Early): Neither equals DevSecOps on its own — continuous security spans infrastructure, culture, and shared responsibility. - **Fixing vulnerabilities early is dramatically cheaper** (Early): The book argues pre-production fixes cost a fraction of post-incident response, and steady control improvement beats reactive firefighting. - **High-performing DevOps organizations lead in security integration** (Early): Puppet's DevOps Evolution Model stage-5 companies show the strongest security adoption, tying maturity to outcomes. - **Learn from real failures and successes** (Ending): Netflix, Facebook, and HSBC case studies illustrate pitfalls and practices rather than abstract theory. 【Reading Tips】 - **Deep-read Chapters 1–2** for the cultural and conceptual foundation; skim if you already live in a mature DevOps org, but don't skip the misconceptions section. - **Treat the 4Cs as your organizing spine** — map each later chapter to code, container, cluster, or cloud so the hands-on material stays coherent. - **Pause on the culture chapter** if you're from InfoSec; the trust/blameless discussion is the book's most challenging and most valuable shift. - **Follow the coded examples actively** rather than reading passively — the container and orchestrator hardening sections reward hands-on practice. - **Use the case studies as a checklist** near the end to audit your own program against known mistakes. 【Coverage Limits】 The excerpts cover the book's framing, culture, and early tooling discussions well, but the later hands-on chapters on containers, clusters, and cloud — and the detailed case studies — are only lightly represented here; specifics of those sections are not fully captured.

Passage locations

Excerpt 1
Inc. , 1005 Gravenstein Highway North, Sebastopol, CA 95472. O’Reilly books may be purchased for educational, business, or sales promotional use. Online edit...
View in text
Excerpt 2
nuous integration and continuous delivery (CI/CD) pipelines. Designed to help automate the steps between a developer’s submission of their code into the repo...
View in text
Excerpt 3
m a set of improvements on software engineering performance. Perhaps there is no need to label such advancements as Agile , continuous delivery , or DevOps ,...
View in text
Excerpt 4
y event happens, must also involve developers and operators. After identifying the source of the attack, together they can think about the necessary training...
View in text

Recommended for You

Loading recommended books...
Failed to load, please try again later

Tip the Site

Scan the WeChat Pay or Alipay code to tip. No login required.

WeChat Pay
Alipay
← Back to List