Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Michelle Ribeiro

Rating No ratings yet

Learn how to implement continuous security throughout your entire software development and delivery pipeline. With this hands-on book, developers, SREs, tech leads, and security engineers will learn how to combine their security process with their DevOps culture. You'll gain a thorough understanding of the best DevSecOps practices, from the construction of safer container images to the hardening of orchestrators to methods for securing your cloud environment. Michelle Ribeiro, CEO of SPIRITSEC, shows you how to introduce security into DevOps culture, methodologies and tools. You'll learn how to take advantage of contrasting security and DevOps cultures to build an effective DevSecOps program. You'll also explore the four Cs of the cloud-native security model: code, container, cloud, and cluster security by following coded examples. Get a review of the current threat environment to learn why security is becoming part of the DevOps movement Build an effective DevSecOps program by bridging the gap between the InfoSec and DevOps cultures Integrate security into the rapid-release cycles typical of modern software application development and delivery Secure your code, containers, clusters, and the cloud Avoid common DevSecOps mistakes by looking at case studies from Netflix, Facebook, and HSBC

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical guide to weaving continuous security into every stage of a DevOps pipeline, written for developers, SREs, tech leads, and security engineers who want to stop treating security as a gate at the end. If your team ships fast but still bolts on security late, this book shows how to make it everyone's job. 【Book Arc】 - **Opening (~0%–9%)**: Frames DevSecOps as a cultural change, not a tool, and introduces the "three faces" model — introducing security into DevOps culture, methodologies, and tools. - **Early (~9%–33%)**: Traces the evolution from waterfall to Agile/DevOps, explains why security must join the rapid-release cycle, and lays out the 4Cs (code, container, cluster, cloud) plus common misconceptions. - **Middle (~33%–52%)**: Tackles the hard human problem — bridging InfoSec and DevOps cultures — covering trust vs. zero-trust tension, value streams, blameless collaboration, and where test automation (SAST, dependency scanning, DAST) fits. - **Late (~52%+)**: Moves into hands-on securing of the 4Cs — safer container images, orchestrator hardening, and cloud environment security — with coded examples. - **Ending**: Reinforces lessons through case studies from Netflix, Facebook, and HSBC, showing common DevSecOps mistakes and how mature organizations avoid them. 【Key Takeaways】 - **DevSecOps is an evolution of DevOps, not a replacement** (Early): Without a functioning DevOps culture and maturity, DevSecOps cannot take root — the book stresses "no DevSecOps without DevOps." - **The 4Cs give you a mental model for cloud-native security** (Early): Code, container, cluster, and cloud security form four layers; on-premise teams can swap "cloud" for "computer." - **Culture is the hardest part, not tooling** (Middle): InfoSec's zero-trust instincts clash with DevOps' trust-based, blameless culture; leaders must reframe security as an enabler and distribute decision-making. - **Security must shift left into the CI/CD pipeline** (Middle): SAST, dependency scanning, and DAST automate protection at each stage, giving fast feedback so developers fix issues themselves. - **Compliance as code and application security are only pieces** (Early): Neither equals DevSecOps on its own — continuous security spans infrastructure, culture, and shared responsibility. - **Fixing vulnerabilities early is dramatically cheaper** (Early): The book argues pre-production fixes cost a fraction of post-incident response, and steady control improvement beats reactive firefighting. - **High-performing DevOps organizations lead in security integration** (Early): Puppet's DevOps Evolution Model stage-5 companies show the strongest security adoption, tying maturity to outcomes. - **Learn from real failures and successes** (Ending): Netflix, Facebook, and HSBC case studies illustrate pitfalls and practices rather than abstract theory. 【Reading Tips】 - **Deep-read Chapters 1–2** for the cultural and conceptual foundation; skim if you already live in a mature DevOps org, but don't skip the misconceptions section. - **Treat the 4Cs as your organizing spine** — map each later chapter to code, container, cluster, or cloud so the hands-on material stays coherent. - **Pause on the culture chapter** if you're from InfoSec; the trust/blameless discussion is the book's most challenging and most valuable shift. - **Follow the coded examples actively** rather than reading passively — the container and orchestrator hardening sections reward hands-on practice. - **Use the case studies as a checklist** near the end to audit your own program against known mistakes. 【Coverage Limits】 The excerpts cover the book's framing, culture, and early tooling discussions well, but the later hands-on chapters on containers, clusters, and cloud — and the detailed case studies — are only lightly represented here; specifics of those sections are not fully captured.
Excerpt 1
Inc. , 1005 Gravenstein Highway North, Sebastopol, CA 95472. O’Reilly books may be purchased for educational, business, or sales promotional use. Online edit...
View in text
Excerpt 2
nuous integration and continuous delivery (CI/CD) pipelines. Designed to help automate the steps between a developer’s submission of their code into the repo...
View in text
Excerpt 3
m a set of improvements on software engineering performance. Perhaps there is no need to label such advancements as Agile , continuous delivery , or DevOps ,...
View in text
Excerpt 4
y event happens, must also involve developers and operators. After identifying the source of the attack, together they can think about the necessary training...
View in text
Excerpt 5
shown inside a chat room. Monitoring InfoSec loves a metric. That is why some vendors used to gauge how advanced a security tool was by the number of graphic...
View in text
Excerpt 6
tomation task knows how to execute all necessary operations. Popular tools include Ansible and Terraform, and public cloud providers also have their own flav...
View in text
Excerpt 7
eats and fix vulnerabilities in a reasonable amount of time. The principle behind observability tools is to provide us with more than individual metrics, but...
View in text
Excerpt 8
find programming language violations and improve their code. Manual Security Reviews Second, asking team members to review each other’s code is probably the...
View in text
Tags
AI categories
DevOpsCybersecurityCloud Native
ISBN: 1098106938
Publish Year: 2021
Language: English
Pages: 180
File Format: EPUB
File Size: 3.6 MB