A collection of best practices and effective implementation recommendations that are proven to work, Secure, Resilient, and Agile Software Development leaves the boring details of software security theory out of the discussion as much as possible to concentrate on practical applied software security for practical people. Written to aid your career as well as your organization, the book shows how to gain skills in secure and resilient software development and related tasks. The book explains how to integrate these development skills into your daily duties, thereby increasing your professional value to your company, your management, your community, and your industry. Secure, Resilient, and Agile Software Development was written for the following professionals:

  • AppSec architects and program managers in information security organizations
  • Enterprise architecture teams with application development focus
  • Scrum teams
  • DevOps teams
  • Product owners and their managers
  • Project managers
  • Application security auditors

With a detailed look at Agile and Scrum software development methodologies, this book explains how security controls need to change in light of an entirely new paradigm on how software is developed. It focuses on ways to educate everyone who has a hand in any software development project with appropriate and practical skills to Build Security In. After covering foundational and fundamental principles for secure application design, this book dives into concepts, techniques, and design goals to meet well-understood acceptance criteria on features an application must implement. It also explains how the design sprint is adapted for proper consideration of security as well as defensive programming techniques. The book concludes with a look at white box application analysis and sprint-based activities to improve the security and quality of software under development.

chapter Chapter 2|12 pages

Deconstructing Agile and Scrum

chapter Chapter 3|14 pages

Learning Is FUNdamental!

chapter Chapter 4|22 pages

Product Backlog Development— Building Security In

chapter Chapter 5|16 pages

Secure Design Considerations

chapter Chapter 6|16 pages

Security in the Design Sprint

chapter Chapter 7|18 pages

Defensive Programming

chapter Chapter 8|20 pages

Testing Part 1: Static Code Analysis

chapter Chapter 10|12 pages

Securing DevOps

chapter Chapter 11|22 pages

Metrics and Models for AppSec Maturity

chapter Chapter 12|18 pages

Frontiers for AppSec

chapter Chapter 13|6 pages

AppSec Is a Marathon— Not a Sprint!