Security assurance program

We will discuss the security assurance program by introducing some industry practices such as SDL, OWASP SAMM, and ISO 27001. SDL lists security activities through the whole development lifecycle. OWASP SAMM explains three levels of maturity to apply security practices in four different functional roles. ISO 27001 is considered the foundation of security certification standards and gives an overview of what a security management program should be.

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.