Data input/output

Each project team implements the data input validation differently. Some project teams may miss filtering certain illegal characters, some may not know how to encode the output correctly, and some may neglect to do path or URL canonicalization before validation. These data input/output handling issues could cause some security problems. Therefore, the CTO wants the security team to help provide the appropriate security framework and also create hands-on tutorials for their staff members.

The security team proposes a security training kit that includes coding rules, the coding framework, scanning tools, and some case studies.

Data input/output training kit: The purpose of the training kit is to provide security best practices, ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.