Stage 4 – self-build security services

In this stage, the company not only has its own security testing and monitoring team but also develops and tailors its own security services such as a web application firewall (WAF) and intrusion detection. Furthermore, the company may even contribute some security tools or services to the open source community. The security assurance program covers not only the company itself but also the partners or the ecosystem.

Take Salesforce as an example—the Salesforce Developer Center portal provides security training modules, coding, implementation guidelines, tools such as assessment tools, code scanning, testing or CAPTCHA modules, and also a developer forum. Whether you are building an application on top ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.