Application Security Posture Management: Security from the Supply Chain to Cloud Runtime
1h 57mIntermediate2024-10-16
Authors

James Berthoty
Course details
This course covers the core concepts and skills required to secure a modern, cloud-native application. Join instructor and security engineer James Berthoty as he provides a comprehensive overview of the emerging field of application security posture management (ASPM) and how it integrates a variety of different security tools used to secure applications from supply chain and other threats. Explore the fundamentals of code security, container security, runtime security, and remediating findings. Along the way, test out your new skills in the exercise challenges at the end of each section. Upon completing this course, you’ll be prepared to successfully argue for the value of different security tools in your development workflows, as well as implement a full program to operationalize those tools.
Skills covered
Supply Chain ManagementApplication SecurityCybersecurityBusiness Analysis and StrategyOne-Off
Concepts
0. Introduction
- 01 - Risks are everywhere
- 02 - What you should know
- 03 - How modern web applications are deployed
- 04 - DevOps best practices
- 05 - Security challenges in a DevOps world
- 06 - Everything you could possibly scan
- 07 - What you'll actually want to do
- 08 - Challenge - Diagram a workflow
- 09 - Solution - Diagram a workflow
1. Code Security
- 10 - Challenges with securing code
- 11 - Static application security testing (SAST)
- 12 - Software bill of materials (SBOM)
- 13 - Software composition analysis (SCA)
- 14 - Secret scanning
- 15 - Infrastructure as code scanning
- 16 - Challenge - Run your own scan
- 17 - Solution - Run your own scan
2. Container Security
- 18 - Challenges with securing supply chains
- 19 - Secure software development lifecycle (SSDLC)
- 20 - Container vulnerability scanning
- 21 - Securing DevOps runners
- 22 - Approaches to container scanning
- 23 - Challenge - Compare container base images
- 24 - Solution - Compare container base images
3. Runtime Security
- 25 - Securing applications at runtime
- 26 - Dynamic application security testing (DAST)
- 27 - Cloud security posture management (CSPM)
- 28 - Emerging runtime security - CADR and beyond
- 29 - Challenge - Tell the attack story
- 30 - Solution - Tell the attack story
4. Remediating Findings
- 31 - Getting it all done
- 32 - Operationalizing remediation programs
- 33 - What buy-in do you need
- 34 - Point solutions vs. all-in-one platforms
- 35 - Challenge - Prioritize and remediate
- 36 - Solution - Prioritize and remediate
Conclusion
- 37 - Continuing on with application security