You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[DevSecOps controls - Cloud Adoption Framework | Microsoft Learn](https://learn.microsoft.com/en-ca/azure/cloud-adoption-framework/secure/devsecops-controls)
39
+
-[What Is DevSecOps? Definition and Best Practices | Microsoft Security](https://www.microsoft.com/en-us/security/business/security-101/what-is-devsecops)
-[What is DevSecOps? | IBM](https://www.ibm.com/topics/devsecops)
42
+
-[What is DevSecOps? 5 Key Components - Hyperproof](https://hyperproof.io/resource/devsecops/)
43
+
-[Guide to Secure .NET Development with OWASP Top 10](https://learn.microsoft.com/fr-ca/training/modules/owasp-top-10-for-dotnet-developers/)
44
+
-[Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security](https://github.blog/2020-08-06-achieving-devsecops-maturity-with-a-developer-first-community-driven-approach/)
45
+
-[SCA vs SAST: what are they and which one is right for you? - The GitHub Blog](https://github.blog/2022-09-09-sca-vs-sast-what-are-they-and-which-one-is-right-for-you/)[](https://github.blog/2023-03-08-application-security-orchestration-with-github-advanced-security/)
46
+
-[Application security orchestration with GitHub Advanced Security](https://github.blog/2023-03-08-application-security-orchestration-with-github-advanced-security/)[](https://www.microsoft.com/en-us/security/blog/2023/04/06/devops-threat-matrix/)
47
+
-[Get started securing your application | GitLab](https://docs.gitlab.com/ee/user/application_security/get-started-security.html)[](https://www.microsoft.com/en-us/security/blog/2023/04/06/devops-threat-matrix/)
48
+
-[DevOps threat matrix | Microsoft Security Blog](https://www.microsoft.com/en-us/security/blog/2023/04/06/devops-threat-matrix/)
49
+
-[DevOps environment posture management overview - Microsoft Defender for Cloud](https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-devops-environment-posture-management-overview)
-[Integrating Security Into the DevSecOps Toolchain (govtech.com)](https://insider.govtech.com/california/sponsored/integrating-security-into-the-devsecops-toolchain.html)
54
+
-[DevSecOps Tools: 9 Ways to Integrate Security Into the SDLC (aquasec.com)](https://www.aquasec.com/cloud-native-academy/devsecops/devsecops-tools/)
55
+
-[What is DevSecOps Automation and its 6 Benefits (practical-devsecops.com)](https://www.practical-devsecops.com/devsecops-automation/)
56
+
-[AppSec Map](https://appsecmap.com/AppSecMap)
57
+
-[BleepingComputer | Cybersecurity, Technology News and Support](https://www.bleepingcomputer.com/)
58
+
-[World’s Biggest Data Breaches & Hacks — Information is Beautiful](https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/)
-[The Complete Guide To Start A Successful DevSecOps Transformation](https://thei4group.com/the-complete-guide-to-start-a-successful-devsecops-transformation/)
67
+
-[3 phases to start a DevSecOps transformation | Opensource.com](https://opensource.com/article/21/10/first-phases-devsecops-transformation)
68
+
-[Microsoft Defender for Cloud DevOps security - the benefits and features - Microsoft Defender for Cloud | Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-devops-introduction)
-[DevSecOps Tools and Dev Sec Ops Services | Microsoft Azure](https://azure.microsoft.com/en-us/solutions/devsecops/)
71
+
-[GitHub Advanced Security for Azure DevOps (microsoft.com)](https://azure.microsoft.com/en-us/products/devops/github-advanced-security)
72
+
-[Security best practices - Azure DevOps | Microsoft Learn](https://learn.microsoft.com/en-us/azure/devops/organizations/security/security-best-practices?view=azure-devops)[](https://docs.gitlab.com/ee/user/application_security/)
-[OWASP Devsecops Maturity Model | OWASP Foundation](https://owasp.org/www-project-devsecops-maturity-model/)
75
+
-[Achieving DevSecOps Level 1 Maturity with GitHub Advanced Security](https://github.blog/2020-08-06-achieving-devsecops-maturity-with-a-developer-first-community-driven-approach/)
76
+
-[AppSec is harder than you think. Here’s how AI can help. - The GitHub Blog](https://github.blog/2024-02-06-appsec-is-harder-than-you-think-heres-how-ai-can-help/)
-[What is Shift Left Security in DevSecOps (practical-devsecops.com)](https://www.practical-devsecops.com/what-is-shift-left-security/)
79
+
-[How to “Shift-Left” SAST scans (Semgrep as an example) | by Mohamed AboElKheir | AppSec Untangled](https://medium.com/appsec-untangled/how-to-shift-left-sast-scans-semgrep-as-an-example-56f4428c31d3)
80
+
-[Behind the Scenes of DAST — How do Security Scanners Work? | by Inon Shkedy | Medium](https://inonst.medium.com/behind-the-scenes-of-dast-how-do-security-scanners-work-65572b72bddb)
81
+
-[DevSecOps and Code Vulnerabilities (cxotoday.com)](https://cxotoday.com/news-analysis/devsecops-and-code-vulnerabilities/)
82
+
-[The Fundamentals of DevSecOps in DevOps - GitHub Resources](https://resources.github.com/devops/fundamentals/devsecops/)
83
+
-[Defending CI/CD Environments - The NSA/CISA Way (substack.com)](https://resilientcyber.substack.com/p/defending-cicd-environments-the-nsacisa)
84
+
-[CISA and NSA Release Joint Guidance on Defending Continuous Integration/Continuous Delivery (CI/CD) Environments | CISA](https://www.cisa.gov/news-events/alerts/2023/06/28/cisa-and-nsa-release-joint-guidance-defending-continuous-integrationcontinuous-delivery-cicd)
0 commit comments