- static code analysis
- software composition analysis
- platform vulnerability scanning
- container scanning
@armillz @GlobalAppSecDC
- unit testing
- health tests
- API testing
- UI testing
@armillz @GlobalAppSecDC
- DAST
- performance testing
- 508 accessibility testing
- other compliance testing
@armillz @GlobalAppSecDC
- log aggregation
- real-time container and host monitoring
- container and host scanning
- performance monitoring
Wraps into SIEM
@armillz @GlobalAppSecDC
Get the teams to work together.
- Security consultants, not security police
- Contributors, not naysayers
@armillz @GlobalAppSecDC
@armillz @GlobalAppSecDC
Start small, possibly free.
@armillz @GlobalAppSecDC
@armillz @GlobalAppSecDC
@armillz @GlobalAppSecDC
@armillz @GlobalAppSecDC