Victoria Almazova joins David Blank-Edelman to explore the tools for DevSecOps in a CI/CD Pipeline on Azure.
Resources
• WAF Security pillar aka.ms/azenabl...
• Azure Well-Architected Review aka.ms/azenabl...
• Secure DevOps aka.ms/azenabl...
• DevSecOps in Azure aka.ms/azenabl...
• Secure DevOps Kit for Azure aka.ms/azenabl...
• Secure Azure pipelines aka.ms/azenabl...
Related Episodes
• DevSecOps: bringing security into your DevOps practice on Azure • DevSecOps: bringing se...
• Improve app security with Application Security Groups • Improve app security w...
• Better app token security through application roles • Better app token secur...
To watch more episodes in the Well-Architected Series, check out our playlist: aka.ms/azenabl...
Explore more cloud enablement resources!
www.azure.com/...
0:00 Overview
1:09 Let's review what we've learned about DevSecOps so far.
1:55 Why are we focusing only on dependency management and security scanning?
3:17 Is there a way we could see a concrete example of implementing security practices?
5:16 Can you show me a real life example of how this implementation works in Azure DevOps?
7:46 Why do you deploy the ZAP Scanner WebApp after you built the application?
8:43 What is the next stage in the [CI/CD] pipeline, once all the scanning is done?
9:52 How will I know whether the tools find a security vulnerability, and how I get notified?
11:11 By "breaking the build," do we mean the pipeline itself stops when it discovers a vulnerability?
11:35 We've covered credentials scan results. Are there other results to mention?
#Azure #AzureEnablementShow #WellArchitected
14 авг 2024