Reader small image

You're reading from  Enterprise DevOps for Architects

Product typeBook
Published inNov 2021
Reading LevelBeginner
PublisherPackt
ISBN-139781801812153
Edition1st Edition
Languages
Concepts
Right arrow
Author (1)
Jeroen Mulder
Jeroen Mulder
author image
Jeroen Mulder

Jeroen Mulder is a certified enterprise and security architect, and he works with Fujitsu (Netherlands) as a Principal Business Consultant. Earlier, he was a Sr. Lead Architect, focusing on cloud and cloud native technology, at Fujitsu, and was later promoted to become the Head of Applications and Multi-Cloud Services. Jeroen is interested in the cloud technology, architecture for cloud infrastructure, serverless and container technology, application development, and digital transformation using various DevOps methodologies and tools. He has previously authored “Multi-Cloud Architecture and Governance”, “Enterprise DevOps for Architects”, and “Transforming Healthcare with DevOps4Care”.
Read more about Jeroen Mulder

Right arrow

Summary

In this chapter, we discussed various security frameworks. These frameworks are guidelines for setting security controls for the IT environments of the enterprise. These controls apply to systems and applications, and also to the DevOps practice. From the moment developers pull code from a repository and start the build, up until deployment and production, IT environments, including CI/CD pipelines, need to adhere to security controls. There are a lot of different frameworks. Some of them are generically and broadly accepted by enterprises, such as NIST, CIS, and COBIT.

We also discussed the MITRE ATT&CK framework, which takes a different angle by comparing itself to other security control frameworks. MITRE ATT&CK lists tactics and techniques that hackers may use or have used to exploit vulnerabilities. Just like CIS, MITRE ATT&CK lists specifics for various platforms and technologies, including containers that are commonly used in CI/CD.

In the last section...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Enterprise DevOps for Architects
Published in: Nov 2021Publisher: PacktISBN-13: 9781801812153

Author (1)

author image
Jeroen Mulder

Jeroen Mulder is a certified enterprise and security architect, and he works with Fujitsu (Netherlands) as a Principal Business Consultant. Earlier, he was a Sr. Lead Architect, focusing on cloud and cloud native technology, at Fujitsu, and was later promoted to become the Head of Applications and Multi-Cloud Services. Jeroen is interested in the cloud technology, architecture for cloud infrastructure, serverless and container technology, application development, and digital transformation using various DevOps methodologies and tools. He has previously authored “Multi-Cloud Architecture and Governance”, “Enterprise DevOps for Architects”, and “Transforming Healthcare with DevOps4Care”.
Read more about Jeroen Mulder