1 Answer

0 votes
by

AppSec Pipeline

An AppSec pipeline applies the principle of DevOps and lean into the application security program.

The ultimate aim of an AppSec pipeline is to deliver a consistent process from the application security team and the constituency which typically involves the developers, QA, product managers, and senior stakeholders.

An AppSec pipeline is designed for iterative improvement and can organically grow in functionality over time.

Each activity has well-defined states throughout the process flow.

The pipeline extensively depends on automation for repeatable tasks.

AppSec Pipelines

Pipelines comprises of four distinct areas.

The first is the intake process or first impression.

  • Here the customers requests AppSec services such as static, dynamic, or manual assessments from the AppSec team.

  • The intake process comprises of an application repository that a requester will either choose from a listing of applications or provide the details manually.

The second part is triage

  • An analysis is done to apply the requested services.

  • For example, an application request may include an automated scan. In such a case a request would be made to conduct a security scan.

  • AppSec Pipeline - Intake and Triage
    AppSec Pipeline - Intake and Triage

    The image above illustrates the components of the intake and triage phase.

  • AppSec Pipeline - Testing Phase

    AppSec Pipeline - Testing Phase
    AppSec Pipelines
    AppSec Pipelines

    The last part of the pipeline deliver.

    Here the results are distributed to the customer.

    • In this phase most pipelines integrate with the defect tracker and will produce summary matrices and reports for senior management

Related questions

0 votes
    An AppSec pipeline applies the principle of _________ into the application security program. 1.DevOps and Agile 2.Rugged DevOps 3.DevOps 4.DevOps and Lean...
asked Oct 28, 2020 in Technology by JackTerrance
0 votes
    In the AppSec pipeline, the first phase, intake process, is also known as ___________. 1. In point 2. In tunnel 3. Request phase 4. First impression...
asked Oct 28, 2020 in Technology by JackTerrance
0 votes
    How many distinct areas does the AppSec pipeline comprise? 1. Two 2. Four 3. Three 4. Depends on the application...
asked Oct 28, 2020 in Technology by JackTerrance
0 votes
    How to achieve Integrating DevOps in the AppSec Pipeline?...
asked Oct 27, 2020 in Technology by JackTerrance
0 votes
    What is OWASP AppSec Pipeline?...
asked Oct 27, 2020 in Technology by JackTerrance
0 votes
    Each operation in a demand-driven pipeline can be implemented as an ____ that provides the following ... Database Interview Questions and Answers for Freshers and Experience...
asked Oct 11, 2021 in Education by JackTerrance
0 votes
    How to define a pipeline to not run between its start and end time? (1)isPaused: false (2)isPaused: true (3)is paused: true (4)is paused: false...
asked Sep 1, 2021 in Technology by JackTerrance
0 votes
    What is a Jenkins Pipeline?...
asked Jul 16, 2021 in Technology by JackTerrance
0 votes
    During which stage of the continuous delivery pipeline should features be verified in production before the business need them?...
asked Nov 28, 2020 in Technology by JackTerrance
0 votes
    The “system always runs” is a component of which Continuous Delivery Pipeline aspect?...
asked Nov 27, 2020 in Technology by JackTerrance
0 votes
    Which of the following can be used to ensure the security of the CI/CD pipeline? 1. Authentication to push ... storage of build artifacts 4. Login tracking 5. Key management...
asked Oct 28, 2020 in Technology by JackTerrance
0 votes
    Which of the tools is not mandated for integration in a CI pipeline ? (i)Terraform (ii)Chef (iii)Maven (iv)Selenium...
asked Oct 5, 2020 in Technology by Editorial Staff
0 votes
    Does CI pipeline need to have all the software development functionalities integrated in place ? (1)False (2)True...
asked Oct 5, 2020 in Technology by Editorial Staff
0 votes
    Does CI pipeline need to have all the software development functionalities integrated in place ? (1)False (2)True...
asked Oct 5, 2020 in Technology by Editorial Staff
0 votes
    CI pipeline consists of ______________. (i)Items (ii)Stages (iii)Artifacts (iv)Commitments (v)Tickets...
asked Oct 5, 2020 in Technology by Editorial Staff
...