3 Matching Annotations
  1. Last 7 days
    1. This closes a loop with Session 5, because the immutable infrastructure of the cloud-native world is what makes the pipeline trustworthy: every environment is built fresh from the same tested definition, so there is no drift between what was tested and what runs.

      Immutable infrastructure contributes to consistency and reduces configuration drift, but pipeline security also involves areas such as access control, secrets management, and protection of the build and deployment process.

    2. Definition 8.3 (Web application firewall) A web application firewall (WAF) describes a component placed in front of a web application that inspects incoming HTTP requests at the application layer and blocks those that match patterns of attack, such as SQL injection, cross-site scripting and the application-layer floods of Session 3, before they reach the application.

      This seems too absolute. A WAF can mitigate and block many SQL injection attempts, but it does not guarantee protection against all SQL injection attacks. The underlying vulnerability still needs to be fixed.

    3. The application is a layer no network control reaches

      This statement seems too absolute. Network-based security controls can operate at the application layer, with a WAF being an obvious example discussed in the same chapter. Wouldtraditional network-layer controls alone cannot address all application-layer vulnerabilities be more accurate?