From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 24,700 courses taught by industry experts.
Determine the roles and responsibilities of development and security teams on a software development workflow - GitHub Tutorial
From the course: GitHub Advanced Security Cert Prep by Microsoft Press
Determine the roles and responsibilities of development and security teams on a software development workflow
- [Narrator] Who's responsible for what? Speaking of themes, that's yet another one that goes through this entire training course. The importance of repository organization and GitHub Enterprise account governance. Who's responsible for what? On the development team, it's a great idea, to say the very least, to train your developers to implement secure coding practices, write unit tests, and work on resolving code scanning alerts. Hopefully, your development team is regularly collaborating with your security team on remediation and threat modeling. For their part, your security team is defining and enforcing security policies and best practices. They're doing regular human audits and penetration testing, both automated and manual. The security team's also providing guidance and support to developers. Cross training. These are core principles of DevOps.
Contents
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
(Locked)
Learning objectives40s
-
(Locked)
Use a CVE and CWE to describe a GitHub Advanced Security alert and list potential remediation3m 34s
-
(Locked)
Advanced security alert and list potential remediation1m 48s
-
(Locked)
Describe the decision-making process for closing and dismissing security alerts1m 21s
-
(Locked)
Determine the roles and responsibilities of development and security teams on a software development workflow1m 4s
-
(Locked)
Explain how to set a review cadence with security teams when appropriate1m 37s
-
(Locked)
Use security policies to instruct all contributors to better secure their repositories2m 4s
-
(Locked)
Compare the code scanning alert against the repository's security policy53s
-
(Locked)
Align repository branch protection configuration with written security policies11m 24s
-
(Locked)
-
-