We will read about End-to-End Application Security. From Secure Design by Threat Modeling to Secure Deployment. Below are the topics to master.
Testing:
- SAST, 2. DAST, 3. IAST, 4. SCA, 5. MAST (Mobile), 6. IaC Scanning
API Security: 7. BOLA, 8. BFLA, 9. Mass Assignment, 10. Data Over-exposure, 11. Rate Limiting, 12. API Discovery
IAM: 13. OAuth 2.0, 14. OIDC, 15. mTLS, 16. RBAC/ABAC, 17. JWT Security, 18. Least Privilege
Runtime: 19. WAF, 20. RASP, 21. Bot Management, 22. Service Mesh Security, 23. Container Security
Data: 24. Encryption at Rest/Transit, 25. Hashing, 26. Input Validation, 27. Output Encoding
Strategy: 28. Threat Modeling, 29. Shift-Left, 30. Zero Trust Architecture