The meetup participants will discuss practical approaches to implementing regulatory requirements in DevSecOps processes, including:
- management of components and software supply chain security (SCA),
- static code analysis (SAST),
- dynamic code analysis (DAST),
- interactive code analysis (IAST),
- multifactor component identification and change control.
iIT Distribution experts will demonstrate through practical examples how to use Black Duck and SonarSource solutions to manage software security and meet regulatory requirements for code and development process protection.
A separate segment of the event will be devoted to monitoring information systems and resources and the role of a unified event collection and processing gateway in DevSecOps architecture.
It will be discussed how Cribl solution can ensure optimization, enrichment, routing, and data protection for information security, analytics, and AI use cases.
Guests from Talsec.app will explain how RASP+ (Runtime Application Self-Protection — an enhanced SDK for mobile application security) protects mobile apps.