November 2024
Intermediate to advanced
340 pages
10h 38m
English
In this chapter we will look at the security lifecycle of data and systems, shadow IT and cybersecurity supply chain risk management before moving on to development security operations (DevSecOps) and Agile.
In the large organisations I have worked at, there has always been an issue of legacy systems or end-of-life equipment, such as Linux systems that can only handle eight-character passwords or bespoke software that has required compensating controls to continue operation. On investigation I have found that the two main causes have generally been either no record of an asset list or it being hidden from security. Recently, I had to assess a piece of software that had been developed in-house, unsupported ...
Read now
Unlock full access