In this chapter, we turn to security topics beyond writing code but that nonetheless affect our application security: developers and their devices, third-party components, and supply chain security.
People are often the weakest link in application security. Attackers know this and therefore target organizations’ staff in preference to finding code vulnerabilities. Fortunately, there are defenses against such attacks, and we will look at those in this chapter.
All code depends in some ...