TestAndVerification -> Static depth for infrastructure: Test of virtualized environments
Risk and Opportunity
Risk: Virtualized environments (e.g. via Container Images) might contains unsecure configurations.
Opportunity: Test virtualized environments for unsecured configurations.
Usefulness and Requirements of this Activitiy
Required knowledge: Low (one discipline)
Required time: Very Low
Required resources (systems): Low
- Dive to inspect a container images, Link, Tags:
- Cluster Scanner (will be open sourced soon) to check different aspects, , Tags:
OWASP SAMM VERSION 2