Shifting Log4j Discovery Right

You hear a lot about shifting your application security (AppSec) left – in other words, shifting AppSec to the beginning of the software development lifecycle (SDLC). While we firmly believe that you should continue scanning in development environments, that doesn’t mean that you should neglect applications that have been deployed to or staged in runtime environments.  Runtime presents a unique set of challenges – misconfigurations, logic errors and the like that can’t be identified in a static or third-party scan.

Read full article on Veracode

 


Date:

Categorie(s):