← Ghi chú← Notes

DevSecOpsDevSecOps

17 ghi chú17 notes

  1. 01Giới thiệu về DevSecOpsIntroduction to DevSecOpsDevSecOps là thực hành tích hợp bảo mật (security) vào mọi giai đoạn của vòng đời phát triển phần mềm — từ lập kế hoạch, viết code, cho đến build, test, deploy và vận hành — thay vì coi bảo mật là một bước kiểm tra cuối…DevSecOps is the practice of integrating security into every stage of the software delivery lifecycle — from planning and coding through building, testing, deploying, and operating — rather than treating security as a…19 Th7, 2026Jul 19, 2026
  2. 02Nền tảng lập trình & ScriptingProgramming & Scripting FoundationsDevSecOps không phải là vai trò "đứng ngoài xem". Các security engineer chỉ biết đọc dashboard và tạo ticket sẽ bị giới hạn trong những check mà người khác đã xây sẵn. Ngay khi bạn có thể viết một script, bạn có thể tự…DevSecOps is not a spectator role. Security engineers who can only read dashboards and file tickets are limited to the checks someone else already built. The moment you can write a script, you can automate a scan across…19 Th7, 2026Jul 19, 2026
  3. 03Nền tảng Networking cho Bảo mậtNetworking Fundamentals for SecurityMọi biện pháp bảo mật cuối cùng đều nằm trên nền của network: một firewall rule, một TLS handshake, một ranh giới segmentation, một DNS query trả về IP của service của bạn hoặc IP của server kẻ tấn công. Nếu không hiểu…Every security control eventually sits on top of a network: a firewall rule, a TLS handshake, a segmentation boundary, a DNS query that either resolves to your service or to an attacker's server. If you don't understand…19 Th7, 2026Jul 19, 2026
  4. 04Nền tảng Mật mã họcCryptography FundamentalsCryptography (mật mã học) là nền tảng toán học mà hầu như mọi security control khác trong DevSecOps đều dựa vào: TLS trên đường truyền, secrets khi lưu trữ (at rest), container image được ký (signed), password storage…Cryptography is the mathematical foundation that every other security control in DevSecOps ultimately leans on: TLS on the wire, secrets at rest, signed container images, password storage, VPN tunnels, code-signing, and…19 Th7, 2026Jul 19, 2026
  5. 05Identity & Access ManagementIdentity & Access ManagementTrong bối cảnh DevSecOps, IAM không chỉ là "user đăng nhập vào website." Nó bao trùm:In a DevSecOps context, IAM is not just "user logs into a website." It spans:19 Th7, 2026Jul 19, 2026
  6. 06Threat Modeling & Đánh giá rủi roThreat Modeling & Risk AssessmentThreat modeling là hoạt động "suy nghĩ như một kẻ tấn công" trước khi kẻ tấn công thật sự làm điều đó — xác định một cách có hệ thống điều gì có thể sai (what can go wrong), mức độ nghiêm trọng của nó, và cần làm gì để…Threat modeling is the practice of thinking like an attacker before an attacker does — systematically identifying what could go wrong in a system, how bad it would be, and what to do about it. It is one of the…19 Th7, 2026Jul 19, 2026
  7. 07Secure Coding & Bảo mật ứng dụng WebSecure Coding & Web Application SecuritySecure coding là thực hành viết phần mềm chống chịu được lạm dụng nhờ thiết kế, chứ không phải nhờ may mắn. Phần lớn các vụ vi phạm (breach) không bắt đầu từ một zero-day kỳ lạ — chúng bắt đầu từ một câu query được ghép…Secure coding is the practice of writing software that resists misuse by design, not by luck. Most breaches do not start with an exotic zero-day — they start with a query built from string concatenation, a template that…19 Th7, 2026Jul 19, 2026
  8. 08Bảo mật mạng & Zero TrustNetwork Security & Zero TrustBảo mật mạng (network security) là lớp phòng thủ theo chiều sâu (defense-in-depth) kiểm soát cách traffic được phép di chuyển — giữa internet và hệ thống của bạn, giữa các zone bên trong môi trường, và giữa từng…Network security is the layer of defense-in-depth that controls how traffic is allowed to move — between the internet and your systems, between zones inside your environment, and between individual workloads. In a…19 Th7, 2026Jul 19, 2026
  9. 09Công cụ kiểm thử bảo mậtSecurity Testing ToolsCác công cụ kiểm thử bảo mật (security testing tools) giúp một đội ngũ xác minh rằng những biện pháp phòng thủ mà họ nghĩ là đã xây dựng thực sự hoạt động — thay vì giả định rằng một rule firewall, một bộ validate…Security testing tools let a team verify that the defenses they think they built actually work — instead of assuming a firewall rule, an input validator, or a patch level is correct, you probe the system the way an…19 Th7, 2026Jul 19, 2026
  10. 10Bảo mật Container & KubernetesContainer & Kubernetes SecurityContainer và Kubernetes thay đổi cách phần mềm được triển khai, nhưng đồng thời cũng thay đổi bề mặt tấn công (attack surface). Một container không phải là một VM thu nhỏ — nó là một tập hợp các process bình thường trên…Containers and Kubernetes changed how software ships, but they also changed the attack surface. A container is not a lightweight VM — it is a set of regular processes on the host, isolated by kernel features rather than…19 Th7, 2026Jul 19, 2026
  11. 11Bảo mật CloudCloud SecurityBảo mật cloud (cloud security) là tập hợp các thực hành, kiểm soát và công cụ dùng để bảo vệ dữ liệu, workload và hạ tầng chạy trên các nền tảng public cloud (AWS, Azure, GCP, v.v.). Nó khác với bảo mật on-premises…Cloud security is the set of practices, controls, and tools used to protect data, workloads, and infrastructure running on public cloud platforms (AWS, Azure, GCP, and similar). It differs from traditional on-premises…19 Th7, 2026Jul 19, 2026
  12. 12Bảo mật CI/CD & Supply ChainCI/CD & Supply Chain SecurityBảo mật CI/CD và supply chain là phần lõi vận hành của DevSecOps — nơi "shift-left" không còn là khẩu hiệu mà trở thành automation cụ thể chạy trên từng commit. Một build pipeline không chỉ là dây chuyền lắp ráp; đó là…CI/CD and supply chain security is the operational core of DevSecOps — it is where "shift-left" stops being a slogan and becomes concrete automation running on every commit. A build pipeline is not just an assembly…19 Th7, 2026Jul 19, 2026
  13. 13Monitoring & LoggingMonitoring & LoggingHệ thống nào cũng đã có monitoring và logging vì lý do vận hành — service có đang chạy không, latency có chấp nhận được không, job có chạy thành công không. Security monitoring và logging đặt ra một câu hỏi khác hẳn: có…Every system already has monitoring and logging for operational reasons — is the service up, is latency acceptable, did the job succeed. Security monitoring and logging asks a different question: is someone doing…19 Th7, 2026Jul 19, 2026
  14. 14SIEM & Tự động hóa bảo mậtSIEM & Security AutomationMonitoring & Logging đề cập đến việc từng hệ thống riêng lẻ phát ra metric, log, trace như thế nào. Điều đó cần thiết nhưng chưa đủ: một lần đăng nhập thất bại trên một máy chỉ là nhiễu; nhưng hàng trăm lần đăng nhập…Monitoring and Logging covers how individual systems emit metrics, logs, and traces. That's necessary but not sufficient: a single failed login on one host is noise; a hundred failed logins across ten hosts followed by…19 Th7, 2026Jul 19, 2026
  15. 15Incident Response & Digital ForensicsIncident Response & Digital ForensicsSớm hay muộn, mọi tổ chức đều sẽ trải qua một security incident. Với đủ thời gian, đủ attack surface, và đủ những kẻ tấn công kiên trì, các control phòng ngừa cuối cùng cũng sẽ bị vượt qua, bị cấu hình sai, hoặc đơn…Every organization eventually experiences a security incident. Given enough time, enough attack surface, and enough determined adversaries, prevention controls will eventually be bypassed, misconfigured, or simply not…19 Th7, 2026Jul 19, 2026
  16. 16Compliance, Governance & Quản lý rủi roCompliance, Governance & Risk ManagementCompliance, governance và quản lý rủi ro (thường viết tắt là GRC) là chất keo tổ chức kết nối công việc kỹ thuật security với thực tế kinh doanh, pháp lý và hợp đồng. Một đội có thể ship phần mềm được scan, ký (sign)…Compliance, governance, and risk management (often abbreviated GRC) are the organizational glue that connects security engineering work to business, legal, and contractual reality. A team can ship perfectly scanned…19 Th7, 2026Jul 19, 2026
  17. 17Bảo mật doanh nghiệp ở quy mô lớnEnterprise Security at ScaleMọi chủ đề trong bộ kiến thức này — identity, mật mã học (cryptography), secure coding, network security, bảo mật container/cloud, CI/CD, monitoring, incident response, compliance — đều mô tả một control (biện pháp kiểm…Every topic in this knowledge base — identity, cryptography, secure coding, network security, container/cloud security, CI/CD, monitoring, incident response, compliance — describes a control or a discipline. This note…19 Th7, 2026Jul 19, 2026