Автор: John Jackson
Издательство: Wiley-IEEE Press
Год: 2022
Страниц: 224
Язык: английский
Формат: epub
Размер: 36.6 MB
An insider’s guide showing companies how to spot and remedy vulnerabilities in their security programs.
A bug bounty program is offered by organizations for people to receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities. Corporate Cybersecurity gives cyber and application security engineers (who may have little or no experience with a bounty program) a hands-on guide for creating or managing an effective bug bounty program. Written by a cyber security expert, the book is filled with the information, guidelines, and tools that engineers can adopt to sharpen their skills and become knowledgeable in researching, configuring, and managing bug bounty programs.
This book addresses the technical aspect of tooling and managing a bug bounty program and discusses common issues that engineers may run into on a daily basis. The author includes information on the often-overlooked communication and follow-through approaches of effective management. Corporate Cybersecurity provides a much-needed resource on how companies identify and solve weaknesses in their security program. This important book:
Contains a much-needed guide aimed at cyber and application security engineers
Presents a unique defensive guide for understanding and resolving security vulnerabilities
Encourages research, configuring, and managing programs from the corporate perspective
Topics covered include bug bounty overview; program set-up; vulnerability reports and disclosure; development and application Security Collaboration; understanding safe harbor and SLA
Written for professionals working in the application and cyber security arena, Corporate Cybersecurity offers a comprehensive resource for building and maintaining an effective bug bounty program.
Contents:
Foreword
Part 1 Bug Bounty Overview
1 The Evolution of Bug Bounty Programs
Part 2 Evaluating Programs
2 Assessing Current Vulnerability Management Processes
3 Evaluating Program Operations
Part 3 Program Setup
4 Defining Program Scope and Bounties
5 Understanding Safe Harbor and Service Level Agreements
6 Program Configuration
Part 4 Vulnerability Reports and Disclosure
7 Triage and Bug Management
8 Vulnerability Disclosure Information
Part 5 Internal and External Communication
9 Development and Application Security Collaboration
10 Hacker and Program Interaction Essentials
Part 6 Assessments and Expansions
11 Internal Assessments
12 Expanding Scope
13 Public Release
Index
Скачать Corporate Cybersecurity: Identifying Risks and the Bug Bounty Program