Название: Corporate Cybersecurity: Identifying Risks and the Bug Bounty Program Автор: John Jackson Издательство: Wiley-IEEE Press Год: 2022 Страниц: 224 Язык: английский Формат: epub Размер: 36.6 MB
An insider’s guide showing companies how to spot and remedy vulnerabilities in their security programs.
A bug bounty program is offered by organizations for people to receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities. Corporate Cybersecurity gives cyber and application security engineers (who may have little or no experience with a bounty program) a hands-on guide for creating or managing an effective bug bounty program. Written by a cyber security expert, the book is filled with the information, guidelines, and tools that engineers can adopt to sharpen their skills and become knowledgeable in researching, configuring, and managing bug bounty programs.
This book addresses the technical aspect of tooling and managing a bug bounty program and discusses common issues that engineers may run into on a daily basis. The author includes information on the often-overlooked communication and follow-through approaches of effective management. Corporate Cybersecurity provides a much-needed resource on how companies identify and solve weaknesses in their security program. This important book:
Contains a much-needed guide aimed at cyber and application security engineers Presents a unique defensive guide for understanding and resolving security vulnerabilities Encourages research, configuring, and managing programs from the corporate perspective Topics covered include bug bounty overview; program set-up; vulnerability reports and disclosure; development and application Security Collaboration; understanding safe harbor and SLA
Written for professionals working in the application and cyber security arena, Corporate Cybersecurity offers a comprehensive resource for building and maintaining an effective bug bounty program.
Contents:
Foreword Part 1 Bug Bounty Overview 1 The Evolution of Bug Bounty Programs Part 2 Evaluating Programs 2 Assessing Current Vulnerability Management Processes 3 Evaluating Program Operations Part 3 Program Setup 4 Defining Program Scope and Bounties 5 Understanding Safe Harbor and Service Level Agreements 6 Program Configuration Part 4 Vulnerability Reports and Disclosure 7 Triage and Bug Management 8 Vulnerability Disclosure Information Part 5 Internal and External Communication 9 Development and Application Security Collaboration 10 Hacker and Program Interaction Essentials Part 6 Assessments and Expansions 11 Internal Assessments 12 Expanding Scope 13 Public Release Index
Скачать Corporate Cybersecurity: Identifying Risks and the Bug Bounty Program
|