Designing & Developing Secure Azure Solutions, 1st edition

Published by Microsoft Press (November 8, 2022) © 2023

  • Michael Howard
  • Simone Curzi
  • Heinrich Gantenbein

eTextbook

$47.99

  • Available for purchase from all major ebook resellers, including InformIT.com.
  • To request a review copy, click on the "Request a Review Copy" button.
$39.99

  • A print text (hardcover or paperback) 
  • Free shipping
  • Also available for purchase as an ebook from all major ebook resellers, including InformIT.com

As more and more applications and workloads move to the Microsoft Azure cloud, safeguarding them isn't just business-critical, it's existential. To deliver Azure solutions that stand up against unprecedented threats, you must build robust security into your designs, use proven security best practices across the entire development lifecycle, and combine multiple Azure services to optimize security. In Designing & Developing Secure Azure Solutions, a team of leading Azure security experts show how to do just that. Drawing on extensive experience securing Azure workloads of all types and sizes, the authors present both a practical tutorial for addressing immediate challenges, and a definitive design reference you can rely on far into the future. You'll learn how to integrate multiple Azure security technologies at both application and network layers, to make the most of all the platform offers—from design and development to testing, deployment, governance, and compliance.

PART I SECURITY PRINCIPLES

CHAPTER 1 Secure development lifecycle processes

CHAPTER 2 Secure design

CHAPTER 3 Security patterns

CHAPTER 4 Threat modeling

CHAPTER 5 Identity, authentication, and authorization

CHAPTER 6 Monitoring and auditing

CHAPTER 7 Governance

CHAPTER 8 Compliance and risk programs

 

PART II SECURE IMPLEMENTATION

CHAPTER 9 Secure coding

CHAPTER 10 Cryptography in Azure

CHAPTER 11 Confidential computing

CHAPTER 12 Container security

CHAPTER 13 Database security

CHAPTER 14 CI/CD security

CHAPTER 15 Network security

Appendix A: Core cryptographic techniques

Michael Howard is a 30-year Microsoft veteran and is currently a Principal Security Program Manager in the Azure Data Platform team, working on security engineering. He is one of the original architects of the Microsoft Security Development Lifecycle and has helped diverse customers such as government, military, education, finance, and healthcare secure their Azure workloads. He was the application security lead for the Rio 2016 Olympic games, which were hosted on Azure.

Heinrich Gantenbein is a Senior Principal Consultant on Cybersecurity in Microsoft's Industry Solutions Delivery. With 30+ years of experience in software engineering and more than 30 years of experience in consulting, he brings a wealth of practical know-how to his role. Heinrich specializes in Azure security, threat modeling, and DevSecOps.

Simone Curzi is a Principal Consultant from Microsoft's Industry Solutions Delivery. He has 20+ years of experience covering various technical roles in Microsoft and has fully devoted himself to security for more than 10 years. A renowned threat modeling and Microsoft Security Development Lifecycle expert, Simone is a regular speaker at international conferences such as Microsoft Ready, Microsoft Spark, (ISC)2 Security Congress, Carnegie Mellon's SEI DevOps Days, and Security Compass Equilibrium. Simone is also author of an open source threat modeling tool, Threats Manager Studio.

Need help? Get in touch

Video
Play
Privacy and cookies
By watching, you agree Pearson can share your viewership data for marketing and analytics for one year, revocable by deleting your cookies.

Pearson eTextbook: What’s on the inside just might surprise you

They say you can’t judge a book by its cover. It’s the same with your students. Meet each one right where they are with an engaging, interactive, personalized learning experience that goes beyond the textbook to fit any schedule, any budget, and any lifestyle.Â