Blog

Articoli su Product Security, SDLC sicuro, CRA compliance e le migliori pratiche per costruire prodotti digitali sicuri. Articles on Product Security, Secure SDLC, CRA compliance, and best practices for building secure digital products.

ENISA CRA Maturity Model

Il Maturity Model ENISA per il CRA: Cosa C'è Dentro e Come Usarlo Davvero

ENISA's CRA Maturity Model: What's Inside and How to Actually Use It

ENISA ha pubblicato lo SME Cyber Resilience Maturity Assessment Model con un tool Excel gratuito: 5 domini, 25 domande, scala 1–5 e checklist di azioni. Analisi practitioner: cosa fa bene, dove si ferma, come usarlo.

ENISA published the SME Cyber Resilience Maturity Assessment Model with a free Excel tool: 5 domains, 25 questions, a 1–5 scale, and an action checklist. A practitioner's analysis: what it does well, where it stops, how to use it.

Leggi l'articolo Read the article
SecDevOps CI/CD SAST DAST

SecDevOps: Automatizzare la Sicurezza nei Pipeline CI/CD

SecDevOps: Automating Security Into Your CI/CD Pipeline

Semgrep, CodeQL, Trivy, OWASP ZAP, Nuclei e Gitleaks integrati nel pipeline CI/CD: la guida tecnica pratica per automatizzare SAST, DAST e SCA con strumenti open source.

Semgrep, CodeQL, Trivy, OWASP ZAP, Nuclei, and Gitleaks integrated into CI/CD: the practical technical guide for automating SAST, DAST, and SCA with open source tools.

Leggi l'articolo Read the article
Threat Modeling STRIDE AppSec

Threat Modeling in Application Security: La Guida Tecnica dal Campo

Threat Modeling in Application Security: A Technical Guide from the Field

STRIDE, DFD, trust boundary, PASTA, TARA e come costruire un programma di threat modeling sostenibile. Una guida tecnica scritta da chi lo ha fatto sul campo per anni.

STRIDE, DFDs, trust boundaries, PASTA, TARA, and how to build a sustainable threat modeling program. A technical guide written by someone who has done it in the field for years.

Leggi l'articolo Read the article
SDLC SecDevOps

Secure Development Lifecycle (SDLC): Guida Completa

Secure Development Lifecycle (SDLC): A Complete Guide

Scopri cos'è il Secure Development Lifecycle, le fasi che lo compongono e tutti i termini chiave: Threat Modeling, Risk Analysis, SAST, DAST, SecDevOps, SBOM e molto altro.

Learn what the Secure Development Lifecycle is, its phases, and all the key terminology: Threat Modeling, Risk Analysis, SAST, DAST, SecDevOps, SBOM, and more.

Leggi l'articolo Read the article