<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure Coding Practices for a Cloud Application in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Secure-Coding-Practices-for-a-Cloud-Application/m-p/30775#M2017</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Was not sure if i chose the right location for this post.. so apologies in advance if i have to recategorize this post.&lt;/P&gt;&lt;P&gt;I am trying to locate resources (standards, checklists etc.) which will help accessing the security posture of a Cloud Based Application. There is OWASP and other standard resources but what if the application is not a web based application hosted on a cloud provider but a Integration based application running as PaaS. There is no front end but a lot of data manipulation. In such a scenario are we just limited to looking for PII data that is being extracted, transformed and moved around. Do we have to look at any other aspect of "Secure Coding Practices" that are being violated. If any member can share their experience, would greatly appreciate it.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;vishu&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:23:16 GMT</pubDate>
    <dc:creator>va</dc:creator>
    <dc:date>2023-10-09T09:23:16Z</dc:date>
    <item>
      <title>Secure Coding Practices for a Cloud Application</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Secure-Coding-Practices-for-a-Cloud-Application/m-p/30775#M2017</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Was not sure if i chose the right location for this post.. so apologies in advance if i have to recategorize this post.&lt;/P&gt;&lt;P&gt;I am trying to locate resources (standards, checklists etc.) which will help accessing the security posture of a Cloud Based Application. There is OWASP and other standard resources but what if the application is not a web based application hosted on a cloud provider but a Integration based application running as PaaS. There is no front end but a lot of data manipulation. In such a scenario are we just limited to looking for PII data that is being extracted, transformed and moved around. Do we have to look at any other aspect of "Secure Coding Practices" that are being violated. If any member can share their experience, would greatly appreciate it.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;vishu&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:23:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Secure-Coding-Practices-for-a-Cloud-Application/m-p/30775#M2017</guid>
      <dc:creator>va</dc:creator>
      <dc:date>2023-10-09T09:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Coding Practices for a Cloud Application</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Secure-Coding-Practices-for-a-Cloud-Application/m-p/30778#M2018</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/105133605"&gt;@va&lt;/a&gt;I had an initial cast around and found this - which may give you some thoughts and principles to apply:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ibm.com/cloud/garage/architectures/securityArchitecture/implement-secure-devops" target="_blank"&gt;https://www.ibm.com/cloud/garage/architectures/securityArchitecture/implement-secure-devops&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 01:52:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Secure-Coding-Practices-for-a-Cloud-Application/m-p/30778#M2018</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-12-19T01:52:40Z</dc:date>
    </item>
  </channel>
</rss>

