BeginnerAppSecFoundationsDevSecOps

Alice and Bob Learn Application Security

4 / 5

Tanya Janca's hands-on AppSec primer covering threat modeling, secure design, secure coding, testing, deployment, and the social side of running an AppSec program — through a friendly, narrative-driven structure.

Buy on Amazon

As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.

Published
2020
Publisher
Wiley
Pages
288
Language
English

Read this if

Software developers, junior AppSec engineers, and security champions who need a single, friendly book that covers the AppSec lifecycle without assuming security knowledge. Excellent as the first book to hand to a developer asked to lead AppSec for their team.

Skip this if

Senior AppSec professionals who already have the lifecycle internalized; the book is a primer by design. Also relatively light on cloud-native AppSec specifics (IaC scanning, supply-chain attestation), which Janca's later writing covers more deeply.

Key takeaways

  • AppSec is a lifecycle discipline, not a scanning discipline; Janca's structure makes that argument by walking through each stage with concrete examples.
  • Most AppSec wins come from secure design and developer-relations work, not from finding more bugs at the end of the SDLC.
  • The book's tone is its underrated strength — many developers will finish this book; very few will finish a more formal AppSec textbook.

Notes

Pair with Designing Secure Software (Kohnfelder) for the design-pattern depth and with The Web Application Hacker's Handbook for the offensive complement. Janca's We Hack Purple community and her ongoing Cloud Penetration Testing book are the natural follow-ups. The right answer to 'what AppSec book should we put on the engineering team's reading list?' for almost any team that doesn't already have one.