GitGuardian:2023实战实录:企业级应用安全机密治理态势白皮书(英文版)(30页).pdf
1、Executive summary1Voice of PractitionersVoice Of PractitionersThe State of Secrets in AppSecINSIGHTS FROM 507 IT DECISION-MAKERS ON SECRETS SPRAWL AND RISK MITIGATIONToday more than ever,secrets are omnipresent along the software development cycle.They tie together the building blocks of software ap
2、plications,being the foundation of critical security mechanisms such as authentication,authorization,and encryption.In fact,digital identity and access management rely heavily on secrets.Earlier this year,GitGuardians 2023 State of Secrets Sprawl once again sounded the alarm about secrets in source
3、code:no less than 10,000,000 secrets occurrences were detected on public GitHub in 2022(+67%compared to 2021),over a total of 1.027B new commits scanned.High-profile cybersecurity incidents involving secrets have affected some of the largest tech companies in recent years,underscoring the difficulty
4、 of properly managing secrets at scale.Even as organizations become more concerned with the security of their code and the resiliency of their supply chains,adapting their security posture to the new landscape represents a significant challenge.To better understand the awareness of the problem in th
5、e field and the obstacles encountered by security leadership,this year GitGuardian partnered with Sapio Research to conduct a field study about hard-coded secrets risk awareness and mitigation strategies.Together,we analyzed the responses from 507 IT decision-makers(IT director,VP of IT,CIO,CSO,CISO
6、,VP of Cybersecurity,etc.)in the US and the UK.Here are the results.Executive summary04The Study06Deploying detection,remediation&prevention at scale17The industry is aware of the risk of leaked secretsSecrets management maturity is still unevenProtecting AppSec bandwidth requires reprioritizing0710





点击查看更多