flâneur — a map of the web's best reading

WTF is ASPM?

pulse.latio.tech · saved by 1 readers

Application Security Posture Management (ASPM) is the latest Gartner fueled buzzword to take over cybersecurity, but no one knows exactly what it is. On the one hand, it’s a fancy name for vulnerability management: helping ingest and prioritize vulnerabilities from third party tools. On the other hand, it’s a one stop shop for code scanning. In this article I argue that the only meaningful ASPM is an all in one application security scanning tool. Why would you want an ASPM? Why Disagree with Gartner? CSPM and ASPM, towards an SPM Defining The Perfect ASPM Defining the Minimum ASPM Some Examples Musings About the Future DevSecOps is the only way to ship products quickly while staying secure and compliant. If you care about protecting customer data, and the consumer trust (revenue) tied to that, you need to scan your application for misconfigurations. I have the benefit of being new to application security: I’m not used to long scan times, grumpy security buzzkills, and quarterly patch c

Application Security Posture Management (ASPM) is the latest Gartner fueled buzzword to take over cybersecurity, but no one knows exactly what it is. On the one hand, it’s a fancy name for vulnerability management: helping ingest and prioritize vulnerabilities from third party tools. On the other hand, it’s a one stop shop for code scanning. In this article I argue that the only meaningful ASPM is an all in one application security scanning tool. Why would you want an ASPM? Why Disagree with Gartner? CSPM and ASPM, towards an SPM Defining The Perfect ASPM Defining the Minimum ASPM Some Example

Explore this link on the map →