Security study notes

What's an SDK- An SKD is a software development kit
What is an ACL- An ordered set of router rules that will permit or deny traffic based upon certain characteristics

Waterfall is big
Good for when security is needed

Agile is faster than waterfall
Agile uses sprints

Development and Operation
Speed up
Good to have a security person involved

CIA triad- confidentiality, integrity, availability

Least privilege

Defense in depth- layered security
Don't trust user input- do input validation to protect against SQL injections, buffer overflows

Input validation is what I work on now!

