Abstract

Functions as a Service (FaaS) is an ultimate expression of cloud computing. FaaS provides a significant business value proposition to users and offloads the security issues of the platform to the provider. The user is responsible for the security of their implementation. FaaS application implementations are typically subject to OWASP top 10 vulnerabilities and require corresponding security controls. For simple implementations this is straightforward. For large FaaS applications, strong process and operational controls combined with automation are necessary to provide reasonable assurance of application security during the development and deployment process. Without these controls, particularly in DevOps/continuous development environments, maintaining security can be problematic. The issue and control approaches are reviewed.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call