Giter Site home page Giter Site logo

Be-Secure (BeS)

Developed by open source security specialists, Be-Secure is an ecosystem project for the open source security community. Among the tools included in the suite are open source security tools, sandbox environments for security assessments, as well as custom utilities written for the open source security community. Security assessment capabilities are provided by the platform through the aggregation of various open source security assessment services and utilities.

Be-Secure is an open-source project that is led by the Be-Secure Community. This community is transforming next generation Application security threat models and security assessment playbooks into global commons. Anyone can access these threat models and security assessment playbooks and participate in their development, transforming them from an enterprise asset to a global commons.

Unlike other offensive security environments which bundle in hundreds of tools all into a single environment for red teaming or blue teaming, the focus of creating the BeS environment is to make each security testing environment recyclable with minimal memory footprint and simple to execute with minimal script or parameter modification.

BeS environments will include cherry-picked open source tools that have been tried and tested, as well as playbooks for performing security assessments.

Why Be-Secure

Open source is the way forward to develop new capabilities through collaboration with open source community projects. Organizations have realized the benefits from open source software. This realization has led them to increase their adoption of open source projects to build business capabilities. This approach necessitates the focus on security for open source projects. Be-Secure projects focus on addressing common security requirements of open source projects.

Who is Be-Secure for –

Organisations, open source developers, security researchers, auditors, and regulators can all benefit from Be-Secure.

The Be-Secure Community encourages security specialists to participate in scripting of various threat models and creating security assessment playbooks while experimenting with custom tools and security testing environments.

TAVOSS

TAVOSS is Trusted And Verified Open Source software that has undergone a security assessment by the Be-Secure Community.

Be-Secure Development and Security Assessment Environments

Open source is vast and we have frequent new releases ,bug fixes and patches published every day . It is impossible for any organization to keep track of all the changes that happen across the open source landscape . Hence we have identified five Be-Secure Open source tech stacks or blue prints which we call as Be-Secure environments to help the Be-Secure community navigate through security assessment of these open source projects.

The open source projects are categorized based on purpose,interoperability and technology ,They include other open source dependencies that are most frequently required to develop enterprise grade open source solutions.

Each Be-Secure technology stack will be associated with atleast two types of BeSman environments namely the Development or Provisioning environment [Dev] as well as the security testing or security sandbox environment [Sec].

Be-Secure Open Source Technology stacks are –

  • DevOps [DO] : Be-Secure tech stacks to secure open source devops tools eg. Ansible, Puppet etc.

DO

  • Language and framework [L&F]: Be-Secure tech stacks to secure language and framework built on generic languages e.g. Ruby & Rails, PHP & Symphony, Python & Django, Javascript & Angular/Node etc.

L&F

  • Application [A] : Be-Secure tech stacks for fully function open source applications like Drupal, magneto, odoo etc.

A

DA

S

Benefits from Be-Secure –

Developers can easily learn secure development practices and are proactively guided by BeSman environments to apply those practices and automatically informed when action is needed to prevent, remediate, or mitigate security issues.

Developers, auditors, and regulators can create new BeSman Environments and easily distribute security policies that are enforced through tooling and automation, providing continuous assurance of the results.

Security assessment environments aid Developers and researchers to identify security issues ,like unintentional vulnerabilities and have this information swiftly flow - backward through the supply chain to someone who can rapidly address the issue.

Be-Secure Community members can provide information and notifications about product defects, mitigations, quality, and supportability and have this information rapidly flow forward across the ecosystem system to all users, and users can rapidly update their software or implement mitigations as appropriate.

LEARN MORE >>

OSS Project We Track :

Click here to view the list of projects we track.

OSS Project We Contribute :

BeSman Be-Secure Manager or BeSman for short is a command-line utility to provision customized environments for each TAVOSS tech stack known as Be-Secure environments.

oah-bes-vm for easy local deployment of Be-Secure environments.

BeSLighthouse BeSLighthouse is a community dashboard for TAVOSS Components that are security assessed by the Be-Secure community.

Be-Secure's Projects

egov-analytics icon egov-analytics

Analysis of the municipal data for real time alerts, predictive analytics and more...

emmy icon emmy

Library for zero-knowledge proof based applications (like anonymous credentials)

espocrm icon espocrm

EspoCRM open source CRM application

evosuite icon evosuite

EvoSuite - automated generation of JUnit test suites for Java classes

fabric icon fabric

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. Its modular and versatile design satisfies a broad range of industry use cases. It offers a unique approach to consensus that enables performance at scale while preserving privacy.

falco icon falco

Cloud Native Runtime Security

farmos-client icon farmos-client

A simplified farmOS app that works offline in both browser and native app form.

flask icon flask

The Python micro framework for building web applications.

footloose icon footloose

Container Machines - Containers that look like Virtual Machines

fosslight icon fosslight

Integrated management webservice for Open Source Compliance Process

fuzzbench icon fuzzbench

FuzzBench - Fuzzer benchmarking as a service.

fuzzing icon fuzzing

Tutorials, examples, discussions, research proposals, and other resources related to fuzzing

ghidra icon ghidra

Ghidra is a software reverse engineering (SRE) framework

gitlabhq icon gitlabhq

GitLab CE Mirror | Please open new issues in our issue tracker on GitLab.com

glue icon glue

Application Security Automation

go-ethereum icon go-ethereum

Official Go implementation of the Ethereum protocol

govready-q icon govready-q

An open source, self-service GRC tool to automate security assessments and compliance.

gpt-code-clippy icon gpt-code-clippy

Full description can be found here: https://discuss.huggingface.co/t/pretrain-gpt-neo-for-open-source-github-copilot-model/7678?u=ncoop57

gradle icon gradle

Adaptable, fast automation for all

grafana icon grafana

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.