Code Monkey home page Code Monkey logo

Be-Secure (BeS)

Developed by open source security specialists, Be-Secure is an ecosystem project for the open source security community. Among the tools included in the suite are open source security tools, sandbox environments for security assessments, as well as custom utilities written for the open source security community. Security assessment capabilities are provided by the platform through the aggregation of various open source security assessment services and utilities.

Be-Secure is an open-source project that is led by the Be-Secure Community. This community is transforming next generation Application security threat models and security assessment playbooks into global commons. Anyone can access these threat models and security assessment playbooks and participate in their development, transforming them from an enterprise asset to a global commons.

Unlike other offensive security environments which bundle in hundreds of tools all into a single environment for red teaming or blue teaming, the focus of creating the BeS environment is to make each security testing environment recyclable with minimal memory footprint and simple to execute with minimal script or parameter modification.

BeS environments will include cherry-picked open source tools that have been tried and tested, as well as playbooks for performing security assessments.

Why Be-Secure

Open source is the way forward to develop new capabilities through collaboration with open source community projects. Organizations have realized the benefits from open source software. This realization has led them to increase their adoption of open source projects to build business capabilities. This approach necessitates the focus on security for open source projects. Be-Secure projects focus on addressing common security requirements of open source projects.

Who is Be-Secure for –

Organisations, open source developers, security researchers, auditors, and regulators can all benefit from Be-Secure.

The Be-Secure Community encourages security specialists to participate in scripting of various threat models and creating security assessment playbooks while experimenting with custom tools and security testing environments.

TAVOSS

TAVOSS is Trusted And Verified Open Source software that has undergone a security assessment by the Be-Secure Community.

Be-Secure Development and Security Assessment Environments

Open source is vast and we have frequent new releases ,bug fixes and patches published every day . It is impossible for any organization to keep track of all the changes that happen across the open source landscape . Hence we have identified five Be-Secure Open source tech stacks or blue prints which we call as Be-Secure environments to help the Be-Secure community navigate through security assessment of these open source projects.

The open source projects are categorized based on purpose,interoperability and technology ,They include other open source dependencies that are most frequently required to develop enterprise grade open source solutions.

Each Be-Secure technology stack will be associated with atleast two types of BeSman environments namely the Development or Provisioning environment [Dev] as well as the security testing or security sandbox environment [Sec].

Be-Secure Open Source Technology stacks are –

  • DevOps [DO] : Be-Secure tech stacks to secure open source devops tools eg. Ansible, Puppet etc.

DO

  • Language and framework [L&F]: Be-Secure tech stacks to secure language and framework built on generic languages e.g. Ruby & Rails, PHP & Symphony, Python & Django, Javascript & Angular/Node etc.

L&F

  • Application [A] : Be-Secure tech stacks for fully function open source applications like Drupal, magneto, odoo etc.

A

DA

S

Benefits from Be-Secure –

Developers can easily learn secure development practices and are proactively guided by BeSman environments to apply those practices and automatically informed when action is needed to prevent, remediate, or mitigate security issues.

Developers, auditors, and regulators can create new BeSman Environments and easily distribute security policies that are enforced through tooling and automation, providing continuous assurance of the results.

Security assessment environments aid Developers and researchers to identify security issues ,like unintentional vulnerabilities and have this information swiftly flow - backward through the supply chain to someone who can rapidly address the issue.

Be-Secure Community members can provide information and notifications about product defects, mitigations, quality, and supportability and have this information rapidly flow forward across the ecosystem system to all users, and users can rapidly update their software or implement mitigations as appropriate.

LEARN MORE >>

OSS Project We Track :

Click here to view the list of projects we track.

OSS Project We Contribute :

BeSman Be-Secure Manager or BeSman for short is a command-line utility to provision customized environments for each TAVOSS tech stack known as Be-Secure environments.

oah-bes-vm for easy local deployment of Be-Secure environments.

BeSLighthouse BeSLighthouse is a community dashboard for TAVOSS Components that are security assessed by the Be-Secure community.

Be-Secure's Projects

indy-node icon indy-node

The server portion of a distributed ledger purpose-built for decentralized identity.

iris-web icon iris-web

Collaborative Incident Response platform

iroha icon iroha

Iroha - A simple, enterprise-grade decentralized ledger

istio icon istio

Connect, secure, control, and observe services.

itk icon itk

Insight Toolkit (ITK) -- Official Repository. ITK builds on a proven, spatially-oriented architecture for processing, segmentation, and registration of scientific images in two, three, or more dimensions.

jackhammer icon jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

jackson icon jackson

Main Portal page for the Jackson project

jackson-core icon jackson-core

Core part of Jackson that defines Streaming API as well as basic shared abstractions

jackson-databind icon jackson-databind

General data-binding package for Jackson (2.x): works on streaming API (core) implementation(s)

jdk icon jdk

JDK main-line development

joplin icon joplin

Joplin - an open source note taking and to-do application with synchronisation capabilities for Windows, macOS, Linux, Android and iOS.

k6 icon k6

A modern load testing tool, using Go and JavaScript - https://k6.io

kaa icon kaa

Kaa Internet of Things platform for device management, data collection, analytics and visualization, remote control, software updates and more

kedro icon kedro

Kedro is a toolbox for production-ready data science. It uses software engineering best practices to help you create data engineering and data science pipelines that are reproducible, maintainable, and modular.

keepassxc icon keepassxc

KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”.

kestra icon kestra

Infinitely scalable, event-driven, language-agnostic orchestration and scheduling platform to manage millions of workflows declaratively in code.

keto icon keto

Open Source (Go) implementation of "Zanzibar: Google's Consistent, Global Authorization System". Ships gRPC, REST APIs, newSQL, and an easy and granular permission language. Supports ACL, RBAC, and other access models.

kibana icon kibana

Your window into the Elastic Stack

koalas icon koalas

Koalas: pandas API on Apache Spark

koha icon koha

Koha is a free software integrated library system (ILS). Koha is distributed under the GNU GPL version 3 or later. ***Note: this is a synced mirror of the official Koha repo. Note: This project uses its own bug tracker, see https://bugs.koha-community.org/ to report a bug or submit a patch.

kotlin icon kotlin

The Kotlin Programming Language.

kratos icon kratos

Next-gen identity server (think Auth0, Okta, Firebase) with Ory-hardened authentication, MFA, FIDO2, TOTP, WebAuthn, profile management, identity schemas, social sign in, registration, account recovery, passwordless. Golang, headless, API-only - without templating or theming headaches. Available as a cloud service.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.