Key IT Laws in Sri Lanka 1. Electronic Transactions Act, No. 19 of 2006 (Amended 2017) Legalizes electronic contracts, digital signatures, and electronic documents, giving them the same legal status as paper-based documents. The 2017 amendment expands the scope to include biometric authentication and strengthens provisions for cross-border e‑commerce facilitation. 2. Computer Crimes Act, No. 24 of 2007 Criminalizes offenses such as unauthorized access to systems, data interception, and the disclosure of passwords. This law forms the backbone of cybercrime enforcement in Sri Lanka. 3. Intellectual Property Act, No. 36 of 2003 Protects creative and technological works, including software, trade secrets, and integrated circuits. It ensures protection through copyright, trademarks, and patents—essential for safeguarding digital innovation. 4. Payment and Settlement Systems Act, No. 28 of 2005 Empowers the Central Bank to regulate electronic payment systems and ensure the sa...
This comment has been removed by the author.
ReplyDeleteSAFECode, “Practical security stories and security tasks for agile development
ReplyDeleteenvironments,” SAFECode, Tech. Rep., July 2012. [Online]. Available: http://safecode.org/
wp-content/uploads/2018/01/SAFECode Agile Dev Security0712.pdf
SAFECode, “Fundamental practices for secure software development: Essential elements
ReplyDeleteof a secure development lifecycle program,” SAFECode, Tech. Rep. Third Edition, March
2018. [Online]. Available: https://safecode.org/wp-content/uploads/2018/03/SAFECode
Fundamental Practices for Secure Software Development March 2018.pdf
WhiteSource identifies every open source component in your software, including dependencies. It then secures you from vulnerabilities and enforces license policies throughout the software development lifecycle. The result? Faster, smoother development without compromising on security.
ReplyDeleteCredential Scanner (aka CredScan) is a tool developed and maintained by Microsoft to identify credential leaks such as those in source code and configuration files. Some of the commonly found types of credentials are default passwords, SQL connection strings and Certificates with private keys.
ReplyDeletesome games - 7https://www.usenix.org/conference/3gse14/summit-program/presentation/shostack
ReplyDelete8https://securitycards.cs.washington.edu/ Protection Poker [30]
Security Quality Requirements Engineering (SQUARE)
ReplyDeletehttps://insights.sei.cmu.edu/library/security-quality-requirements-engineering-square/
Cloud Computing Law
ReplyDeleteSecond Edition
Edited by
CHRISTOPHER MILLARD
AWS
ReplyDeleteAll-in-One
Security Guide
Design, Build, Monitor, and Manage a
Fortified Application Ecosystem on AWS
https://portswigger.net/web-security
ReplyDeleteFree, online web security training from the creators of Burp Suite
ReplyDeletehttps://www.handsonsecurity.net/resources.html
ReplyDeletehttps://trainingportal.linuxfoundation.org/learn/course/developing-secure-software-lfd121
ReplyDeletehttps://portswigger.net/burp/communitydownload
ReplyDeleteISO 27001 Controls
ReplyDeleteA guide to implementing and auditing
This comment has been removed by the author.
ReplyDeleteBook - Grokking Web Application Security
ReplyDeletehttps://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Defendable-Architectures.pdf and https://www.lockheedmartin.com/
ReplyDelete(1) AWS Graviton Memory Encryption
ReplyDelete(2) AWS Nitro instance Memory Encryption
https://nse.digital/
ReplyDeletehttps://www.nirsoft.net/system_tools.html various tools to study the system, recover passwords, etc
ReplyDeleteA Cuckoo Sandbox is an open-source tool that can be used to automatically analyze malware. Imagine, it’s 2 am in the Security Operations Center (SOC) and an alert has triggered…
ReplyDeletehttps://www.varonis.com/blog/cuckoo-sandbox
A challenge - https://www.varonis.com/frostbyte
ReplyDelete