Serverless CISO

We explore the benefits and cybersecurity of serverless computing. Serverless allows startups and large enterprises to build some amazing things by providing on-demand, event-based, and low-cost computing.

Follow publication

Overview of the OWASP Serverless Top 10

Miguel A. Calles
Serverless CISO
Published in
2 min readNov 8, 2021

This YouTube video series provides quick overviews of serverless applications' top 10 cybersecurity risks. Each video covers the risk and some recommendations on how to address it.

Why is the OWASP Serverless Top 10 important?

In this video, I discussed the reasons why the OWASP Serverless Top 10 cybersecurity risks for a serverless application are important to consider.

Injection attacks

In this video, I discussed what is the injection attack.

Broken authorization

In this video, I discussed what is broken authentication and authorization.

Sensitive data exposure

In this video, I discussed the sensitive data exposure risk.

XML external entities

In this video, I discussed the XML external entities risk.

Broken access control

In this video, I discussed the broken access control risk.

Security misconfiguration

In this video, I discussed the security misconfiguration risk.

Cross-site script attacks

In this video, I discussed cross-site scripting (XSS).

Insecure deserialization

In this video, I discussed the insecure deserialization risk.

Vulnerable components

I discussed the risk of using components with known vulnerabilities in this video.

Logging and monitoring

In this video, I discussed the insufficient logging and monitoring risk.

Before you go

These are other posts you might enjoy.

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

Serverless CISO
Serverless CISO

Published in Serverless CISO

We explore the benefits and cybersecurity of serverless computing. Serverless allows startups and large enterprises to build some amazing things by providing on-demand, event-based, and low-cost computing.

Miguel A. Calles
Miguel A. Calles

Written by Miguel A. Calles

Author of Mastering AWS Serverless · AWS Community Builder · Specializing in CMMC, SOC 2, serverless & engineering.

Write a response