{"id":46,"date":"2019-10-23T13:40:17","date_gmt":"2019-10-23T13:40:17","guid":{"rendered":"https:\/\/sdf-docs.mansystems.com\/docs\/ams\/"},"modified":"2023-10-25T10:43:33","modified_gmt":"2023-10-25T10:43:33","slug":"ams","status":"publish","type":"docs","link":"https:\/\/sdf-docs.clevr.com\/?docs=ams","title":{"rendered":"AMS (Preview)"},"content":{"rendered":"<p><!--StartFragment--><\/p>\n\n\n<p class=\"wedocs-callout\">This is a preview tool. Find out more about preview tools <a href=\"https:\/\/sdf-docs.clevr.com\/docs\/what-is-preview\/\">here<\/a>.<\/p>\n\n\n\n<p>When you scan your app you manually have to\ndecide whether the data you see is correct. What AMS adds to this is to repeat\nthe scan automatically and compare the results. So if, with CI\/CD you restored\nthe same database and you run the scan against a different model then the\nchanges you see are caused by the model. These changes can either be as\nintended and be approved, or the change is a regression and the model needs to\nbe fixed.<\/p>\n\n\n\n<p>Application Model Security (AMS) is a tool\nthat scans your app from the outside and shows you what data is visible. This\ntool does NOT check the infrastructure security, nor does it test the platform\nand check for example OWASP criteria. AMS checks the security of how you\nmodeled your app.<\/p>\n\n\n\n<p>In the process this means when deploying to\nthe test (or autotest) environment the pipeline should not block on security\nerrors and just report the result, so the right person can approve of fix the\nissue.<\/p>\n\n\n\n<p>When deploying to acceptance the pipeline\nshould stop on differences.<\/p>\n\n\n\n<p>Using AMS you bring security into the\nprocess of the developer, more than just a checkbox in the definition of done.<\/p>\n\n\n<p><!--EndFragment--><\/p>","protected":false},"featured_media":0,"parent":0,"menu_order":4,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[],"class_list":["post-46","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/46"}],"collection":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/types\/docs"}],"replies":[{"embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46"}],"version-history":[{"count":4,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/46\/revisions"}],"predecessor-version":[{"id":462,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/46\/revisions\/462"}],"next":[{"title":"API","link":"https:\/\/sdf-docs.clevr.com\/?docs=api","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/2920"}],"prev":[{"title":"CI\/CD (Preview)","link":"https:\/\/sdf-docs.clevr.com\/?docs=ci-cd","href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=\/wp\/v2\/docs\/10"}],"wp:attachment":[{"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/sdf-docs.clevr.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdoc_tag&post=46"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}