Identity Security for Software Development
Couldn't load pickup availability
ISBN: 9789365892536
eISBN: 9789365898354
Authors: Aiyan Ma
Rights: Worldwide
Edition: 2026
Pages: 300
Dimension: 7.5*9.25 Inches
Book Type: Paperback

- Description
- Table of Contents
- About the Authors
As modern infrastructures become increasingly automated, non-human identities, such as service accounts, API tokens, and automation agents, are emerging as critical security assets. Securing these identities is essential to protecting cloud-native environments, automated workflows, and machine-to-machine interactions from breaches, data leaks, and abuse.
This book provides a comprehensive guide to securing NHIs through practical strategies and hands-on demonstrations. Readers will explore the evolution of NHI security, from early machine-to-machine protocols to modern Zero Trust frameworks. Key topics include designing secure service accounts, managing API tokens and certificates, implementing secrets management with tools like HashiCorp Vault, SPRIE, and applying robust security controls such as encryption, access control, monitoring, ZTA, testing, automation, and centralization. To reinforce these concepts, the book presents a hands-on proof of concept (PoC) that demonstrates secure NHI management in an MCP system. Readers will gain insights into automating identity provisioning, ensuring credential hygiene, and integrating security best practices.
By the end of this book, readers will be equipped with the knowledge and skills to build resilient, security-first environments that protect NHIs across dynamic infrastructures.
WHAT YOU WILL LEARN
● Understand the evolution of NHI and best practices for securing service accounts, API tokens, and certificates.
● Implement secure credential storage, rotation, and access control using HashiCorp Vault and Kubernetes Secrets.
● Practical strategies for enforcing Zero Trust Architecture, rate limiting, and allow/block lists to mitigate unauthorized access and abuse.
● Build a functional MCP system that integrates secure identity management, credential hygiene, and automated workflows.
● Explore future-ready strategies like AI-driven threat detection, quantum-resistant algorithms, and dynamic authentication models to secure evolving infrastructures.
WHO THIS BOOK IS FOR
This book targets intermediate to advanced practitioners, security professionals, engineering teams, and technical leadership who must have foundational knowledge of cloud-native, API-driven, and automated infrastructure concepts.
1. History of Non-human Identities Security
2. Introduction to Non-human Identities
3. NHI Security Landscape
4. Identity of NHI
5. Credential Management
6. Security Controls
7. Automation and Orchestration
8. Build a Secure MCP System
9. Building Security Culture by Coding
10. Emerging Trends in NHI Security
Aiyan Ma is a cybersecurity expert with over 20 years of experience in software security architecture, secure software design and coding, identity and access management, and network security. With a strong background spanning software design and development, global software lead, and security architecture. He is passionate about cybersecurity, specializing in both the why and the how of implementing security, bridging the gap between theoretical security principles and real-world coding and implementation.