Course Summary

Modern enterprises are implementing the technical and cultural changes required to embrace DevOps methodology by introducing practices such Continuous Integration (CI), Continuous Delivery (CD), Continuous Monitoring (CM) and Infrastructure as Code(IaC).

DevSecOps extends DevOps by introducing security into each of these practices giving a level of security assurance in the final product. In this course, we will demonstrate using our state-of-the-art DevSecOps Lab how to effectively inject security in CI, CD, CM and IaC.

Trained delegates can:

• Implement security tools and build and automate secure processes within their DevOps pipelines.
• Secure any DevOps environment, from development and staging to production.
• Securely deploy all the latest DevSecOps technologies which are covered in the course.
• Understand the business impact of DevSecOps principles and articulate this to key stakeholders.
• Solve business and development problems with a security mindset.
• Take on greater responsibility in the team and become an advocate of security in the wider business.

INTRODUCTION TO DEVOPS
• What is DevOps?
• DevOps Pipeline

INTRODUCTION TO DEVSECOPS
• Challenges for Security in DevOps
• DevOps Threat Model
• DevSecOps – Why, What and How?
• Vulnerability Management

CONTINUOUS INTEGRATION
• Pre-Commit Hooks
• Introduction to Talisman
• Running Talisman
• Create your own regexes for Talisman
• Secrets Management
• Introduction to HashiCorp Vault
• Vault Commands

CONTINUOUS DELIVERY
• Software Composition Analysis (SCA)
• Introduction to Dependency-Check
• Run Dependency-Check pipeline
• Fix issues reported by Dependency-Check
• Static Analysis Security Testing (SAST)
• Introduction to Semgrep
• Run Semgrep pipeline
• Create your own Semgrep Rules
• Fix Issues reported by Semgrep
• Dynamic Analysis Security Testing (DAST)
• Introduction to OWASP ZAP
• Creating ZAP Context File
• Run ZAP in pipeline

INFRASTRUCTURE AS CODE
• Vulnerability Assessment (VA)
• Introduction to OpenVAS
• Run OpenVAS pipeline
• Container Security (CS)
• Introduction to Trivy
• Run Trivy in Pipeline
• Improvise Docker base image
• Compliance as Code (CaC)
• Introduction to Inspec
• Run Inspec in Pipeline
• Improvise Docker compliancy controls

CONTINUOUS MONITORING
• Logging
• Introduction to the ELK Stack
• View Logs in Kibana
• Alerting
• Introduction to ElastAlert and ModSecurity
• View Alerts in Kibana
• Monitoring
• Create Attack Dashboards in Kibana

DEVSECOPS IN AWS
• DevOps on Cloud Native AWS
• AWS Threat Landscape
• DevSecOps in Cloud Native AWS

DEVSECOPS CHALLENGES AND ENABLERS
• Challenges with DevSecOps
• Building DevSecOps Culture
• Security Champions
• Case Studies
• Where do we Begin?
• DevSecOps Maturity Model

There is no prerequisite for taking this course. However, it is recommended that a candidate has more than a year of experience and/or equivalent certifications/courses

Upon successful completion of the course, delegates will receive a certificate of completion, acknowledging their proficiency in the subject matter.

Following your booking, a confirmation message will be sent to all participants, ensuring you're well-informed of your successful enrollment. Calendar placeholders will also be dispatched to assist you in scheduling your commitments around the course. Rest assured, all course materials and access to necessary labs or platforms will be provided no later than one week before the course begins, allowing you ample time to prepare and engage fully with the learning experience ahead.

Our comprehensive training package includes all the necessary materials and resources to facilitate a full learning experience. Enrollees will be provided with detailed course content, encompassing a wide array of topics to ensure a thorough understanding of the subject matter. Additionally, participants will receive a certificate of completion to recognize their dedication and hard work. It's important to note that while the course fee covers all training materials and experiences, the examination fee for certification is not included but can be purchased separately.

Questions About This Course?