Skip to main content

DevSecOps - Security in DevOps


About this course

DevSecOps integrates security into every stage of the development lifecycle, automating security testing and creating a culture where security is everyone's responsibility.


Prerequisites

  • Basic DevOps knowledge
  • CI/CD (GitHub Actions, GitLab CI)
  • Docker and Kubernetes
  • Understanding of IT security

Course content

  1. Introduction to DevSecOps

    • DevSecOps culture
    • Security by design
    • Shared responsibility
  2. Shift Left Security

    • Shift Left principles
    • Threat modeling
    • Security requirements
  3. SAST and DAST

    • Static Application Security Testing
    • Dynamic Application Security Testing
    • Tools and CI integration
  4. Container security

    • Image scanning
    • Runtime security
    • Kubernetes security
  5. Supply Chain Security

    • Dependency scanning (SCA)
    • SBOM
    • Signing and attestation
  6. Secrets management

    • Vault, AWS Secrets Manager
    • Automatic rotation
    • Zero-knowledge
  7. Compliance as Code

    • Policy as Code
    • OPA, Kyverno
    • Automated auditing
  8. Incident Response

    • Detection and response
    • Forensics
    • Post-mortem
  9. Best practices

    • OWASP guidelines
    • Security champions
    • Security metrics
  10. Exercises and Projects

    • Hands-on labs
    • Secure project
    • Certifications

Estimated duration

⏱️ 18-22 hours of training including hands-on exercises


Learning objectives

By the end of this course, you will be able to:

  • Integrate security into CI/CD pipelines
  • Use SAST, DAST, and SCA tools
  • Secure containers and Kubernetes
  • Manage secrets securely
  • Implement Compliance as Code
  • Respond to security incidents