DevSecOps - Security in DevOps
About this course
DevSecOps integrates security into every stage of the development lifecycle, automating security testing and creating a culture where security is everyone's responsibility.
Prerequisites
- Basic DevOps knowledge
- CI/CD (GitHub Actions, GitLab CI)
- Docker and Kubernetes
- Understanding of IT security
Course content
-
- DevSecOps culture
- Security by design
- Shared responsibility
-
- Shift Left principles
- Threat modeling
- Security requirements
-
- Static Application Security Testing
- Dynamic Application Security Testing
- Tools and CI integration
-
- Image scanning
- Runtime security
- Kubernetes security
-
- Dependency scanning (SCA)
- SBOM
- Signing and attestation
-
- Vault, AWS Secrets Manager
- Automatic rotation
- Zero-knowledge
-
- Policy as Code
- OPA, Kyverno
- Automated auditing
-
- Detection and response
- Forensics
- Post-mortem
-
- OWASP guidelines
- Security champions
- Security metrics
-
- Hands-on labs
- Secure project
- Certifications
Estimated duration
⏱️ 18-22 hours of training including hands-on exercises
Learning objectives
By the end of this course, you will be able to:
- Integrate security into CI/CD pipelines
- Use SAST, DAST, and SCA tools
- Secure containers and Kubernetes
- Manage secrets securely
- Implement Compliance as Code
- Respond to security incidents