DevSecOps
NotSoSecure
Hands-on training to automate security into a fast-paced DevOps environment using various open-source tools and scripts. Modern enterprises are implementing the technical and cultural changes required to embrace DevOps methodology by introducing practices such as Continuous Integration (CI), Continuous Delivery (CD), Continuous Monitoring (CM) and Infrastructure as Code (IaC).
Who Should Attend
- Leaders looking to understand what DevOps is and how it will help their organization
- Technical specialists looking to understand the concepts and route to becoming a DevOps Practitioner
- Developers wanting to integrate security into their DevOps workflows
- IT managers seeking to build a DevSecOps culture
- Anyone with a background in IT or software development
Prerequisites
- Background in IT or related to software development
- Basic understanding of DevOps concepts
- Familiarity with software development lifecycle
- No advanced security experience required
What You Will Learn
- Introduction to DevOps and DevOps Pipeline
- Introduction to DevSecOps
- Challenges for Security in DevOps
- DevOps Threat Model
- Vulnerability Management
- Pre-Commit Hooks
- Introduction to Talisman
- Lab: Running Talisman
- Secrets Management
- Introduction to HashiCorp Vault
- Demo: Vault Commands
- Software Composition Analysis (SCA)
- Introduction to Dependency-Check
- Lab: Run Dependency-Check pipeline
- Lab: Fix issues reported by Dependency-Check
- Static Analysis Security Testing (SAST)
- Introduction to Semgrep
- Lab: Run Semgrep pipeline
- Lab: Create your own Semgrep rules
- Lab: Fix issues reported by Semgrep
- Dynamic Analysis Security Testing (DAST)
- Introduction to OWASP ZAP
- Demo: Creating ZAP Context File
- Lab: Run ZAP in pipeline
- Infrastructure As Code
- Vulnerability Assessment (VA)
- Introduction to OpenVAS
- Lab: Run OpenVAS pipeline
- Container Security (CS)
- Introduction to Trivy
- Lab: Run Trivy in pipeline
- Lab: Improvise Docker base image
- Compliance and Monitoring
- Compliance as Code (CaC)
- Introduction to Inspec
- Lab: Run Inspec in pipeline
- Lab: Improvise Docker compliancy controls
- Continuous Monitoring
- Logging with the ELK Stack
- Lab: View Logs in Kibana
- Alerting with ElastAlert and ModSecurity
- Lab: View Alerts in Kibana
- Monitoring and Attack Dashboards in Kibana
- DevSecOps in AWS
- DevOps on Cloud Native AWS
- AWS Threat Landscape
- DevSecOps in Cloud Native AWS
- DevSecOps Challenges and Enablers
Course Outline
Labs & Practical Exercises
This course includes extensive hands-on labs using open-source security tools integrated into CI/CD pipelines. Labs cover Talisman for pre-commit hooks, HashiCorp Vault for secrets management, Dependency-Check for SCA, Semgrep for SAST, OWASP ZAP for DAST, OpenVAS for vulnerability assessment, Trivy for container security, Inspec for compliance as code, and the ELK Stack for monitoring and alerting.
Certification & Assessment
Certificate of Completion. This course also supplies delegates with a copy of "The Phoenix Project - A Novel About IT, DevOps, and Helping Your Business Win", an informative bible for those wanting to know more about how to embrace DevOps in their business.
