DevSecOps

Hands-on training to automate security into a fast-paced DevOps environment using various open-source tools and scripts. Modern enterprises are implementing the technical and cultural changes required to embrace DevOps methodology by introducing practices such Continuous Integration (CI), Continuous Delivery (CD), Continuous Monitoring (CM) and Infrastructure as Code (IaC).

Interested in attending? Have a suggestion about running this event near you?
Register your interest now

Description

Day 1

  • Lab Setup
  • Online Lab Setup
  • Offline Lab Instructions
  • Introduction to DevOps
  • What is DevOps?
  • Lab : DevOps Pipeline
  • Introduction to DevSecOps
  • Challenges for Security in DevOps
  • DevOps Threat Model
  • DevSecOps – Why, What and How?
  • Vulnerability Management
  • Continuous Integration
  • Pre-Commit Hooks
  • Introduction to Talisman
  • Lab : Running Talisman
  • Lab : Create your own regexes for Talisman
  • Secrets Management
  • Introduction to HashiCorp Vault
  • Demo : Vault Commands
  • Continuous Delivery
  • Software Composition Analysis (SCA)
  • Introduction to Dependency-Check
  • Lab : Run Dependency-Check pipeline
  • Lab : Fix issues reported by Dependency-Check
  • Static Analysis Security Testing (SAST)
  • Introduction to Semgrep
  • Lab : Run Semgrep pipeline
  • Lab : Create your own Semgrep Rules
  • Lab : Fix Issues reported by Semgrep
  • Dynamic Analysis Security Testing (DAST)
  • Introduction to OWASP ZAP
  • Demo : Creating ZAP Context File
  • Lab : Run ZAP in pipeline

Day 2

  • Infrastructure As Code
  • Vulnerability Assessment (VA)
  • Introduction to OpenVAS
  • Lab : Run OpenVAS pipeline
  • Container Security (CS)
  • Introduction to Trivy
  • Lab : Run Trivy in Pipeline
  • Lab : Improvise Docker base image
  • Compliance as Code (CaC)
  • Introduction to Inspec
  • Lab : Run Inspec in Pipeline
  • Lab : Improvise Docker compliancy controls
  • Continuous Monitoring
  • Logging
  • Introduction to the ELK Stack
  • Lab : View Logs in Kibana
  • Alerting
  • Introduction to ElastAlert and ModSecurity
  • Lab : View Alerts in Kibana
  • Monitoring
  • Lab : Create Attack Dashboards in Kibana
  • DevSecOps in AWS
  • DevOps on Cloud Native AWS
  • AWS Threat Landscape
  • DevSecOps in Cloud Native AWS
  • DevSecOps Challenges and Enablers
  • Challenges with DevSecOps
  • Building DevSecOps Culture
  • Security Champions
  • Case Studies
  • Where do we Begin?
  • eDvSecOps Maturity Model

Prerequisites

Anybody with a background in IT or related to software development whether a developer or a manager can attend this course to get an insight about DevOps and DevSecOps.

Audience

Designed for leaders looking to understand what DevOps is and how it will help them and technical specialists looking to understand the concepts and route to becoming a DevOps Practitioner.
This course also supplies delegates with a copy of 'The Phoenix Project - A Novel About IT, DevOps, and Helping Your Business Win', an informative bible for those wanting to know more about how to embrace DevOps in their business.

Subscribe to Newsletter

Enter your email address to register to our newsletter subscription delivered on regular basis! 

CONTACT US     ABOUT     PRIVACY   BLOG

© Copyright GTP Computrain, Limited 2025