Course Outline
1. DevSecOps Fundamentals: Security by Design
Understanding: Core DevSecOps concepts & secure SDLC
Demonstration: Direct comparison of legacy versus modern secure pipelines
Practical Exercise: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Deploy an application vulnerable to SQLi & XSS
- Leverage OWASP ZAP to identify and neutralise threats
Defence Strategies:
- Automated scanning using ZAP
- CI/CD integration through the ZAP API
Practical Exercise: Tailor ZAP baseline scans + attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defence Strategies:
- Track vulnerabilities via OWASP Dependency-Track
- Apply policy gates that abort builds on critical CVEs
Practical Exercise: Formulate vulnerability policies & alert workflows
Illustrative Demonstration: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management Crisis Room
Breach Simulation:
- Exploit unpatched container vulnerabilities
Defence Strategies:
- Consolidate reporting using OWASP DefectDojo
- Scan containers with Trivy
Practical Exercise: Develop real dashboards for CISO/executive reporting
Competition: “Prioritise 50 findings faster than your competitors”
5. Secrets & Configuration Emergency Response
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defence Strategies:
- Pre-commit hooks to intercept patterns like
password=.* - Utilise ZAP’s configuration spider to expose risky settings
Practical Exercise: Implement GitHub Actions secret scanning
Reality Check: “Your database password is currently visible in Slack”
6. Conclusion: DevSecOps Strategy Roadmap
OWASP Integration Roadmap:
- Map out the adoption of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Outline your 30-day security checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic software and SDLC experience
Target Audience
DevOps, Security & Cloud Engineers who are dissatisfied with purely theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer