Course Outline
1. DevSecOps Fundamentals: Security by Design
Understanding: Core DevSecOps principles & secure SDLC
Demonstration: Comparative analysis of legacy versus modern secure pipelines
Exercise: Developing your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Installing a vulnerable application containing SQLi & XSS
- Employing OWASP ZAP to identify and neutralize threats
Defensive Strategies:
- Automated scanning using ZAP
- CI/CD integration through the ZAP API
Exercise: Configuring ZAP baseline scans + attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Security
Breach Simulation:
- Introducing a malicious npm package with CVEs
Defensive Strategies:
- Monitoring vulnerabilities via OWASP Dependency-Track
- Enforcing policy controls that halt builds upon critical CVE detection
Exercise: Establishing vulnerability policies & alert workflows
Impactful Demonstration: “How a single compromised dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploiting unpatched container vulnerabilities
Defensive Strategies:
- Consolidating reporting using OWASP DefectDojo
- Scanning containers with Trivy
Exercise: Developing live dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings more quickly than competitors”
5. Secrets & Configuration Emergency Drill
Breach Simulation:
- Exfiltrating secrets from Git history utilizing truffleHog
Defensive Strategies:
- Pre-commit hooks to block patterns like
password=.* - Leveraging ZAP’s configuration spider to reveal risky settings
Exercise: Deploying GitHub Actions secret scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Action Plan
OWASP Integration Strategy:
- Planning the adoption of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Drafting your 30-day security checklist
- Defining DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software and SDLC experience
Target Audience
DevOps, Security & Cloud Engineers who are disinterested in abstract security discussions
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 1300 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
real life examples