Course Outline
1. DevSecOps Essentials: Designing for Security
Learn: Key DevSecOps principles & secure SDLC practices
Demo: Comparative analysis of legacy vs. modern secure pipelines
Lab: Develop your initial DevSecOps-integrated pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Set up a vulnerable application containing SQLi & XSS issues
- Leverage OWASP ZAP to identify and neutralize threats
Defense Tactics:
- Automate scanning processes with ZAP
- Integrate ZAP into CI/CD workflows via its API
Lab: Tailor ZAP baseline scans and attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Supply Chain Resilience: Taming Dependency Chaos
Breach Simulation:
- Introduce a malicious npm package containing known CVEs
Defense Tactics:
- Track vulnerabilities using OWASP Dependency-Track
- Implement policy gates that halt builds upon critical CVE detection
Lab: Establish vulnerability policies and alert workflows
Demo: “Discover how a single faulty dependency can compromise your entire infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit unpatched vulnerabilities within containers
Defense Tactics:
- Centralize vulnerability reporting with OWASP DefectDojo
- Perform container scans using Trivy
Lab: Construct live dashboards tailored for CISO/executive reporting
Competition: “Prioritize and triage 50 findings quicker than your competitors”
5. Secrets & Configuration Incident Drill
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Tactics:
- Deploy pre-commit hooks to intercept patterns such as
password=.* - Utilize ZAP’s configuration spider to reveal risky settings
Lab: Execute secret scanning within GitHub Actions
Reality Check: “Your database credentials are currently exposed on Slack”
6. Conclusion: DevSecOps Strategic Roadmap
OWASP Integration Strategy:
- Chart the adoption path for DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Create a 30-day security implementation checklist
- Establish DevSecOps KPIs and monitoring dashboards
Requirements
Basic knowledge of software and SDLC processes
Target Audience
DevOps, Security & Cloud Engineers who dislike abstract security theory
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer