Course Outline
1. DevSecOps Basics: Security-First Architecture
Concepts: Fundamental DevSecOps tenets & secure SDLC
Demonstration: Direct comparison between legacy and modern secure pipelines
Exercise: Construct your initial DevSecOps-compatible pipeline template
2. OWASP ZAP Security Assessment Intensive
Threat Simulation:
- Set up a vulnerable application featuring SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize risks
Mitigation Strategies:
- Automate scanning processes using ZAP
- Integrate into CI/CD workflows via ZAP API
Exercise: Tailor ZAP baseline scans + attack signatures
Task: “Locate the concealed admin interface within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Threat Simulation:
- Introduce a malicious npm package containing CVEs
Mitigation Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Apply policy controls that halt builds upon critical CVE detection
Exercise: Establish vulnerability policies & notification workflows
Impact Demo: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management Command Center
Threat Simulation:
- Exploit unpatched container flaws
Mitigation Strategies:
- Consolidate reporting through OWASP DefectDojo
- Scan containers using Trivy
Exercise: Develop actual dashboards for CISO/executive insights
Competition: “Prioritize 50 detections quicker than competitors”
5. Secrets & Config Crisis Management
Threat Simulation:
- Extract secrets from Git history utilizing truffleHog
Mitigation Strategies:
- Install pre-commit hooks to intercept patterns like
password=.* - Utilize ZAP's config spider to reveal risky configurations
Exercise: Deploy GitHub Actions secrets scanning
Reality Check: “Your database credentials are currently exposed in Slack”
6. Conclusion: DevSecOps Action Strategy
OWASP Adoption Roadmap:
- Map out the rollout for DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Outline your 30-day security review checklist
- Specify your DevSecOps KPIs & reporting visualizations
Requirements
Basic software development and SDLC knowledge
Target Audience
DevOps, Security & Cloud Professionals who disfavor abstract security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer