Course Outline
1. DevSecOps Fundamentals: Designing for Security
Learn: Essential DevSecOps principles & secure SDLC practices
Demo: Comparative analysis of legacy versus modern secure pipelines
Lab: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Deploy an application vulnerable to SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize threats
Defense Strategies:
- Execute automated scans using ZAP
- Integrate CI/CD workflows via the ZAP API
Lab: Configure ZAP baseline scans + attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Management: Protecting the Supply Chain
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defense Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Apply policy gates that halt builds upon detecting critical CVEs
Lab: Establish vulnerability policies & alerting workflows
Illustrative Demo: “How a single flawed dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit unpatched vulnerabilities in containers
Defense Strategies:
- Consolidate reporting through OWASP DefectDojo
- Perform container scans using Trivy
Lab: Create live dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings more quickly than competitors”
5. Secrets & Configuration Emergency Response
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Strategies:
- Set up pre-commit hooks to intercept patterns like
password=.* - Utilize ZAP’s configuration spider to reveal risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database credentials are currently exposed in Slack”
6. Conclusion: DevSecOps Strategic Roadmap
OWASP Adoption Plan:
- Map out your implementation of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Outline your 30-day security audit checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic software development and SDLC knowledge
Target Audience
DevOps, Security & Cloud Engineers who dislike theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer