Course Outline
1. DevSecOps Fundamentals: Security by Design
Key Takeaways: Core DevSecOps principles & secure SDLC
Demonstration: Direct comparison between legacy and modern secure pipelines
Practical Exercise: Create your first DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Scenario:
- Deploy a vulnerable application containing SQLi & XSS
- Leverage OWASP ZAP to identify and address threats
Defense Strategies:
- Implement automated scanning using ZAP
- Integrate into CI/CD via ZAP API
Practical Exercise: Tailor ZAP baseline scans + attack rules
Challenge: “Locate the hidden admin panel in 10 minutes”
3. Dependency Risks: Supply Chain Protection
Breach Scenario:
- Introduce a malicious npm package containing CVEs
Defense Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Establish policy gates that halt builds upon critical CVEs
Practical Exercise: Define vulnerability policies & alert workflows
Impactful Demo: “How a single flawed dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Scenario:
- Exploit unpatched container vulnerabilities
Defense Strategies:
- Aggregate reporting using OWASP DefectDojo
- Scan containers using Trivy
Practical Exercise: Develop real dashboards for CISO/executive reporting
Competition: “Triage 50 findings faster than your peers”
5. Secrets & Configuration Emergency Response
Breach Scenario:
- Extract secrets from Git history using truffleHog
Defense Strategies:
- Set up pre-commit hooks to block patterns like
password=.* - Utilize ZAP’s config spider to uncover dangerous settings
Practical Exercise: Implement GitHub Actions secrets scannin
Real-World Scenario: “Your database password is in Slack right now”
6. Conclusion: DevSecOps Action Plan
OWASP Integration Strategy:
- Outline the adoption plan for DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Prepare your 30-day security checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software and the SDLC
Audience
DevOps, Security & Cloud Engineers who are frustrated with theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer