Course Outline
1. DevSecOps Basics: Security-First Architecture
Discovery: Fundamental DevSecOps concepts and secure SDLC practices
Demonstration: Direct comparison between legacy and contemporary secure pipelines
Hands-On: Develop an initial DevSecOps-compatible pipeline template
2. OWASP ZAP Security Assessment Intensive
Attack Simulation:
- Deploy a vulnerable application containing SQLi and XSS flaws
- Leverage OWASP ZAP to identify and neutralize threats
Mitigation Strategies:
- Perform automated scanning using ZAP
- Integrate into CI/CD workflows via the ZAP API
Hands-On: Adapt ZAP baseline scans and custom attack rules
Task: Locate the concealed admin panel within 10 minutes
3. Dependency Risks: Supply Chain Protection
Attack Simulation:
- Introduce a malicious npm package containing known CVEs
Mitigation Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Apply policy controls that halt builds upon critical CVE detection
Hands-On: Establish vulnerability policies and alert workflows
Case Study: Demonstrate how a single flawed dependency can compromise infrastructure
4. Vulnerability Management Command Center
Attack Simulation:
- Exploit unpatched vulnerabilities in containers
Mitigation Strategies:
- Consolidate reporting using OWASP DefectDojo
- Execute container scans with Trivy
Hands-On: Construct operational dashboards for CISO and executive oversight
Competition: Prioritize 50 findings more quickly than competitors
5. Secrets and Configuration Crisis Simulation
Attack Simulation:
- Extract secrets from Git history utilizing truffleHog
Mitigation Strategies:
- Install pre-commit hooks to block patterns like
password=.* - Utilize ZAP’s configuration spider to expose risky settings
Hands-On: Execute secrets scanning in GitHub Actions
Insight: Reveal common pitfalls where database credentials remain exposed in collaboration tools
6. Conclusion: DevSecOps Strategic Plan
OWASP Adoption Roadmap:
- Strategy for implementing DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Develop a 30-day security compliance checklist
- Establish DevSecOps KPIs and reporting dashboard structures
Requirements
Essential software and SDLC knowledge
Target Audience
DevOps, Security, and Cloud Engineers who prefer action over theory
Testimonials (2)
The knowledge and experience of the consultant, as theoretical topics are addressed by applying them to the reality of processes. The course contains a highly valuable program in information technology management.
Luis Castro Gamboa - Cooperativa De Ahorro Y Credito Ande No. 1 R.L.
Course - Site Reliability Engineering (SRE) Foundation®
Machine Translated
That it was very clear in each specification
Ricardo Ramirez - AMX CONTENIDO
Course - DevOps Leader (DOL)®
Machine Translated