Course Outline
1. DevSecOps Fundamentals: Security by Design
Discover: Key DevSecOps concepts & secure SDLC practices
Demo: Comparative analysis of legacy versus modern secure pipelines
Lab: Develop your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Implement a vulnerable application containing SQLi & XSS vulnerabilities
- Leverage OWASP ZAP to identify and address threats
Defense Tactics:
- Automated scanning using ZAP
- Integrating ZAP into CI/CD via its API
Lab: Tailor ZAP baseline scans + attack rules
Challenge: “Locate the hidden admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Breach Simulation:
- Introduce a malicious npm package with known CVEs
Defense Tactics:
- Track vulnerabilities using OWASP Dependency-Track
- Enforce policy gates that halt builds upon critical CVE detection
Lab: Establish vulnerability policies & alert workflows
Impactful Demo: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit vulnerabilities in unpatched containers
Defense Tactics:
- Consolidate reporting with OWASP DefectDojo
- Perform container scanning with Trivy
Lab: Construct live dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings more quickly than competitors”
5. Secrets & Configuration Crisis Simulation
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Tactics:
- Pre-commit hooks to intercept patterns like
password=.* - Utilize ZAP’s configuration spider to reveal risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Strategic Plan
OWASP Integration Roadmap:
- Strategy for adopting DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Create your 30-day security checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software development and the SDLC
Audience
DevOps, Security & Cloud Engineers who prefer practical over theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer