Get in Touch

Course Outline

Day 01

Introduction

DevSecOps Overview

  • CI (Continuous Integration) and CD (Continuous Delivery)
  • Shifting security left, through the DevOps approach

DevSecOps Methodologies

  • Security considerations for DevOps technologies
  • Timing and methods of security interaction with the application and development lifecycle
  • Shared ownership of security responsibilities and activities

Day 02

Implementing DevSecOps with Jenkins

  • Setting up an agent
  • Creating a pipeline job
  • Utilizing SYNK and SonarQube for SAST security scanning
  • Utilizing Arachni and OWASP-ZAP for DAST security scanning
  • Utilizing Anchore and Aqua MicroScanner for container image security scanning
  • Developing a DevSecOps pipeline
  • Enabling CI and CD

Security Automation

  • Automating security testing with Gaunit
  • Executing an automated attack

Application Security Automation

  • Automating and refactoring XSS attack scenarios
  • Automating SQLi attack scenarios
  • Automating fuzzing processes
  • Evaluating security within software delivery pipelines

Summary and Next Steps

Requirements

  • A foundational understanding of the DevOps process

Target Audience

  • DevOps professionals
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories