Course Outline
1. DevSecOps Fundamentals: Security by Design
Learn: Key DevSecOps principles & secure SDLC practices
Demo: Direct comparison between legacy and modern secure pipelines
Lab: Create your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Set up a vulnerable app with SQLi & XSS
- Leverage OWASP ZAP to identify and mitigate threats
Defense Strategies:
- Automated scanning using ZAP
- CI/CD integration through the ZAP API
Lab: Tailor ZAP baseline scans and attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defense Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Apply policy gates that halt builds upon critical CVE detection
Lab: Establish vulnerability policies and alert workflows
Impactful Demo: “How a single faulty dependency can compromise your infrastructure”
4. Vulnerability Management Operations
Breach Simulation:
- Exploit unpatched container vulnerabilities
Defense Strategies:
- Centralize reporting via OWASP DefectDojo
- Scan containers using Trivy
Lab: Construct real-time dashboards for CISO and executive reporting
Competition: “Prioritize 50 findings more quickly than your competitors”
5. Secrets & Configuration Crisis Management
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Strategies:
- Implement pre-commit hooks to block patterns like
password=.* - Utilize ZAP’s config spider to reveal dangerous settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Action Plan
OWASP Integration Roadmap:
- Strategy for adopting DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Prepare your 30-day security checklist
- Establish your DevSecOps KPIs and reporting dashboards
Requirements
Basic software development and SDLC experience
Target Audience
DevOps, Security, and Cloud Engineers who prefer practical over theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer