Course Outline
1. DevSecOps Fundamentals: Designing for Security
Learn: Essential DevSecOps principles & secure SDLC practices
Demo: Comparative analysis of legacy versus modern secure pipelines
Lab: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Deploy a vulnerable application containing SQLi & XSS flaws
- Leverage OWASP ZAP to identify and neutralize threats
Defense Tactics:
- Implement automated scanning using ZAP
- Integrate ZAP into CI/CD workflows via the ZAP API
Lab: Tailor ZAP baseline scans + custom attack rules
Challenge: “Locate the hidden admin panel within 10 minutes”
3. Dependency Challenges: Supply Chain Protection
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defense Tactics:
- Track vulnerabilities using OWASP Dependency-Track
- Establish policy gates that halt builds upon critical CVE detection
Lab: Develop vulnerability policies & alert workflows
Shocking Demo: “How a single faulty dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit unpatched container vulnerabilities
Defense Tactics:
- Consolidate reporting with OWASP DefectDojo
- Scan containers using Trivy
Lab: Develop dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings faster than your competitors”
5. Secrets & Configuration Emergency Exercise
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Tactics:
- Utilize pre-commit hooks to block patterns such as
password=.* - Leverage ZAP’s config spider to expose risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Action Plan
OWASP Integration Roadmap:
- Map out the adoption strategy for DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Draft your 30-day security checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software development and the SDLC
Target Audience
DevOps, Security & Cloud Engineers who dislike abstract security presentations
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer