Course Outline
1. DevSecOps Fundamentals: Security by Design
Key Takeaways: Core DevSecOps concepts & secure SDLC practices
Demonstration: A comparative analysis of legacy versus contemporary secure pipelines
Hands-on Exercise: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Attack Simulation:
- Deploy a vulnerable application featuring SQLi & XSS flaws
- Leverage OWASP ZAP to identify and neutralize threats
Mitigation Strategies:
- Implement automated scanning using ZAP
- Integrate ZAP into CI/CD workflows via its API
Hands-on Exercise: Configure ZAP baseline scans + custom attack rules
Challenge: “Locate the concealed admin interface within 10 minutes”
3. Dependency Risks: Supply Chain Protection
Attack Simulation:
- Introduce a malicious npm package containing known CVEs
Mitigation Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Establish policy gates that halt builds upon critical CVE detection
Hands-on Exercise: Define vulnerability policies & alert workflows
Impactful Demonstration: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management Command Center
Attack Simulation:
- Exploit unpatched vulnerabilities in containerized environments
Mitigation Strategies:
- Consolidate reporting via OWASP DefectDojo
- Perform container scans using Trivy
Hands-on Exercise: Develop real-time dashboards for CISO/executive oversight
Competition: “Prioritize 50 findings more efficiently than your competitors”
5. Secrets & Configuration Emergency Drill
Attack Simulation:
- Extract secrets from Git history using truffleHog
Mitigation Strategies:
- Deploy pre-commit hooks to block patterns such as
password=.* - Utilize ZAP’s configuration spider to reveal insecure settings
Hands-on Exercise: Implement secrets scanning within GitHub Actions
Reality Check: “Your database credentials are currently exposed in Slack”
6. Conclusion: DevSecOps Strategy Blueprint
OWASP Adoption Roadmap:
- Map out the implementation path for DefectDojo, Dependency-Track, and ZAP
Personal Action Plan:
- Formulate a 30-day security improvement checklist
- Establish your DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software development and the SDLC
Target Audience
DevOps, Security & Cloud Engineers who disfavor abstract security theory
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer