NOTE: This course is only available by customer request. If you are interested in taking this course, please call 651-905-3729 or submit a request for a date.
This DevSecOps training boot camp is the most practical, in-depth educational solution for teams who want to understand, apply and improve their skills on “shifting left” in IT security. This expert-led boot camp focuses on the principles, processes, and technical skills necessary to make security and risk profiling a front-end priority: embracing a “quality first” mindset. Teams will leave class understanding that they have a responsibility for how applications and IT services perform when they are complete and in production…even if they are involved primarily in design, development or testing applications. For IT teams primarily on the end of the operations of the spectrum, this class will teach them how to shift left and collaborate on the upstream work that ultimately impacts the IT security environment, the organization’s risk management, and their own daily jobs.
In this Course, You will Learn How to:
Who Should Attend:
There are currently no public events available for this course. However, you can submit a request for a new date and we will try our best to get you into a DevSecOps Boot Camp class.
Part 1: DevOps, Security, and DevSecOps: Definitions
Part 2: Where do we start with security?
Part 3: Security as a DevOps practice
Part 4: DevSecOps and “requirements”
Part 5: Secure development patterns
Part 6: Security Testing in the Pipeline
Part 7: Identity and Access Management (IAM)
Part 8: Deployment patterns for security
1. Canary candidates
2. Dark launches
3. Streamlining libraries and dependencies
4. Keeping packages up to date
5. Keeping deploys repeatable and reliable
6. OpenSCAP for scanning baselines before and after deployments
7. Scanning web server configuration
8. Database exploitation through applications
9. Infrastructure scanning
10. Scanning web applications
1. Where does Ops security begin and end?
2. Infrastructure as Secure Code
3. Incident response planning and emergency drills
4. Release Archives
5. OS Protections:
7. Monitoring, logging and intelligent alerts
8. Log management
9. Penetration Testing
10. Exercise C: Profiling a DevSecOps Hybrid model
1. GRC review
2. Coding for compliance
3. DevOps and the “segregation of duties”
4. Tooling example: Chef InSpec
5. Change management and policy
6. Exercise D: Automated vs. Manual, to comply with Audit requirements
1. Three types of “change”
2. When and why to use CAB boards
3. Peer review vs. change management
4. Automating change management
ITIL in 2020
There are currently no public events available for this course. However, you can submit a request for a new date and we will try our best to get you into a DevSecOps Boot Camp class.
This DevSecOps training is for those who have at least an introductory-level understanding of DevOps and Agile topics.
There are currently no public events available for this course. However, you can submit a request for a new date and we will try our best to get you into a DevSecOps Boot Camp class.