Course Outline
1. DevSecOps Foundations: Security by Design
Acquire: Core DevSecOps principles & secure SDLC
Demo: Comparative analysis of legacy vs. modern secure pipelines
Lab: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Breach Simulation:
- Deploy a vulnerable application featuring SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize threats
Defense Strategies:
- Perform automated scanning using ZAP
- Integrate CI/CD via ZAP API
Lab: Tailor ZAP baseline scans + attack rules
Challenge: “Locate the hidden admin panel within 10 minutes”
3. Supply Chain Resilience: Managing Dependency Risks
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defense Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Implement policy gates that halt builds upon critical CVEs
Lab: Establish vulnerability policies & alert workflows
Illustrative Demo: “How a single faulty dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit unpatched container vulnerabilities
Defense Strategies:
- Consolidate reporting via OWASP DefectDojo
- Analyze containers using Trivy
Lab: Develop real dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings quicker than competitors”
5. Secrets & Configuration Crisis Drill
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Strategies:
- Utilize pre-commit hooks to intercept patterns like
password=.* - Employ ZAP’s config spider to expose risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database credentials are currently exposed in Slack”
6. Conclusion: DevSecOps Strategic Plan
OWASP Adoption Roadmap:
- Outline your implementation of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Prepare a 30-day security checklist
- Establish DevSecOps KPIs & reporting dashboards
Requirements
Basic software and SDLC proficiency
Target Audience
DevOps, Security & Cloud Engineers who prefer practical over theoretical security discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer