Course Outline
1. DevSecOps Core: Security by Design
Discover: Fundamental DevSecOps principles & secure SDLC practices
Demo: Direct comparison between legacy and modern secure pipelines
Lab: Construct your initial DevSecOps-enabled pipeline template
2. OWASP ZAP Security Testing Intensive
Attack Simulation:
- Launch a vulnerable application featuring SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize threats
Defensive Strategies:
- Automated scanning using ZAP
- Integrating ZAP API into CI/CD workflows
Lab: Tailor ZAP baseline scans and define attack rules
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Security
Attack Simulation:
- Introduce a malicious npm package containing CVEs
Defensive Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Implement policy gates that halt builds upon detecting critical CVEs
Lab: Establish vulnerability policies and alert workflows
Impactful Demo: “How a single flawed dependency can compromise your entire infrastructure”
4. Vulnerability Management Command Center
Attack Simulation:
- Exploit unpatched container vulnerabilities
Defensive Strategies:
- Consolidate reporting via OWASP DefectDojo
- Scan containers using Trivy
Lab: Design live dashboards for CISO and executive-level reporting
Competition: “Prioritize 50 findings more quickly than your competitors”
5. Secrets & Configuration Emergency Drill
Attack Simulation:
- Extract secrets from Git history using truffleHog
Defensive Strategies:
- Implement pre-commit hooks to prevent patterns such as
password=.* - Utilize ZAP’s configuration spider to reveal risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database password is currently exposed in Slack”
6. Conclusion: DevSecOps Action Strategy
OWASP Integration Pathway:
- Strategy your adoption of DefectDojo, Dependency-Track, and ZAP
Individual Action Plan:
- Create your 30-day security checklist
- Establish your DevSecOps KPIs and reporting dashboards
Requirements
Basic knowledge of software and the SDLC
Target Audience
DevOps, Security & Cloud Engineers who dread theoretical security briefings
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer