Course Outline
1. DevSecOps Essentials: Security-First Architecture
Learn: Fundamental DevSecOps concepts & secure SDLC implementation
Demo: Comparative analysis of legacy versus modern secure pipelines
Lab: Construct an initial DevSecOps-compatible pipeline template
2. OWASP ZAP Security Assessment Intensive
Breach Simulation:
- Deploy an application vulnerable to SQLi & XSS
- Leverage OWASP ZAP to identify and neutralize threats
Defense Strategies:
- Automated scanning using ZAP
- CI/CD integration through ZAP API
Lab: Adapt ZAP baseline scans + attack configurations
Challenge: “Locate the concealed admin panel within 10 minutes”
3. Dependency Risks: Supply Chain Security
Breach Simulation:
- Introduce a malicious npm package containing CVEs
Defense Strategies:
- Track vulnerabilities using OWASP Dependency-Track
- Implement policy controls that trigger build failures for critical CVEs
Lab: Establish vulnerability policies & alerting workflows
Impactful Demo: “How a single flawed dependency can compromise your infrastructure”
4. Vulnerability Management Command Center
Breach Simulation:
- Exploit unpatched vulnerabilities in containers
Defense Strategies:
- Consolidate reporting via OWASP DefectDojo
- Scan containers using Trivy
Lab: Develop live dashboards for CISO/executive reporting
Competition: “Prioritize 50 findings more efficiently than competitors”
5. Secrets & Configuration Emergency Exercise
Breach Simulation:
- Extract secrets from Git history using truffleHog
Defense Strategies:
- Pre-commit hooks to prevent patterns such as
password=.* - Utilize ZAP’s configuration spider to reveal risky settings
Lab: Deploy GitHub Actions secrets scanning
Reality Check: “Your database credentials are currently exposed in Slack”
6. Conclusion: DevSecOps Strategic Roadmap
OWASP Adoption Pathway:
- Map out the implementation of DefectDojo, Dependency-Track, and ZAP
Personal Development Plan:
- Formulate a 30-day security checklist
- Establish DevSecOps KPIs & reporting dashboards
Requirements
Basic knowledge of software and the SDLC
Target Audience
DevOps, Security & Cloud Engineers who prefer practical application over theoretical discussions
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer