Course Outline
Introduction
- How DevOps Creates Additional Security Risks for Organizations
- The Trade-offs Between Agility, Speed, and Decentralized Control
Inadequacies of Traditional Security Tools
- Security Policies
- Firewall Rules
- Lack of APIs for Integration
- Lack of Visualization Capabilities
Implementing a DevOps-Ready Security Program for Government
Aligning Security with Business Goals for Government
Removing the Security Bottleneck in Government Operations
Implementing Detailed Visibility for Government
Standardizing Security Configurations for Government
Adding Sensors into Applications for Government
- Interactive Application Security Testing
- Runtime Application Self-Protection
Providing Security Data to DevOps Tools through RESTful APIs for Government
On-Demand Scaling and Micro-Perimeterization of Security Controls for Government
Implementing Per-Resource Granular Security Policies for Government
Automating Attacks against Pre-Production Code for Government
Continually Testing the Production Environment for Government
Protecting Web Applications from an Agile/DevOps Perspective for Government
Securing Containers and Clouds for Government
Embracing Next Generation Automated Security Tools for Government
The Future of DevOps and Its Strategic Role in Security for Government
Summary and Conclusion
Requirements
- Experience with DevOps practices.
- Basic knowledge or interest in security principles.
Audience
- DevOps engineers for government agencies
- Security engineers
Testimonials (1)
There were many practical exercises supervised and assisted by the trainer