DevSecOps Training Course
DevOps is the collaboration between IT operations and software development throughout the service lifecycle. DevSecOps integrates security practices within the DevOps process, ensuring secure and scalable evolution of constantly changing systems.
This instructor-led, live training (available online or onsite) is designed for government DevOps professionals who wish to enhance the security of their DevOps processes through the implementation of DevSecOps programs.
By the end of this training, participants will be able to:
- Understand how a DevSecOps program can effectively integrate security into a software development pipeline for government.
- Build a secure continuous delivery pipeline that meets public sector standards.
- Automate security testing within a software delivery workflow to ensure compliance and efficiency.
Format of the Course
- Interactive lectures and discussions.
- Extensive exercises and practical activities.
- Hands-on implementation in a live-lab environment tailored for government use cases.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline
Day 01
Introduction
An Overview of DevSecOps
- Continuous Integration (CI) and Continuous Delivery (CD)
- Incorporating security early in the development process, the DevOps approach
Theories and Methods of DevSecOps
- Security integration with DevOps technologies
- Timing and methods for incorporating security into application and development lifecycle
- Shared responsibility for security tasks and activities
Day 02
Implementing DevSecOps with Jenkins
- Creating a Jenkins agent
- Setting up a pipeline job
- Utilizing SYNK and SonarQube for Static Application Security Testing (SAST)
- Employing Arachni and OWASP-ZAP for Dynamic Application Security Testing (DAST)
- Using Anchore and Aqua MicroScanner for container image security scanning
- Developing a comprehensive DevSecOps pipeline
- Enabling CI and CD processes
Automated Security Practices
- Automating security testing with Gauntlt
- Conducting automated security attacks
Automating Application Security
- Automating and refactoring Cross-Site Scripting (XSS) attacks
- Automating SQL Injection (SQLi) attacks
- Automating fuzz testing
- Integrating security testing into software delivery pipelines for government
Summary and Next Steps
Requirements
- An understanding of the DevOps process for government
Audience
- DevOps professionals in the public sector
Runs with a minimum of 4 + people. For 1-to-1 or private group training, request a quote.
DevSecOps Training Course - Booking
DevSecOps Training Course - Enquiry
DevSecOps - Consultancy Enquiry
Consultancy Enquiry
Testimonials (1)
There were many practical exercises supervised and assisted by the trainer
Aleksandra - Fundacja PTA
Course - Mastering Make: Advanced Workflow Automation and Optimization
Upcoming Courses
Related Courses
Advanced Zapier: Custom Integrations and Multi-Step Automations
14 HoursSmart Workflow Automation: AI & Machine Learning with Make
14 HoursAPI Integrations with Make: Advanced Automation
14 HoursBuilding Efficient Workflows with Zapier
14 HoursThis instructor-led, live training in US (online or onsite) is aimed at intermediate-level professionals who wish to create and optimize automated workflows using Zapier for government operations.
By the end of this training, participants will be able to:
- Design and implement efficient Zapier workflows for government.
- Integrate multiple business applications for seamless automation.
- Optimize Zap performance and troubleshoot common issues.
- Scale workflow automation to meet the needs of public sector operations.
Mastering Make: Advanced Workflow Automation and Optimization
14 HoursMake for App Integration: Automating Business Workflows
14 HoursMake for Data Integration
14 HoursMake for DevOps
14 HoursMake for eCommerce: Automating Sales and Inventory Management
14 HoursMake Fundamentals: Introduction to Workflow Automation
7 HoursMake for Marketing Automation
14 HoursThis instructor-led, live training in US (online or onsite) is designed for intermediate-level marketing professionals who aim to automate repetitive tasks, effectively nurture leads, and optimize customer engagement through workflow automation.
By the end of this training, participants will be able to:
- Utilize Make to automate marketing campaigns and lead nurturing workflows.
- Develop personalized customer journey maps using integrated platforms.
- Synchronize data across various marketing tools such as Mailchimp, HubSpot, and social media platforms.
- Monitor and analyze automated workflows to enhance campaign performance.
- Implement best practices for scalable marketing automation strategies, ensuring alignment with public sector workflows and governance standards for government.