Get in Touch

Course Outline

1. DevSecOps Foundations: Security by Design

🔍 Learn: Fundamental principles of DevSecOps and secure software development life cycles (SDLC)

🛠️ Demo: Comparative analysis of legacy versus modern secure engineering pipelines

🔧 Lab: Construct a foundational pipeline template for government applications

2. OWASP ZAP Security Testing Bootcamp

💣 Breach Simulation:

  • Deploy a simulated vulnerable application containing SQL injection and cross-site scripting (XSS) flaws
  • Utilize OWASP ZAP to identify and mitigate identified threats

⚙️ Defense Tactics:

  • Implement automated vulnerability scanning using ZAP
  • Integrate security testing into CI/CD workflows via the ZAP API

🧪 Lab: Customize baseline scans and define attack rules in ZAP

🎯 Challenge: Identify concealed administrative interfaces within a ten-minute timeframe

3. Dependency Hell: Supply Chain Defense

💣 Breach Simulation:

  • Inoculate the environment with a malicious npm package containing known CVEs to test detection capabilities

🛡️ Defense Tactics:

  • Monitor third-party dependencies for vulnerabilities using OWASP Dependency-Track
  • Establish policy gates that halt builds upon identification of critical CVEs

🧪 Lab: Develop vulnerability management policies and automated alerting workflows

⚠️ Shocking Demo: “Impact analysis: How a single compromised dependency can jeopardize infrastructure”

4. Vulnerability Management War Room

💣 Breach Simulation:

  • Exploit unpatched vulnerabilities within containerized environments

🛡️ Defense Tactics:

  • Centralize vulnerability data and reporting using OWASP DefectDojo
  • Perform container scanning with Trivy to ensure image integrity

🧪 Lab: Configure real-time dashboards for CISO and executive-level reporting

🏁 Competition: “Prioritize and triage fifty vulnerability findings under time constraints”

5. Secrets & Configuration Fire Drill

💣 Breach Simulation:

  • Detect unauthorized exfiltration of secrets from Git repositories using TruffleHog

🛡️ Defense Tactics:

  • Deploy pre-commit hooks to block hard-coded credentials matching patterns such as password=.*
  • Leverage ZAP’s configuration spider to identify unsafe application settings

🧪 Lab: Implement automated secrets scanning within GitHub Actions for government repositories

🚨 Reality Check: “Assessing exposure: The risk of sensitive credentials in collaborative platforms”

6. Wrap-Up: DevSecOps Battle Plan

🧭 OWASP Integration Roadmap:

  • Formulate a strategic plan for adopting DefectDojo, Dependency-Track, and ZAP within agency operations

📋 Personal Action Plan:

  • Develop a thirty-day security implementation checklist
  • Establish DevSecOps Key Performance Indicators (KPIs) and reporting structures for government oversight

Requirements

Demonstrated proficiency in core software development and the software development life cycle (SDLC).

Target Audience

DevOps, Security, and Cloud Engineering professionals seeking practical, non-theoretical security guidance

 7 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories