Hands-On Security in DevOps

PT22131
Summary
DevOps has provided speed and quality benefits with continuous development and deployment methods, but it does not guarantee the security of an entire organization. Hands-On Security in DevOps shows you how to adopt DevOps techniques to continuously improve your organization’s security at every level, rather than just focusing on protecting your infrastructure. This hands-on course combines DevOps and security to help you to protect cloud services, and teaches you how to use techniques to integrate security directly in your product. You will learn how to implement security at every layer, such as for the web application, cloud infrastructure, communication, and the delivery pipeline layers. With the help of practical examples, you’ll explore the core security aspects, such as blocking attacks, fraud detection, cloud forensics, and incident response. In the final modules, you will cover topics on extending DevOps security, such as risk assessment, threat modeling, and continuous security. By the end of this course, you will be well-versed in implementing security in all layers of your organization and be confident in monitoring and blocking attacks throughout your cloud services.
  • Integrate security at each layer of the DevOps pipeline
  • Discover security practices to protect your cloud services by detecting fraud and intrusion
  • Explore solutions to infrastructure security using DevOps principles
Prerequisites
Before taking this course, students should have a background in IT or software development.
Duration
5 Days/Lecture & Lab
Audience
Anybody with a background in IT or related to software development whether a developer or a manager can attend this course to get an insight about DevOps and DevSecOps. DevOps engineers, security and solutions architects, system administrators will also strongly benefit from this course as it’ll give them a holistic approach towards application security.
Topics
  • DevSecOps Drivers and Challenges
  • Security Goals and Metrics
  • Security Assurance Program and Organization
  • Security Requirements and Compliance
  • Case Study - Security Assurance Program
  • Security Architecture and Design Principles
  • Threat Modeling Practices and Secure Design
  • Secure Coding Best Practices
  • Case Study - Security and Privacy by Design
  • Security-Testing Plan and Practices
  • Whitebox Testing Tips
  • Security Testing Toolkits
  • Security Automation with the CI Pipeline
  • Incident Response
  • Security Monitoring
  • Security Assessment for New Releases
  • Threat Inspection and Intelligence
  • Business Fraud and Service Abuses
  • GDPR Compliance Case Study
  • DevSecOps - Challenges, Tips, and FAQs

Related Scheduled Courses