DevSecOps Boot Camp

Improve your team's DevSecOps practice from guiding principles to daily technical execution

Led by a senior expert, teach your teams how to improve the DevSecOps practice – from guiding principles to daily technical execution.

This DevSecOps training boot camp is the most practical, in-depth educational solution for teams who want to understand, apply, and improve their skills on “shifting left” in IT security. This expert-led boot camp focuses on the principles, processes, and technical skills necessary to make security and risk profiling a front-end priority: embracing a “quality first” mindset. Teams will leave class understanding that they have a responsibility for how applications and IT services perform when they are complete and in production…even if they are involved primarily in design, development or testing applications. For IT teams primarily on the end of the operations of the spectrum, this class will teach them how to shift left and collaborate on the upstream work that ultimately impacts the IT security environment, the organisation’s risk management, and their own daily jobs.

Learning Objectives

  • Assess, specify and automate much of the work associated with application security
  • Bridge the typical functional silos in IT that prevent proactive security practices
  • Translate common risks into technical use cases and software requirements
  • Apply “security first” engineering and testing practices throughout the entire application pipeline
  • Use static analysis, broader unit test coverage, and code quality reviews specifically for security
  • Translate the OWASP risks into practical, actionable software development best practices
  • Deploy for security
  • Tie secure development practices and automated engineering to GRC and audit requirements
  • Try new approaches to change management for increased speed, automation, and security
  • Use DevOps-style metrics to measure and monitor security practices and performance
  • Promote the cultural practices that lead to improved responsibility for security outcomes

Topics covered

  • DevOps, Security, and DevSecOps: Definitions
  • Where do we start with security?
  • Security as a DevOps practice
  • DevSecOps and “requirements”
  • Secure development patterns
  • Security Testing in the Pipeline
  • Identity and Access Management (IAM)
  • Deployment patterns for security
  • DevSecOps and Operations
  • Policy, Governance, and Audit
  • Change management and DevSecOps
  • Measurement and metrics
  • More advice on the cultural factors
  • Putting it all together

You'll also receive

  • Trainer who is a senior expert
  • Electronic copy of the course materials

Trainer