DevSecOps Training

  • Learn via: Classroom / Virtual Classroom / Online
  • Duration: 3 Days
  • We can host this training at your preferred location. Contact us!
Upcoming Training

01 July 2022

3 Days

In this hands-on training, participants will be using various open-source tools and scripts to automate security in a fast-moving DevOps culture where things happen quickly and continuously.

By integrating practices such as Continuous Integration (CI), Continuous Delivery (CD), Continuous Monitoring (CM), and Infrastructure as Code, modern companies are implementing the technological and cultural changes required to embrace DevOps approach (IaC). DevSecOps extends DevOps by including security into each of these principles, ensuring that the final product is secure. In this course, we'll show you how to infuse security into CI, CD, CM, and IaC using our cutting-edge DevSecOps Lab.

This popular hands-on course requires only a browser to participate. The DevSecOps Lab, created using Vagrant and Ansible and containing numerous open-source tools and scripts to assist DevOps engineers in automating security inside their CI/CD pipeline, will be distributed to attendees.

Attendees will receive a DevSecOps-Lab VM that has all of the code, scripts, and tools needed to build the whole DevSecOps pipeline.

Anybody with a background in IT or related to software development whether a developer or a manager can attend this course to get an insight about DevOps and DevSecOps.

In the DevSecOps course, you'll learn:

  • How how to tackle security issues in a fast-paced DevOps environment
  • Identifying tools/solutions and developing processes to create a secure by default infrastructure
  • Utilizing the integration scripts and tools provided in the DevSecOps Lab to create your own DevSecOps pipeline

Day 1

Lab Setup

  • Online Lab Setup
  • Offline Lab Instructions

Introduction to DevOps

  • What is DevOps?
  • Lab : DevOps Pipeline

Introduction to DevSecOps

  • Challenges for Security in DevOps
  • DevOps Threat Model
  • DevSecOps – Why, What and How?
  • Vulnerability Management

Continuous Integration

Pre-Commit Hooks

  • Introduction to Talisman
    • Lab : Running Talisman
    • Lab : Create your own regexes for Talisman

Secrets Management

  • Introduction to HashiCorp Vault
  • Demo : Vault Commands

Continuous Delivery

  • Software Composition Analysis (SCA)
    • Introduction to Dependency-Check
    • Lab : Run Dependency-Check pipeline
    • Lab : Fix issues reported by Dependency-Check
  • Static Analysis Security Testing (SAST)
    • Introduction to Semgrep
    • Lab : Run Semgrep pipeline
    • Lab : Create your own Semgrep Rules
    • Lab : Fix Issues reported by Semgrep
  • Dynamic Analysis Security Testing (DAST)
    • Introduction to OWASP ZAP
    • Demo : Creating ZAP Context File
    • Lab : Run ZAP in pipeline

Day 2

Infrastructure As Code

  • Vulnerability Assessment (VA)
    • Introduction to OpenVAS
    • Lab : Run OpenVAS pipeline
  • Container Security (CS)
    • Introduction to Trivy
    • Lab : Run Trivy in Pipeline
    • Lab : Improvise Docker base image
  • Compliance as Code (CaC)
    • Introduction to Inspec
    • Lab : Run Inspec in Pipeline
    • Lab : Improvise Docker compliancy controls

Continuous Monitoring

  • Logging
    • Introduction to the ELK Stack
    • Lab : View Logs in Kibana
  • Alerting
    • Introduction to ElastAlert and ModSecurity
    • Lab : View Alerts in Kibana
  • Monitoring
    • Lab : Create Attack Dashboards in Kibana

DevSecOps in AWS

  • DevOps on Cloud Native AWS
  • AWS Threat Landscape
  • DevSecOps in Cloud Native AWS

DevSecOps Challenges and Enablers

  • Challenges with DevSecOps
  • Building DevSecOps Culture
  • Security Champions
  • Case Studies
  • Where do we Begin?
  • DevSecOps Maturity Model


Contact us for more detail about our trainings and for all other enquiries!

Upcoming Trainings

Join our public courses in our Istanbul, London and Ankara facilities. Private class trainings will be organized at the location of your preference, according to your schedule.

01 July 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
04 July 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
06 August 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
14 August 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
12 September 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
24 September 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
05 October 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London
08 October 2022

Classroom / Virtual Classroom

Istanbul, Ankara, London

Related Trainings

By using this website you agree to let us use cookies. For further information about our use of cookies, check out our Cookie Policy.