DevSecOps practices are an extension to standard DevOps practices, focusing on automating security and incorporating it as part of the process, which includes Continuous Delivery, Infrastructure-as-Code (IaC), and observability. Use of DevSecOps results not only in delivering safer code faster, but also facilitates early feedback to developers, helping them build more reliable software. This course explores implementing DevSecOps practices into the software delivery pipeline using open source software.
This course is designed for software developers, site reliability engineers, and DevOps practitioners looking to speed up delivery of more secure code. To make the most of this course, learners must have working knowledge of Linux operating systems and the command line interface, Git, Docker, and Kubernetes. They must also know how to build CI/CD pipelines, write Infrastructure-as-Code (IaC), run Ansible Playbooks, and understand observability concepts such as log management and monitoring.
This course begins by laying the foundation of DevSecOps, explaining the principles, practices, cultural aspects and tooling landscape. It then goes on to show you how to incorporate various practices into the Continuous Delivery pipeline: perform Software Composition Analysis (SCA) and add it to the Continuous Integration pipeline, perform static code analysis and project gating using SAST tools, implement security best practices while writing Dockerfiles to build images, scan container images for vulnerability, perform Dynamic Application Software Testing (DAST) on a live environment, set up a centralized vulnerability management system to provide visibility and alerting, and build a cloud native DevSecOps pipeline. You will also use IaC effectively to enforce compliance, collect logs, analyze events to provide detection and monitoring of security issues, and learn to address cloud and container related risks. In order to make adoption of DevSecOps practices frictionless, this course focuses on usage of mostly open source software, at the same time providing enough flexibility to plug in a commercial alternative to match the implementation environment.
This course prepares you with real life professional skills to implement DevSecOps practices into the software development and delivery processes.
Good content. It gave me good exposure to different tools I was not aware of in the industry.
This course makes me well-informed to start securing my environment.
The exercises were really great, I learned a lot, and the instructor was inspiring, and very good.
I found all security aspects compiled in a single course, building from one topic to the other. I loved the complete spectrum that the student leaves with.
To make the most out of this course, you will need to:
To perform the hands-on lab exercises in this course, learners will need internet access, a web browser, Git, and a cloud provider account (e.g., Google Cloud Platform or AWS).
If using a cloud provider like GCP or AWS, you should be able to complete the lab exercises using the free tier or credits provided to you. However, you may incur charges if you exceed the credits initially allocated by the cloud provider, or if the cloud provider’s terms and conditions change.
Feel free to request a quote for corporate in-house programs or our upcoming open events. Write to us at info@meritglobaltraining.com
Build skills with experts anytime, anywhere. Keep up to date with the latest trends in your industry. Explore all of our courses and pick your suitable ones to enroll and start learning!
Hurry, Sale ends soon!
If you have any Queries about schedules Ask us here
More than 5 Participants ? Request for Corporate Training
Don't Miss Out On Amazing Benefits!
We revert you shortly
Should your enquiry be urgent, please mail us at info@meritglobaltraining.com or call us +971 50 205 6399 / +91 80885 11977 / +1 863-250-1577
We revert you shortly
Should your enquiry be urgent, please mail us at info@meritglobaltraining.com or call us +971 50 205 6399 / +91 80885 11977 / +1 863-250-1577