Course Objectives
You will learn:
- The purpose, benefits, concepts, and vocabulary of DevSecOps How DevOps security practices differ from other security approaches Business
- driven security strategies and Best Practices Understanding and applying data and security sciences Integrating corporate stakeholders into DevSecOps Practices Enhancing communication between Dev, Sec, and Ops teams How DevSecOps roles fit with a DevOps culture and organization
Agenda
- Origins of DevOps
- Evolution of DevSecOps
- CALMS
- The Three Ways
- What is the Cyber Threat Landscape?
- What is the threat?
- What do we protect from?
- What do we protect, and why?
- How do I talk to security?
- Demonstrate Model
- Technical, business and human outcomes
- What’s being measured?
- Gating and thresholding
- The DevSecOps State of Mind
- The DevSecOps Stakeholders
- What’s at stake for who?
- Participating in the DevSecOps model
- Start where you are
- Integrating people, process and technology and governance
- DevSecOps operating model
- Communication practices and boundaries
- Focusing on outcomes
- The Three Ways
- Identifying target states
- Value stream-centric thinking
- The goal of a DevOps pipeline
- Why continuous compliance is important
- Archetypes and reference architectures
- Coordinating DevOps Pipeline construction
- DevSecOps tool categories, types and examples
- Security Training Options
- Training as Policy
- Experiential Learning
- Cross-Skilling
- The DevSecOps Collective Body of Knowledge
- Preparing for the DevSecOps Foundation certification exam
FREE
Interested in course?
Course Type: Instructor Led