Cybersecurity Specialization: DevSecOps
- Código del Curso GK840102
- Duración 3 días
- Idioma English
Otros Métodos de Impartición
Método de Impartición
Este curso está disponible en los siguientes formatos:
-
Cerrado
Cerrado
-
Clase de calendario
Aprendizaje tradicional en el aula
-
Aprendizaje Virtual
Aprendizaje virtual
Solicitar este curso en un formato de entrega diferente.
Temario
Parte superiorLearn how to integrate security within DevOps
DevSecOps is designed to empower you with the knowledge and skills necessary to seamlessly integrate security into your DevOps pipeline. You will gain a deep understanding of DevSecOps principles and practices, ensuring that security is an integral part of your software development lifecycle (SDLC). By mastering continuous security testing methods and tools, you will be equipped to identify and address vulnerabilities early, enhancing the overall security posture of your applications.
Learn the knowledge and tools to ensure continuous security and compliance, safeguarding your software solutions from potential threats.
Our Cybersecurity Specialization courses follow the 9 pillars of Cybersecurity, providing key skills necessary to be successful as a cybersecurity professional.
Virtual Learning
This interactive training can be taken from any location, your office or home and is delivered by a trainer. This training does not have any delegates in the class with the instructor, since all delegates are virtually connected. Virtual delegates do not travel to this course, Global Knowledge will send you all the information needed before the start of the course and you can test the logins.
Calendario
Parte superior-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 19-21 mayo, 2025
- Sede: Aula Virtual
- Idioma: Inglés
-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 30 junio-02 julio, 2025
- Sede: Aula Virtual
- Idioma: Inglés
-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 11-13 agosto, 2025
- Sede: Aula Virtual
- Idioma: Inglés
-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 22-24 septiembre, 2025
- Sede: Aula Virtual
- Idioma: Inglés
-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 03-05 noviembre, 2025
- Sede: Aula Virtual
- Idioma: Inglés
-
- Método de Impartición: Aprendizaje Virtual
- Fecha: 10-12 diciembre, 2025
- Sede: Aula Virtual
- Idioma: Inglés
Objetivos del Curso
Parte superior- Understand DevSecOps principles and practices to integrate security within the DevOps pipeline
- Master secure software development lifecycle (SDLC) techniques
- Get familiar with continuous security testing methods and tools to identify vulnerabilities early
- Enhance secure coding practices by understanding common vulnerabilities and how to mitigate them.
- Advanced threat modeling and risk assessment strategies
- Implement best practices for container security using container orchestration tools.
- Leverage Infrastructure as Code (IaC) security to secure infrastructure from the ground up
- Master identity and access management (IAM) principles to manage user identities and permissions securely
- Get hands-on experience with application security testing (AST) tools to uncover and remediate security flaws.
- Utilize security information and event management (SIEM) tools for real-time analysis of security alerts
- Develop strategies for effective incident response and digital forensics
- Understand compliance and regulatory requirements
- Enhancements to secure DevOps toolchains
- Integrate cloud-specific security services provided by major cloud providers to protect cloud-based applications and infrastructure.
- Interact with network security tools to safeguard network communications.
- Design professional scripts to automate security tasks and improve efficiency
- Query databases securely, ensuring data integrity and protection against database-related vulnerabilities.
- Process and protect sensitive data using security measures to ensure compliance with data protection laws and best practices.
Contenido
Parte superiorOverview of DevSecOps
- DevSecOps principles
- The DevOps lifecycle and security integration
- Key challenges in implementing DevSecOps
Security by Design
- Secure software development lifecycle (SSDLC)
- Threat modeling and risk assessment
- Best practices for secure coding
- Resources: OWASP Top Ten, NIST Cybersecurity Framework
Infrastructure as Code (IaC) Security
- Introduction to IaC and its benefits
- Security considerations for IaC
- Tools to Address : Terraform, Azure Resource Manager (ARM)
- Resources To be used: Terraform: HashiCorp Terraform, Azure ARM: Azure Documentation
Continuous Integration and Continuous Security
- Secure CI/CD pipeline design,
- Implementing Zero Trust in CI/CD Pipelines
- Incident Response and Recovery in CI/CD Pipelines"
- Integrating security tools into CI/CD pipelines
- Implementing Security Gates in CI/CD Pipelines"
- Tools to Cover: Jenkins, GitHub Actions, Azure DevOps
- Resources to use: Jenkins: Jenkins Documentation, GitHub Actions: GitHub Actions
Application Security Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Tools: SonarQube, OWASP ZAP, Other SAST Tools (Checkmarx, Veracode), Other DAST Tools (Burp Suite, Acunetix)
- Resources: SonarQube: SonarQube Documentation, OWASP ZAP: OWASP ZAP Documentation
Container Security
- Securing Docker images and containers
- Best practices for container security
- Tools: Docker, Aqua Security. Kubernetes Security
- Resources: Docker: Docker Documentation, Trivy: Aqua Trivy Documentation
Monitoring and Logging
- Importance of monitoring and logging in security
- Tools for monitoring and logging: ELK Stack, Prometheus, Grafana, SIEM (Security Information and Event Management), Grafana for Visualizing Security Metrics
- Resources: ELK Stack: Elastic Documentation, Prometheus: Prometheus
Incident Response and Forensics
- Incident response planning and execution
- Forensic analysis and post-incident review
- Tools: Splunk, Wireshark, SOAR (Security Orchestration, Automation, and Response), Volatility
- Resources: Splunk: Splunk Documentation, Wireshark: Wireshark Documentation
Compliance and Governance
- Understanding security compliance requirements
- Implementing security policies and governance
- Standards: GDPR, HIPAA, PCI-DSS, CCPA (California Consumer Privacy Act)
- Resources: GDPR: EU GDPR Information, HIPAA: HIPAA Journal, PCI-DSS: PCI Security Standards Council
Data Security and Privacy
- Protecting sensitive data
- Encryption techniques and key management
- Tools: Vault by HashiCorp, Azure Key Vault, Google Cloud Key Management Service (KMS), AWS Key Management Service (KMS),
- Resources: Vault: HashiCorp Vault Documentation, Azure Key Vault: Azure
Capstone Project
Pre-requisitos
Parte superior- Foundational Knowledge of DevOps: Participants should have a basic understanding of DevOps principles and practices.
- Basic Security Concepts: Familiarity with fundamental cybersecurity concepts is required.
- Experience with CI/CD Pipelines: Prior experience setting up and using Continuous Integration/Continuous Deployment (CI/CD) pipelines.
- Scripting Knowledge: Experience writing scripts in languages such as Python, Bash, or PowerShell.
- Operating System Proficiency: A working, user-level knowledge of Unix/Linux, Mac, or Windows.
- #000000