Locked
DevSecOps Training
Build and run delivery pipelines where security is integrated at every stage — secrets and dependencies caught early, SAST/DAST/IaC/container scans wired in, gates that cannot be bypassed, and remediation prioritized by real risk.
Engineers, DevOps, SRE, AppSec — anyone owning a CI/CD pipeline · ~50 min · 9 modules
This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 3 content.
What's inside
- 01~6 minWhat DevSecOps meansDevSecOps integrates automated security into every stage of delivery — commit, build, test, stage, provision, package, deploy. Shift-left so problems are caught where they are cheap to fix, not after they ship.
- 02~6 minSecure CI/CD pipelinesYour pipeline runs with privileged credentials and ships your code — it IS production. Gates that can be bypassed don't exist. Treat your build environment with the same rigor as your runtime.
- 03~6 minSecrets and dependency scanningSecrets in code happen — the goal is to catch them before they ever land in history. Dependency scanning catches the supply-chain side. SBOMs let you find a vulnerable component fast when the next CVE drops.
- 04~5 minSAST and DASTSAST reads code without running it. DAST attacks the running application from the outside. Together they cover what each one alone misses.
- 05~5 minIaC scanning and cloud misconfigurationThe most common root cause of cloud data exposure isn't sophisticated attack — it's misconfiguration. Catch insecure defaults in Terraform/Kubernetes/CloudFormation templates before they deploy.
- 06~4 minContainer securityContainers ship the same vulnerabilities as anything else, plus their base image, plus whatever you bake into a layer. Pin minimal bases, scan every build, run as non-root, keep secrets out of layers.
- 07~5 minGates, approvals, and branch protectionBranch protection on main, required code review, no self-approval, no skip-CI, no allow_failure on security jobs. Gates are only gates if they cannot be bypassed.
- 08~6 minRemediation SLAs and prioritizationSeverity is the starting point, not the answer. Real prioritization weighs reachability, exposure, and known exploitability. Define SLAs by severity but order work by real risk.
- 09~5 minA DevSecOps checklist for your pipelineA practical checklist to score your CI/CD against. Customize for your stack. Tie back to {{team}}, {{policyLink}}, and your incident path at {{reportingEmail}}.