FΛForgeAwareness
Locked

DevSecOps Training

Build and run delivery pipelines where security is integrated at every stage — secrets and dependencies caught early, SAST/DAST/IaC/container scans wired in, gates that cannot be bypassed, and remediation prioritized by real risk.

Engineers, DevOps, SRE, AppSec — anyone owning a CI/CD pipeline · ~50 min · 9 modules

This course is part of the paid catalog. Purchase it individually, or unlock it with a membership that includes Tier 3 content.

What's inside

  1. 01
    What DevSecOps means
    DevSecOps integrates automated security into every stage of delivery — commit, build, test, stage, provision, package, deploy. Shift-left so problems are caught where they are cheap to fix, not after they ship.
    ~6 min
  2. 02
    Secure CI/CD pipelines
    Your pipeline runs with privileged credentials and ships your code — it IS production. Gates that can be bypassed don't exist. Treat your build environment with the same rigor as your runtime.
    ~6 min
  3. 03
    Secrets and dependency scanning
    Secrets in code happen — the goal is to catch them before they ever land in history. Dependency scanning catches the supply-chain side. SBOMs let you find a vulnerable component fast when the next CVE drops.
    ~6 min
  4. 04
    SAST and DAST
    SAST reads code without running it. DAST attacks the running application from the outside. Together they cover what each one alone misses.
    ~5 min
  5. 05
    IaC scanning and cloud misconfiguration
    The most common root cause of cloud data exposure isn't sophisticated attack — it's misconfiguration. Catch insecure defaults in Terraform/Kubernetes/CloudFormation templates before they deploy.
    ~5 min
  6. 06
    Container security
    Containers ship the same vulnerabilities as anything else, plus their base image, plus whatever you bake into a layer. Pin minimal bases, scan every build, run as non-root, keep secrets out of layers.
    ~4 min
  7. 07
    Gates, approvals, and branch protection
    Branch protection on main, required code review, no self-approval, no skip-CI, no allow_failure on security jobs. Gates are only gates if they cannot be bypassed.
    ~5 min
  8. 08
    Remediation SLAs and prioritization
    Severity is the starting point, not the answer. Real prioritization weighs reachability, exposure, and known exploitability. Define SLAs by severity but order work by real risk.
    ~6 min
  9. 09
    A DevSecOps checklist for your pipeline
    A practical checklist to score your CI/CD against. Customize for your stack. Tie back to {{team}}, {{policyLink}}, and your incident path at {{reportingEmail}}.
    ~5 min