Implementing DevSecOps (LFS262)

Logo The Linux Foundation Authorized Training Partner

This course begins by laying the foundation of DevSecOps, explaining the principles, practices, cultural aspects and tooling landscape. It then goes on to show you how to incorporate various practices into the Continuous Delivery pipeline: perform Software Composition Analysis (SCA) and add it to the Continuous Integration pipeline, perform static code analysis and project gating using SAST tools, implement security best practices while writing Dockerfiles to build images, scan container images for vulnerability, perform Dynamic Application Software Testing (DAST) on a live environment, set up a centralized vulnerability management system to provide visibility and alerting, and build a cloud native DevSecOps pipeline.

You will also use IaC effectively to enforce compliance, collect logs, analyze events to provide detection and monitoring of security issues, and learn to address cloud and container related risks. In order to make adoption of DevSecOps practices frictionless, this course focuses on usage of mostly open source software, at the same time providing enough flexibility to plug in a commercial alternative to match the implementation environment.

Pr贸ximos inicios

No disponibles en este momento.
Objetivos

This course prepares you with real life professional skills to implement DevSecOps practices into the software development and delivery processes.

Requisitos

To make the most out of this course, you will need to:

  • Have working knowledge of Linux operating systems and the command line interface, Git, Docker, and Kubernetes.
  • Know how to build CI/CD pipelines, write Infrastructure-as-Code (IaC), run Ansible Playbooks, and understand observability concepts such as log management and monitoring.
Contenidos

Module 1: Course Introduction

Module 2: What Is DevSecOps?

Module 3: Setting Up the Lab Environment

Module 4: Building a DevOps Pipeline

Module 5: Securing the Supply Chain with SCA

Module 6: Static Application Security Testing (SAST)

Module 7: Auditing Container Images

Module 8: Secure Deployment and Dynamic Application Security Testing (DAST)

Module 9: System Security Auditing with IAC

Module 10: Securing Kubernetes Deployments

Module 11: Secrets Management with Vault

Module 12: Runtime Security Monitoring and Remediation

Material del curso
  • Documentaci贸n Oficial de This course Implementing DevSecOps (LFS262)
Perfil del docente
  • Formador Certificado por The linux Foundation
  • M谩s de 5 a帽os de experiencia profesional
  • M谩s de 4 a帽os de experiencia docente
  • Profesional activo en empresas del sector IT
Beneficios para tu formaci贸n

Haz click aqu铆 y descubre los descuentos, promociones y ayudas disponibles para tu formaci贸n tecnol贸gica.

Solicitar informaci贸n
Partner oficial de los principales fabricantes tecnol贸gicos

The Swirl Logo es una marca registrada del grupo PeopleCert庐. Utilizada bajo licencia de PeopleCert庐. Todos los derechos reservados.