Course Outline
Introduction
- Understanding how DevOps increases organizational security risks
- The trade-offs of agility, speed, and decentralized control
Limitations of Traditional Security Tools
- Static security policies
- Firewall rules
- Lack of APIs for integration
- Absence of visualization tools
Implementing a DevOps-Ready Security Program
Aligning Security with Business Objectives
Eliminating Security Bottlenecks
Establishing Detailed Visibility
Standardizing Security Configurations
Integrating Sensors into Applications
- Interactive Application Security Testing (IAST)
- Runtime Application Self-Protection (RASP)
Sharing Security Data with DevOps Tools via RESTful APIs
Enabling On-Demand Scaling and Micro-Perimeterization of Security Controls
Implementing Per-Resource Granular Security Policies
Automating Attacks Against Pre-Production Code
Continuously Testing the Production Environment
Protecting Web Applications from an Agile/DevOps Perspective
Securing Containers and Cloud Infrastructures
Adopting Next-Generation Automated Security Tools
The Future of DevOps and Its Strategic Role in Security
Summary and Conclusion
Requirements
- Experience with DevOps.
- Foundational knowledge or interest in security.
Target Audience
- DevOps Engineers
- Security Engineers
Testimonials (2)
Craig was extremely involved in the training, always making sure we are paying attention, adapted the examples to our day-to-day activities and always provided an answer when asked, even if the information was not added in the presentation.
Ecaterina Ioana Nicoale - BOOKING HOLDINGS ROMANIA SRL
Course - DevOps Foundation®
High level of commitment and knowledge of the trainer