Course : DevSecOps, state of the art and best practices

how to take your development to the next level

Seminar - 1d - 07h - Ref. DSF
Price : 940 € E.T.

DevSecOps, state of the art and best practices

how to take your development to the next level



DevOps multiplies code deployments, often broken down into containerized microservices in different clouds. Searching for the origin of a security flaw in this multiplicity of ever-changing "white boxes" is a real challenge. DevSecOps means taking security into account as early as possible.


INTER
IN-HOUSE
CUSTOM

In person or remote class
Available in English on request

Ref. DSF
  1d - 07h
940 € E.T.




DevOps multiplies code deployments, often broken down into containerized microservices in different clouds. Searching for the origin of a security flaw in this multiplicity of ever-changing "white boxes" is a real challenge. DevSecOps means taking security into account as early as possible.


Teaching objectives
At the end of the training, the participant will be able to:
Understand the DevSecOps development cycle for container-based architectures deployed in the cloud
Understand the types of testing and associated tools that can be integrated into a DevSecOps cycle
Be able to plan the transition from a DevOps organization to a DevSecOps organization

Intended audience
HR managers, CIOs, CISOs, security managers, project managers, consultants, administrators.

Prerequisites
Basic knowledge of the DevOps development cycle.

Course schedule

1
What is DevSecOps?

  • The DevOps development cycle. The different environments (development, test, production).
  • DevOps with security taken into account at the end of the development cycle.
  • Slide the safety tests to the left.
  • The DevSecOps development cycle.

2
DevSecOps and distributed container architectures

  • Container principles. Their benefits for continuous deployment.
  • Container flexibility. Security advantages and disadvantages.
  • Integrate code analysis into the development pipeline. Test container security.
  • Test the security of the production environment. Log analysis tools, SIEM. Feedback to developers.

3
The real challenges of taking safety into account

  • The skills gap. DevOps team members are not security experts.
  • The security team is separated from the DevOps team.
  • Correctly use the security features offered by the supplier.
  • Transient containers and microservices are difficult to monitor. The Aqua.
  • Cloud deployment risks. Resource configuration.
  • Legacy applications and how to take them into account in the development cycle.

4
Best practices for the transition to DevSecOps

  • Managing change. Roles involved, organizational issues, training plan, action plan.
  • Cloud security best practices. CSA standards. ENISA risks.
  • Evaluate the security of your cloud providers. Take account of your supplier's security SLAs.
  • Integrate security locks that make it impossible to deploy an unsecured environment.
  • Pushing automation all the way to Infrastructure as Code (IaC). Integrate system and security teams.
  • Automate continuous monitoring.
  • Integrate monitoring of vulnerability announcements (especially for open source software).


Publication date : 07/24/2024