Practical DevSecOps Instructor Led Training
Event Information
About this Event
Practical DevSecOps Instructor-led Training
About Practical DevSecOps
Practical DevSecOps (a Hysn Technologies Inc company) offers vendor-neutral, practical, and hands-on DevSecOps training and certification programs for IT Professionals. Our online training and certifications are focused on modern areas of information security, including DevOps Security, Cloud-Native Security, Cloud Security & Container security. The certifications are achieved after rigorous tests(12-24 hour exams) of skill and are considered the most valuable in the information security field.
We are excited to announce our instructor-led training weeks for this year in Singapore and we would be running three courses.
DevSecOps Professional Course (2 Days) - 16 to17 March 2020
DevSecOps Expert Course (3 days) - 23 to 25 March 2020
DevSecOps Architect Course (5 days) - 23 to 27 March 2020
P.S All Prices are in SGD (not in USD)
Course Syllabus
DevSecOps Professional Course - 2 days (16-17 March)
Syllabus
- Introduction to DevOps and DevSecOps
- Introduction to the Tools of the trade
- Secure SDLC and CI/CD pipeline
- Software Component Analysis(CSA) in CI/CD pipeline
- SAST (Static Analysis) in CI/CD pipeline
- DAST (Dynamic Analysis) in CI/CD pipeline
- Infrastructure as Code and Its Security
- Compliance as code
- Vulnerability Management with custom tools.
DevSecOps Expert Course - 3 days (23-25 March)
- Overview of DevSecOps.
- Introduction to the Tools of the trade.
- Secure SDLC and CI/CD pipeline.
- Security Requirements and Threat Modelling (TM).
- Software Component Analysis (SCA)
- Advanced Static Analysis(SAST) in CI/CD pipeline.
- Advanced Dynamic Analysis(DAST) in CI/CD pipeline.
- Runtime Analysis(RASP/IAST) in CI/CD pipeline.
- Infrastructure as Code(IaC) and Its Security.
- Container (Docker) Security.
- Secrets management on mutable and immutable infra
- Vulnerability Management with custom tools.
DevSecOps Architect Course - 5 days (23-27 March)
- Overview of DevSecOps
- Overview of DevSecOps on AWS
- Attacking and Auditing modern DevOps systems
- Introduction to Amazon Web Services
- Identity and Access Management (IAM)
- Compute services in AWS
- Data security in AWS
- Network Security in AWS
- Infrastructure as Code(IaC) and Its Security
- Patch Management and Security Monitoring
- Compliance in AWS
What students will be provided
The students will be provided with
- Training manuals and lab guide.
- Tools used during the course.
- 30 days online lab setup.
- CDP/CDE/CDA certification attempt.
- Access to slack channel.
What will students learn
- Start or mature your application security program using DevOps practices
- Learn how to co-relate vulnerabilities to scale false positive analysis using automated tools.
- Harden infrastructure using Infrastructure as Code and maintain compliance using Compliance as Code tools and techniques.
Who should take this course
This course is aimed at anyone who is looking to embed security as part of agile/cloud/DevOps environments:
- Security Professionals
- Penetration Testers
- IT managers
- Developers
- DevOps Engineers
Student Requirements
The student should have some knowledge of running basic linux commands like ls, cd, mkdir etc.,
The student should have some basic understanding of application Security practices like OWASP Top 10 though not a necessity.
Students who want to attend DevSecOps Expert course should have either CDE or CDP Certification or have taken our CDE course before.
Software and Hardware Requirements
- Our state of the lab is deployed on our cloud labs so you would need the following to connect to the lab environment.
- Laptop with decent specs
- AWS Free-tier Account access is required for Architect course
About Trainer
Mohammed A. "secfigo" Imran is the Founder of Practical DevSecOps, a DevSecOps Training and Certification company. He has extensive experience in building and improving multiple organization's Information Security Programs. He has a diverse background in R&D, consulting and product-based industries with a passion to solve complex security programs. Imran is the founder of Null Singapore, the largest information security community in Singapore where he has organised more than 60 events & workshops to spread security awareness. He was also nominated as a community star for being the go-to person in the community whose contribution and knowledge sharing has helped many professionals in the security industry. He is usually seen speaking in conferences like Blackhat, DevSecCon, Null and OWASP chapters