Building Your First DevSecOps Pipeline in AWS

Building Your First DevSecOps Pipeline in AWS

2h 4mIntermediate2024-10-17

Authors

Tim Chase

Tim Chase

Director of Application Security and Architecture at Nielsen

Course details

DevSecOps is one of the most important parts of a modern development program, and an essential skill for engineers and developers. With the move to the cloud, speed and agility have become essential to building and securing effective applications. And while there are a number of options available on the market, many companies opt to use AWS as their primary cloud due to its maturity and broad offering of products. In this course, join instructor Tim Chase as he explores the different parts of a modern DevSecOps pipeline and how they can be built natively using AWS tools and services. Along the way, gather insights and tips on integrating additional security tools into your pipeline when AWS native isn’t available.

Learning objectives
Understand the importance of DevSecOps.
Build a DevSecOps pipeline in AWS using native tools.
Integrate additional security tools into an AWS DevSecOps pipeline.
Measure the success of a DevSecOps program, track program metrics, and make improvements, as needed.

Skills covered

Application SecurityDevOps FoundationsAmazon Web Services (AWS)AmazonDevOpsCybersecurityOne-Off

Concepts

Introduction

  • Introduction to the Building Your First DevSecOps Pipeline in AWS course
  • What you should know

DevSecOps in AWS Basics

  • The importance of a DevOps pipeline
  • Building a threat model in AWS
  • Introduction to a software factory
  • Building a software factory in AWS
  • Storing your source code with AWS
  • Building your infrastructure with infrastructure as code
  • Building source code in AWS with CodeBuild
  • Building a DevOps pipeline in AWS with CodePipeline

Building Security into the Pipeline

  • Security testing code with CodeGuru
  • Building vulnerability scanning into the pipeline
  • Infrastructure as code scanning in the pipeline
  • Integrating secrets scanning into DevSecOps
  • Integrating IAST into the pipeline
  • Monitoring cloud security posture
  • Runtime monitoring
  • Managing identities and entitlements

Next Steps

  • Putting it all together
  • Building out metrics to show success
  • Continuous improvement of the DevSecOps pipeline

Conclusion

  • Focus on the future
40,000 Toman