DevSecOps: Building a Secure Continuous Delivery Pipeline
1h 12mBeginner2018-10-29
Authors

James Wickett
Security Engineer and supporter of rugged software and DevSecOps
Course details
Over the past several years, information security has struggled to keep up with the fast-paced DevOps movement. DevSecOps—an extension of DevOps—aims to remedy this by embracing security as an essential part of DevOps culture. This course examines this fresh take on DevOps, providing an overview of the practices and tools that can help you implement security across the entirety of the continuous integration and continuous delivery (CI/CD) pipeline. As instructor James Wickett looks at CI/CD through the lens of security, he breaks up the pipeline into five distinct stages: develop, inherit, build, deploy, and operate. As he moves through each of these stages, he provides an overview of best practices and tools that can fit nicely into your DevSecOps toolchain approach.
Learning objectives
Goals for a DevSecOps toolchain approach
Development, inherit, build, deploy, and operation tools
Keeping secrets with git-secrets
Using OWASP Dependency Check
Testing for dependency issues using Retire.js
Options for software composition analysis
Key security concerns for the deploy phase
Tricks for making compliance happy
Cloud configuration monitoring
Learning objectives
Goals for a DevSecOps toolchain approach
Development, inherit, build, deploy, and operation tools
Keeping secrets with git-secrets
Using OWASP Dependency Check
Testing for dependency issues using Retire.js
Options for software composition analysis
Key security concerns for the deploy phase
Tricks for making compliance happy
Cloud configuration monitoring
Skills covered
DevOps FoundationsDevOpsEssential Training
Concepts
0. Introduction
- 01 - Securing your CI CD pipeline
- 02 - What you should know
1. The DevSecOps Toolchain
- 03 - Traditional InfoSec is in crisis
- 04 - Introducing DevSecOps
- 05 - The continuous delivery pipeline
- 06 - Goals for a DevSecOps toolchain approach
2. Development Tools
- 07 - Secure development practices
- 08 - Static code analysis
- 09 - Tool - Keeping secrets with git-secrets
- 10 - Tool - Rapid Risk Assessment
3. Inherit Tools
- 11 - What's in your app
- 12 - OWASP Dependency Check in practice
- 13 - JavaScript security with Retire.js - Installation
- 14 - JavaScript security with Retire.js - Testing
- 15 - Options for software composition analysis
4. Build Tools
- 16 - Security testing in the build stage
- 17 - AppSec scanning with DAST tools
- 18 - Gauntlt in practice
5. Deploy Tools
- 19 - Security in the deploy phase
- 20 - Rundeck for deployments
- 21 - Tricks for making compliance happy
6. Operation Tools
- 22 - Keeping security in operate
- 23 - Modern application security
- 24 - Signal Sciences in practice
- 25 - Cloud security monitoring
Conclusion
- 26 - Next steps