Building Your First DevSecOps Pipeline in AWS
2h 4mIntermediate2024-10-17
Authors

Tim Chase
Director of Application Security and Architecture at Nielsen
Course details
DevSecOps is one of the most important parts of a modern development program, and an essential skill for engineers and developers. With the move to the cloud, speed and agility have become essential to building and securing effective applications. And while there are a number of options available on the market, many companies opt to use AWS as their primary cloud due to its maturity and broad offering of products. In this course, join instructor Tim Chase as he explores the different parts of a modern DevSecOps pipeline and how they can be built natively using AWS tools and services. Along the way, gather insights and tips on integrating additional security tools into your pipeline when AWS native isn’t available.
Learning objectives
Understand the importance of DevSecOps.
Build a DevSecOps pipeline in AWS using native tools.
Integrate additional security tools into an AWS DevSecOps pipeline.
Measure the success of a DevSecOps program, track program metrics, and make improvements, as needed.
Learning objectives
Understand the importance of DevSecOps.
Build a DevSecOps pipeline in AWS using native tools.
Integrate additional security tools into an AWS DevSecOps pipeline.
Measure the success of a DevSecOps program, track program metrics, and make improvements, as needed.
Skills covered
Application SecurityDevOps FoundationsAmazon Web Services (AWS)AmazonDevOpsCybersecurityOne-Off
Concepts
0. Introduction
- 01 - Introduction to the Building Your First DevSecOps Pipeline in AWS course
- 02 - What you should know
1. DevSecOps in AWS Basics
- 03 - The importance of a DevOps pipeline
- 04 - Building a threat model in AWS
- 05 - Introduction to a software factory
- 06 - Building a software factory in AWS
- 07 - Storing your source code with AWS
- 08 - Building your infrastructure with infrastructure as code
- 09 - Building source code in AWS with CodeBuild
- 10 - Building a DevOps pipeline in AWS with CodePipeline
2. Building Security into the Pipeline
- 11 - Security testing code with CodeGuru
- 12 - Building vulnerability scanning into the pipeline
- 13 - Infrastructure as code scanning in the pipeline
- 14 - Integrating secrets scanning into DevSecOps
- 15 - Integrating IAST into the pipeline
- 16 - Monitoring cloud security posture
- 17 - Runtime monitoring
- 18 - Managing identities and entitlements
3. Next Steps
- 19 - Putting it all together
- 20 - Building out metrics to show success
- 21 - Continuous improvement of the DevSecOps pipeline
Conclusion
- 22 - Focus on the future