DevSecOps Foundation ℠: Integrating Security Best Practices into DevOps
Security should not wait until the final delivery stage. Bring development, operations and security together through DevSecOps to integrate controls into team practices. Develop a shared understanding of responsibilities and practices that support better-controlled delivery.
- Duration
- 2 days 14 hours
- Code
- DSOF Code
- Certification
- DevSecOps Foundation ℠ Certification
Accredited training for the DevSecOps Foundation ℠ certification.
Presentation
In the digital age, businesses develop software faster and more frequently than ever, while security vulnerabilities continue to emerge. DevSecOps practices add business and security value to DevOps projects as a strategic element in their own right. Delivering development, security and operations at the speed of business is essential for a modern organisation.
Our DevSecOps Foundation course explains how DevSecOps security principles differ from other approaches and provides the knowledge to implement this strategy in a business. You will explore its objectives, benefits, principles, terminology and automation tools. In particular, you will learn how DevSecOps responsibilities align with DevOps culture and organisation.
By the end of the course, you will have the knowledge and technical skills to understand and apply the Development | Security | Operations approach. During the final half-day, you will also take the DSOF exam from the DevOps Institute.
Objectives
By the end of this DevSecOps Foundation course, you will be able to:
- understand DevSecOps objectives, benefits, principles and technical terminology;
- understand how DevOps security procedures differ from traditional procedures;
- explore IT security strategies and good practices to implement within an organisation;
- understand and apply data science principles to secure data;
- engage all business stakeholders in DevSecOps activities;
- strengthen communication between development, security and operations teams;
- understand how DevSecOps activities align with DevOps culture and organisation;
- take the DSOF (V2.0) exam and earn DevOps Institute® DevSecOps Foundation certification.
Program
The DevSecOps value stream:
- the origins of DevOps;
- DevSecOps developments;
- implementing the CALMS model;
- continuous improvement.
The cyberthreat landscape:
- an overview of the cyberthreat environment;
- types of IT threats;
- what are we protecting against?
- assets to protect and the rationale for protection;
- communicating with security.
The DevSecOps operating model:
- the 3 pillars of the DevSecOps model;
- technical, business and human impacts;
- measurable value;
- triggering security thresholds and establishing limits.
DevSecOps culture:
- the DevSecOps mindset;
- business stakeholders;
- implications for those involved;
- participation in the DevSecOps operating model.
DevSecOps good practices:
- personal growth;
- integrating people, procedures and digital tools;
- establishing governance;
- implementing the operating model;
- communication methods and techniques;
- focusing on outcomes.
The DevOps pipeline and compliance:
- the purpose of a DevOps pipeline;
- continuous compliance;
- topologies and reference architectures;
- coordinating DevOps pipeline implementation;
- DevSecOps automation tools and their uses.
Learning from outcomes:
- additional IT security training;
- training policy;
- learning through experience;
- cross-functional skills;
- the DevSecOps body of knowledge.
Exam preparation:
- exam prerequisites;
- question weighting and terminology list.
Taking the official DevSecOps Foundation (DSOF) exam:
- exam type: 40 multiple-choice questions;
- duration: 1 hour;
- availability: online;
- open book: yes;
- language: English;
- pass mark: 65% correct answers.
Audience
This course is designed for:
- anyone seeking to learn more about DevOps strategies and automation;
- anyone interested in continuous delivery and DevOps collaboration tools;
- anyone wishing to explore security within a DevOps project.
Prerequisites
The DevSecOps Foundation (DSOF) course requires:
- understanding English to read the supplied documentation and take the DSOF v.2.0 exam;
- knowledge of DevOps principles, Lean IT principles or business agility is strongly recommended.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
A DevSecOps-certified instructor; preparation for the DevSecOps Foundation℠ exam; course materials and official DevOps Institute training; the certification exam included in the training price, with a free second attempt if you fail (Take2).
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Explore our brochure
DevOps Institute
fr
en
