Skip to content

Course designed to to provide participants with the essential skills in the field of DevSecOps.

Notifications You must be signed in to change notification settings

opendevsecops/training-essential-aws-devsecops

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

33 Commits
 
 

Repository files navigation

Follow on Twitter Codacy Badge

Essential AWS DevSecOps

We believe in thinking differently about cybersecurity. We believe that DevSecOps is fundamentally changing the way we build and defend computer networks and we believe there is a skills shortage. The way we must tackle the problem of the skills shortage is by training up and inspiring people to pursue lucrative careers in DevSecOps. We designed a training course for DevSecOps and we will be delighted if you can join us to make this vision a reality.

Introduction

DevSecOps (sometimes referred to SecDevOps) is an approach to defensive cybersecurity where traditional Security Operation (SecOps) are subsidized with Development Operations (DevOps) typically performed by the same team. The advantage of this approach over traditional practices is that the subject networks and human processes become more resilient to attacks. This is largely due to automation, security-first planning, and resilience to changes that cause regressions.

It is a mistake to think of DevSecOps as simply an automated way to build software. This is a very common misconception indeed. While it is true that creating an automated development pipeline for delivering secure software continuously is part of the overall responsibilities, DevSecOps help us achieve a level security resilience unseen before. When you are thinking of DevSecOps, think of how to set up honeypot networks as part of your core infrastructure, or perhaps how to create hack-back capabilities, continuous target reconnaissance, fully automated monitoring and automated response to alerts and much more. All of these ideas are part of the DevSecOps process and philosophy.

The Course

This course is designed to expand your knowledge and perception of cloud security technologies and practices targeting AWS infrastructures specifically. You will learn not only how to build automated security processes for detection and active defense but also learn by example how attacks work too. The most important aspect of the course is to help participants become more independent and creative in solving challenging and building new technologies not covered by this course.

Syllabus

  1. Introduction To AWS
  • Core Concepts
  • Identity and Access Management
  • Setup, Architecture & Networking
  • Audit and Monitoring
  • Tools and Services
  1. AWS Security Principles
  • Security Internals
  • Attacks (OfSecDevOps)
  • Defense (DevSecOps)
  1. Automation
  • Scripting and SDKs
  • CloudFormation and Terraform
  1. Labs
  • Building security resilient infrastructures
  • Building automated recon and hacking

Extras

You will get your own personal AWS account which you will be using during the course. We will help you set it up and delete it if no longer required. We will also help you set up your GitHub account and build your portfolio of DevSecOps projects.

Instructors

pdp

pdp is founder and leading member of the GNUCITIZEN Information Security Think Tank. He is a recognized information security researcher, security tools developer, penetration tester, a frequent speaker at industry recognized events, and published author who has contributed to several best-selling books, numerous popular blogs, and online magazines.

Signup

Fill the form and we will contact you shortly.

Register Now
▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇▇

About

Course designed to to provide participants with the essential skills in the field of DevSecOps.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published