Course Information
Course Name
DSOF: DEVOPS INSTITUTE® DevSecOps Foundation
Exam code
DSOF
Duration
2 Days
Certification
DEVOPS INSTITUTE® DevSecOps Foundation
Overview
As companies deploy code faster and more often than ever, new vulnerabilities are also accelerating. When the boss says, “Do more with less”, DevOps practices add business and security value as an integral, strategic component. Delivering development, security, and operations at the speed of business should be an essential component for any modern enterprise.
Course topics covered include how DevSecOps provides business value, enhancing your business opportunities, and improving corporate value. The core DevSecOps principles taught can support an organizational transformation, increase productivity, reduce risk, and optimize resource usage.
This course explains how DevOps security practices differ from other approaches then delivers the education needed to apply changes to your organization. Participants learn the purpose, benefits, concepts, vocabulary and applications of DevSecOps. Most importantly, students learn how DevSecOps roles fit with a DevOps culture and organization. At the course’s end, participants will understand “security as code” to make security and compliance value consumable as a service.
No course would be complete without practical application and this course teaches the steps to integrate security programs from the developers and operators through the business C-level. Every stakeholder plays a part and the learning material highlights how professionals can use these tools as the primary means of protecting the organization and customer through multiple case studies, video presentations, discussion options, and exercise material to maximize learning value. These real-life scenarios create tangible takeaways participants can leverage upon their return to the home office.
This course positions learners to pass the DEVOPS INSTITUTE® DevSecOps Foundation exam.
DEVOPS INSTITUTE® is a registered trademark of the PeopleCert group. Used under licence from PeopleCert. All rights reserved.
Audience Profile
The target audience for the DEVOPS INSTITUTE® DevSecOps Foundation course are professionals including:
Anyone involved or interested in learning about DevSecOps strategies and automation
Anyone involved in Continuous Delivery toolchain architectures
Compliance Team
Business Managers
Delivery Staff
DevOps Engineers
IT Managers
IT Security Professionals, Practitioners, and Managers
Maintenance and Support Staff
Managed Service Providers
Project & Product Managers
Quality Assurance Teams
Release Managers
Scrum Masters
Site Reliability Engineers
Software Engineers
Testers
Prerequisites
Participants should have baseline knowledge and understanding of common DevOps definitions and principles.
At Course Completion
The learning objectives include a practical understanding of:
The purpose, benefits, concepts, and vocabulary of DevSecOps
How DevOps security practices differ from other security approaches
Business-driven security strategies and Best Practices
Understanding and applying data and security sciences
Integrating corporate stakeholders into DevSecOps Practices
Enhancing communication between Dev, Sec, and Ops teams
How DevSecOps roles fit with a DevOps culture and organization
Course Outline
Module 1: Realizing DevSecOps Outcomes
Origins of DevOps
Evolution of DevSecOps
CALMS
The Three Ways
Module 2: Defining the Cyberthreat Landscape
What is the Cyber Threat Landscape?
What is the threat?
What do we protect from?
What do we protect, and why?
How do I talk to security?
Module 3: Building a Responsive DevSecOps Model
What is the Cyber Threat Landscape?
What is the threat?
What do we protect from?
What do we protect, and why?
How do I talk to security?
Module 4: Integrating DevSecOps Stakeholders
The DevSecOps State of Mind
The DevSecOps Stakeholders
What’s at stake for who?
Participating in the DevSecOps model
Module 5: Establishing DevSecOps Best Practices
Start where you are
Integrating people, process and technology and governance
DevSecOps operating model
Communication practices and boundaries
Focusing on outcomes
Module 6: Best Practices to get Started
The Three Ways
Identifying target states
Value stream-centric thinking
Module 7: DevOps Pipelines and Continuous Compliance
The goal of a DevOps pipeline
Why continuous compliance is important
Archetypes and reference architectures
Coordinating DevOps Pipeline construction
DevSecOps tool categories, types and examples
Module 8: Learning Using Outcomes
Security Training Options
Training as Policy
Experiential Learning
Cross-Skilling
The DevSecOps Collective Body of Knowledge
Preparing for the DevSecOps Foundation certification exam
All DevOps Institute certification courses are conducted by certified trainers from Iverson.
Digital Methods acts as the official training partner and assists with program consultation, registration, coordination, scheduling, and administrative arrangements to ensure a seamless and professionally managed training experience.