|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/devsecops/
课程评论:没有评论
课程名称:DevSecOps:掌握CI/CD DevOps管道安全的实操课程 课程概述:本课程旨在帮助开发人员、DevOps工程师、安全专家、初学者、QA人员、基础设施工程师、构建与发布人员、IT专业人士以及信息安全/应用安全专业人士学习和实施DevSecOps方法论、工具和技术,结合安全最佳实践,为所在公司或项目提供安全保障。这将帮助你在未来的市场中获得高质量的工作,并获得更高的薪水,类似于当前 DevOps、云计算和安全领域的趋势。随着数字化成为所有公司成功的关键,DevSecOps的整合尤为重要。 课程内容包括: - 使用Jenkins及其他工具将安全集成到软件开发生命周期(SDLC)。 - 学习DevSecOps的基本技能、工具及流程,确保应用程序安全,重点关注: - 防止秘密和敏感数据意外泄露到源代码管理系统(SCM)。 - 识别、修复和打补丁应用程序依赖、Dockerfile、镜像及运行时应用程序中的漏洞。 - 确保构建、测试和部署过程的安全(Docker镜像、容器)。 - 使用威胁建模、单元和集成测试、软件成分分析(SCA)、静态应用漏洞扫描(SAST)、动态应用漏洞扫描(DAST)及集成测试进行安全测试。 每个主题将通过易于理解的视觉方式进行分解,课程将以幻灯片概述开始,随后是实际动手练习。学员将设置自己的工具、虚拟机、使用Jenkins进行CI/CD,并访问专用的GitHub代码片段库。 虽然具备以下基础知识是有帮助的,但并非必需:DevOps与Jenkins、Docker、安全、Linux虚拟机、命令行及脚本编写。 为什么选择本课程? - 这是首个也是唯一一个在线实操DevSecOps训练营。 - 学习DevSecOps、安全及应用测试,费用远低于昂贵的机构或辅导(通常在400至4000美元)。 - 以自己的节奏掌握涵盖最新工具与技术的全面课程。 - 理解传统DevOps与现代DevSecOps管道的区别,确保在每个阶段融入安全。 - 在构建过程中自动化安全扫描,而不是依赖于部署后的手动测试。 - 使用免费开源工具进行实践体验。 - 通过宣传视频参考Gartner关于DevOps与安全协作的报告。 课程结束时,学员将掌握大量与DevSecOps相关的理论和实践知识、工具和技术,并能独立实施DevOps或DevSecOps管道文化。此外,学员还将进行DevSecOps小测验,以测试其基本的DevSecOps知识。
This course is designed for Developers, DevOps, Security, Freshers, QA, Infra, Build & Release, IT professionals, InfoSec/AppSec Professional to learn and implement the DevSecOps methodology, tools & technology for your company/project using security best practices. This will help you to secure top quality jobs in the upcoming market with a higher salary (similar to the current trend of DevOps, Cloud & Security). As digitisation is the key for all companies to succeed in market/business. DevSecOps: Integrating Security into the SDLC using Jenkins and Other ToolsThis course is designed for teams and individuals who want to integrate security into their DevOps pipeline. Learn the essential DevSecOps skills, tools, and processes to secure your applications, focusing on:Preventing accidental leaks of secrets and sensitive data to SCMsIdentifying, fixing, and patching vulnerabilities in application dependencies, Dockerfiles, images, and run time application vulnerabilities detectionSecuring build, test, and deployment processes (Docker images, containers)Testing security with Threat Modelling ,Unit & Integration Tests, SCA, SAST, DAST, and Integration TestsWe'll break down each topic in an easy-to-understand, visual way. Every concept will be introduced with a slide-based overview, followed by practical hands-on exercises.Set up your own tools , VMs, CI/CD with JenkinsAccess a dedicated GitHub repository with code snippets used throughout the courseWhile it's helpful to have basic knowledge of the following, it's not required-everything will be covered in the course:DevOps & JenkinsDocker , SecurityLinux VM, CLI & Shell ScriptingWhy purchase this course?The first and only practical, hands-on DevSecOps Bootcamp available online.Learn DevSecOps, Security, and testing for applications without expensive institutes or tutors-at a fraction of the cost (usually $400-$4000).Gain skills at your own pace with a comprehensive curriculum covering the latest tools and techniques.Understand the difference between traditional DevOps and modern DevSecOps pipelines, integrating security at every stage.Automate security scanning during the build process instead of relying on manual testing post-deployment.Use free, open-source tools for hands-on experience.Refer to Gartner's report on DevOps + Security collaboration in the promo video.By the end of the course, I am sure you will have absorbed an enormous amount of theoretical and practical knowledge, tools, technologies related to DevSecOps, and should be able to implement DevOps or DevSecOps pipeline, culture for your project/product independently. Also now you have a DevSecOps quiz to test your basic DevSecOps SecOps skills knowledge.