|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/devsecops-fundamentals/
课程评论:没有评论
课程名称:DevSecOps基础知识 - 包括实践演示 课程概述:对DevSecOps感到好奇?想要了解所有关于DevSecOps的知识?这门课程正适合你。课程将涵盖你需要了解的所有内容,以便在DevSecOps领域顺利起步和成功。 课程特点: - 真实世界学习:跟随实际应用的动手演示,避免枯燥的理论。 - 快速聚焦:课程不会占用你几周的时间,快速掌握所需知识。 - 实践准备资源:可下载的源代码、YAML等,以便在自己环境中练习。 - 工具无关:核心安全原则和技术适用于任何CI/CD平台。 - 专家主导内容:直接向拥有近20年经验的首席安全工程师学习,这些都是实践中总结的经验,而非单纯的理论。 课程目标: - 启动你的DevSecOps之旅:理解DevSecOps是什么,其重要性,以及如何在第一天开始。 - 掌握核心安全原则:在Linux、Docker和Kubernetes环境下应用CIA三元组、深入防御、最低权限等原则;加强SSH、sudo、文件权限和更新等。 - 精通行业领先工具:使用SAST、DAST、SCA、CNAPP及Git进行代码扫描和安全保护;构建、扫描和锁定Docker中的容器;通过真实案例和最佳实践推荐部署和保护Kubernetes集群。 - 在规模上自动化和强制实施安全:安全地实施Terraform和Jenkins,学习基础设施即代码和CI/CD管道的强化。 - 理解渗透测试与漏洞评估:掌握渗透测试和漏洞评估的方法论,了解其如何融入你的DevSecOps生命周期。使用CVSS、EPSS分数解读和优先排序发现的问题。 - 理解网络安全生态系统:利用OWASP(前十名、ZAP、ASVS)、CIS基准、CISA公告和关键开源项目,识别和修复常见的web应用安全问题。 课程内容包括: - 可下载的实验和源代码,让你可以在本地计算机上进行学习 - 每个工具的实践演示和操作视频,以及可直接使用的YAML配置 - 模块结束时的测验,以巩固学习并跟踪进度 - 涉及的每个工具、组织和项目的链接 准备好保护你的管道了吗?立即注册,开始构建你的DevSecOps专业知识——没有废话,只有经过实战验证的最佳实践。
Curious about DevSecOps? Want to learn all about DevSecOps? This is the course for you. This course will cover everything you need know to get started and be successful in DevSecOps. Why This Course Is Different:Real-World Learning: Follow along with hands-on demos around actual apps-no stale theory here.Fast & Focused: This course won't take you weeks to finish. Learn what you need to know to get started. Quickly.Lab-Ready Assets: Downloadable source code, YAML etc. so you can practice in your own environment.Tool-Agnostic: The core security principles and techniques apply to any CI/CD platform.Expert-Driven Content: Learn directly from a Principal Security Engineer with nearly 20 years experience-these are lessons learned in the field, not just theory.By the end of this course, you will:Launch Your DevSecOps Journey: Grasp what DevSecOps is, why it matters, and how to get started on Day 1. Transform any DevOps pipeline into a secure, automated DevSecOps workflow (complete YAML examples included).Command Core Security Principles: Apply CIA triad, defence-in-depth, least-privilege across Linux, Docker & Kubernetes; harden SSH, sudo, file perms, updates and more.Master Industry-Leading Tools: Scan and secure code with SAST, DAST, SCA, CNAPP & Git; build, scan and lock down containers in Docker; deploy and protect Kubernetes clusters with real-world demos and best-practice recommendations.Automate & Enforce Security at Scale: Implement Terraform and Jenkins securely-learn infrastructure-as-code and CI/CD pipeline hardening side by side.Understand Pen Tests & VAs: Grasp the methodology behind penetration testing and vulnerability assessments, and see how they integrate into your DevSecOps lifecycle. Interpret and prioritise findings using CVSS, EPSS scoresUnderstand the Cybersecurity Ecosystem: Leverage OWASP (Top 10, ZAP, ASVS), CIS Benchmarks, CISA advisories and key open-source projects; identify and remediate common web-application security issues as you build.What's Inside:Downloadable Labs & Source Code to follow along on your local machineHands-On Demos & walkthrough videos for each tool, plus ready-to-use YAML configurationsEnd-of-Module Quizzes to reinforce your learning and track progressLinks to every tool, organization and project we coverReady to Secure Your Pipeline?Enroll now and start building your DevSecOps expertise-no fluff, just field-tested best practices.