DevSecOps & Cloud Security Hardening
Security added at the end of a delivery cycle arrives too late to change anything and gets overruled by the release date. Moving it earlier only works if the checks are fast, accurate enough to be trusted, and attached to something a developer can fix. This programme covers both halves: building security into the pipeline without stalling delivery, and hardening the cloud environment against the specific misconfigurations that account for most real breaches.
Programme Agenda
Threat Modelling Without Ceremony
A lightweight approach that fits into design work rather than replacing it. Identifying what an attacker would go for, and letting that drive where the effort goes.
Securing the Pipeline Itself
The pipeline holds credentials to production, which makes it a target. Scoping runner permissions, protecting branches, signing artefacts, and preventing a pull request from executing privileged workflows.
Static Analysis and Secret Scanning
Placing code scanning where it will be acted on, tuning out the noise that causes teams to ignore results, and scanning history for credentials already committed.
Dependency and Supply Chain Risk
Software composition analysis, lockfiles, transitive dependency exposure, and a workable policy for a critical vulnerability in a package you do not control. Generating and using a software bill of materials.
Container Image Security
Base image choice and update cadence, image scanning in the pipeline, running as a non-root user, and admission control that stops an unscanned image reaching the cluster.
Secrets Management
Getting credentials out of code, environment files and pipeline variables into a managed secret store. Dynamic and short-lived credentials, rotation, and workload identity as the better answer.
Cloud Hardening
The misconfiguration categories behind most cloud incidents: public storage, over-permissive identity, exposed management ports, absent logging, and unencrypted data. Detective controls and posture management.
Detection and Incident Readiness
Logging what an investigation will need, alerting on identity and configuration change rather than only on traffic, and rehearsing a compromised-credential scenario end to end.
Learning Outcomes:
Run a lightweight threat model as part of ordinary design work
Harden a delivery pipeline against use as an attack path into production
Place code and secret scanning where results are actually acted on
Set a workable policy for dependency vulnerabilities and produce an SBOM
Secure container images from base selection through admission control
Move credentials into a managed secret store with rotation or short lifetimes
Close the cloud misconfigurations that account for most real breaches
Log and alert on what an incident investigation will need
Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cloud, DevOps and Platform Engineering
- Cloud Engineering Foundations (AWS and Azure) · Beginner, 2 days
- Containers and Kubernetes Basics · Beginner, 2 days
- CI/CD and DevOps Culture · All levels, 1 day
- Infrastructure as Code · All levels, 2 days