DEVSECOPS USING DEFECTDOJO. END-To-END DEVELOPEMNT (XER - 301 )
LEVEL - ADVANCE | FORMAT - INSTRUCTOR LED TRAINING | Days : 5 Days
Prerequisites
- Knowledge of Application Security.
- Understanding of Vulnerability Assessment Tools.
- Knowledge of Security Testing Practices.
- Basic Database and Reporting Skills and Scripting.
- Familiarity with CI/CD Tools and Defect Tracking System.
Objectives
- Streamline Vulnerability Management.
- Compliance and Tagging Management and Reporting.
- Enable Continuous Security Monitoring on Third Party.
- Facilitate Collaboration Among Teams.
- Automate Security Workflows, Reporting and Analysis.
- Risk-Based Decision Making, Compliance and Audit Readiness.
Datasheet
Descriptions |
Training Objectives
- Learn Application Security Orchestration and correlation (ASOC).
- Implement and Automate Open-Source Scanner Integration using Bandit, Trivy and Scout.
- Evaluate Commercial Scanner Integration using Github Action such as Nessus, Qualys, SonarQube, Acunetix (DAST, IAST - Interactive Testing Tool).
- Integration with Issue Trackers - Github Issue and Unified Dashboard Design.
- Threat Modeling - Asset Identification, Threat Identification, Attack Surface Analysis, Mitigation Strategies.
- Risk Management - Risk Identification, Assess each risk based on impact, Mitigation Action.
- Learn and Configure Compliance Management and Role-Bases Access Control (RBAC).
Target Audience
- Security Analysts and Engineers.
- Developers and Software Engineers.
- DevOps/DevSecOps Teams/Security Consultants.
- Applications Security Professionals.
- IT Risk and Compliance Managers/QA Engineers.
Course Module
- Component Tracking - Dependency Management, Component Vulnerability Mapping, Version Tracking.
- Risk Acceptance Waivers.
- Engagement Scheduling - Planned, Automation and Recurring Engagement.
- Custom Field and Attributes.
- Advanced Reporting and Analytics.
- Finding Templates.
- Multi-Tenancy Support - Isolated Work Spaces, Role-Based Access for Tenants.
- Benchmarking and Historical Trends - Securing Trend Analysis.
- Multiple Product Types.
- Integrated Risk Scoring Models.
- Engagement Automation with CICD Pipelines - Seamless Integration with DevOps Tools.
- Securing as Code.
- Configuration as Code.
- Automated Scanning via API.
Scope
- Level - Advance
- Duration : 5 Days
- Format : Lecture and Hands-On Lab
- Platform Support : On-Prime Data Center / Cloud Platform
- Programming Language : Python Programming.
Lab Requirements
- Cloud Platform - AWS Services - S3, EKS, RDS, EC2.
- Windows OS.
- Open Source Software.
- Github Account.
- AIML Applications and DefectDojo Integrations.
Contact Us
- WhatsApp : +919164315460
- Email : info@xerxez.in