Program overview
The program moves from security requirements and threat modeling with STRIDE and LINDDUN through risk-based backlogs mapped to OWASP ASVS and SAMM, secure design, implementation and review.
DevSecOps competencies
Participants build pipelines with SAST, DAST, IAST and SCA; generate SBOMs; use signed builds and provenance such as SLSA; manage secrets; and harden infrastructure as code, CI/CD, containers, Kubernetes and cloud environments.
The course covers supply-chain risk, fuzzing and coverage gates, vulnerability remediation SLAs, secure release and change control, monitoring, incident response and audit evidence for ISO/IEC 27001, ISO/IEC 27034 and SOC 2.
The course will become enrollable when its learning modules are published.
