Program overview

The program moves from security requirements and threat modeling with STRIDE and LINDDUN through risk-based backlogs mapped to OWASP ASVS and SAMM, secure design, implementation and review.

DevSecOps competencies

Participants build pipelines with SAST, DAST, IAST and SCA; generate SBOMs; use signed builds and provenance such as SLSA; manage secrets; and harden infrastructure as code, CI/CD, containers, Kubernetes and cloud environments.

The course covers supply-chain risk, fuzzing and coverage gates, vulnerability remediation SLAs, secure release and change control, monitoring, incident response and audit evidence for ISO/IEC 27001, ISO/IEC 27034 and SOC 2.

Log in to enroll

The course will become enrollable when its learning modules are published.