Saltar al contenido
← Todos los cursos

Experto · Lecciones: 7

DevSecOps and software supply chain security

How security fits into every stage of building and shipping software: pipeline checks, supply chain lessons from SolarWinds and Log4Shell, SBOMs and signing, containers, infrastructure as code and cloud posture.

Empezar el curso

  1. 1 DevSecOps: shifting security left across the lifecycle

    DevSecOps makes security part of every stage of building software instead of a final gate. Learn what “shift left” means, what changes at each stage, and the NIST framework that describes it.

    8 min
  2. 2 Securing the CI/CD pipeline: SAST, DAST, secrets and breaking the build

    Automated checks in continuous integration catch problems before they ship. Learn what static and dynamic testing find, why leaked secrets are so dangerous, when to fail a build, and how to protect the pipeline itself.

    9 min
  3. 3 Software supply chain attacks: SolarWinds and Log4Shell

    Two incidents changed how the world thinks about software you did not write. Learn what happened with SolarWinds Orion and the Log4j vulnerability, what they have in common, and what defenders took away.

    9 min
  4. 4 SBOMs and artifact signing: SPDX, CycloneDX, Sigstore and SLSA

    A software bill of materials lists what is inside your software; signing and provenance prove where it came from. Learn the formats, the tools and the SLSA framework that tie them together.

    9 min
  5. 5 Container and Kubernetes security: least privilege, RBAC and image scanning

    Containers package applications with everything they need, and Kubernetes runs them at scale. Learn where the risks are and the core controls: trusted images, least privilege, RBAC and Pod Security Standards.

    9 min
  6. 6 Infrastructure as code and policy as code

    When servers, networks and permissions are defined in files, they can be reviewed and tested like software. Learn how Terraform and CloudFormation work, and how policy as code catches misconfigurations before deployment.

    8 min
  7. 7 Cloud security posture management: drift, IAM and exposed storage

    Cloud environments change constantly, and not always through code. Learn what cloud security posture management does, why configuration drift happens, and how to find over-permissioned identities and exposed storage.

    8 min

Gratis, sin cuenta, sin rastreo. Tu progreso se queda en este navegador.