Skip to content

Program 2 · DevSecOps and Secure Software Delivery

Status: not started

Security embedded in the software delivery lifecycle — DevSecOps. Expected topics include:

  • Shift-left security: security requirements, threat modeling early in SDLC
  • SAST, DAST, and IAST
  • Software composition analysis (SCA) and supply-chain security (SBOM, signing)
  • Infrastructure-as-code scanning
  • Container and image security
  • CI/CD pipeline hardening
  • Secrets management
  • Runtime application self-protection (RASP) and observability

Modules and submodules will be added as the program is started.


Feeds from

  • Program 1 — CIA/CIAS goals, countermeasures, and policies form the foundation this program applies to the delivery pipeline.

Feeds into

  • Program 3 — the OWASP Top 10 and threat modeling techniques are the concrete vulnerability classes and analysis methods used inside a DevSecOps pipeline.

Personal learning notes — cybersecurity curriculum.