Program 2 · DevSecOps and Secure Software Delivery
Status: not started
Security embedded in the software delivery lifecycle — DevSecOps. Expected topics include:
- Shift-left security: security requirements, threat modeling early in SDLC
- SAST, DAST, and IAST
- Software composition analysis (SCA) and supply-chain security (SBOM, signing)
- Infrastructure-as-code scanning
- Container and image security
- CI/CD pipeline hardening
- Secrets management
- Runtime application self-protection (RASP) and observability
Modules and submodules will be added as the program is started.
Feeds from
- Program 1 — CIA/CIAS goals, countermeasures, and policies form the foundation this program applies to the delivery pipeline.
Feeds into
- Program 3 — the OWASP Top 10 and threat modeling techniques are the concrete vulnerability classes and analysis methods used inside a DevSecOps pipeline.