Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Mohammed Imran -- Back to the Lab Again with a DevOps

27 min18 september 2018

Om avsnittet

Learning DevSecOps is hard when setting up the lab becomes a project of its own. Mohammed Imran introduces DevSecOps Studio, an environment designed to help people practice an automated delivery workflow and add security to it. He shares his transition from offensive security toward building defenses, explains why security practitioners need to understand developers’ tools, and describes the roles of Git, GitLab, containers, and automation. Chris asks how static and dynamic testing fit into the pipeline and how the lab connects with DevSlop. Their discussion keeps returning to hands-on experience: give learners working pieces they can inspect, change, and reconnect. The episode offers a route from knowing security concepts to understanding how those concepts operate inside a real development process.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Mohammed Imran:
Mohammed Imran on LinkedIn
DevSecOps Studio

Mentioned in this episode:
OWASP DevSlop
GitLab
Docker
Bandit

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Learning DevSecOps with Mohammed Imran
01:23 An offensive-security origin story
03:07 Moving from breaking systems to defending them
04:50 What a DevSecOps course needs to teach
06:30 Learning from established DevOps practices
10:15 Dynamic testing and vulnerability scanning
12:07 Bridging operations, coding, and security skills
14:40 Learning Git and CI/CD fundamentals
14:58 Why GitLab is a useful starting point
19:02 What the DevSecOps Studio lab provides
20:20 Teaching with a working environment
23:12 Cloud reference architectures and DevSlop
24:41 How to get started and find the documentation

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.