0%

Explore Courses Defend What Matters

Your Bag

DevSecOps & Cloud Compliance

04 Cloud Security

DevSecOps & Cloud Compliance

Move security into the pipeline, and produce the evidence auditors need without stopping the team from shipping.

Levels
04
Skill Range
Beginner Expert
Track
Cloud Security
Lifetime Access
DevSecOps & Cloud Compliance
From 205CREDS

Security that only runs before release is security that gets skipped before release. This course builds it into the pipeline instead. You will add secret scanning, software composition analysis, static and dynamic testing, and container image scanning to a CI/CD workflow, and tune each one so developers act on the output rather than mute it. Infrastructure as code security covers Terraform scanning, policy as code with OPA, and drift detection. On the compliance side you will map controls to SOC 2, ISO 27001, and PCI DSS, and automate evidence collection so audit season stops being a scramble. Supply chain security, signed artefacts, and SBOM generation close the course.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    205 CREDS

    Purpose

    Move security into the pipeline, because security that only runs before release gets skipped before release.

    Outcome

    You can add security scanning to a pipeline that developers accept.

    What You'll Learn
    • Add secret scanning and software composition analysis to a CI workflow.
    • Tune each check so developers act on the output rather than mute it.
    • Fail a build on a real finding and see the loop close.
  2. Level 02

    Intermediate

    448 CREDS

    Purpose

    Add static, dynamic, and container scanning without drowning the team in noise.

    Outcome

    You can run application and container scanning that stays actionable.

    What You'll Learn
    • Integrate static and dynamic application testing into the pipeline.
    • Scan container images and base layers for known vulnerabilities.
    • Triage results so that what reaches a developer is worth their time.
  3. Level 03

    Advanced

    661 CREDS

    Purpose

    Secure infrastructure as code and enforce policy as code.

    Outcome

    You can secure infrastructure as code and enforce policy automatically.

    What You'll Learn
    • Scan Terraform for insecure configuration before it is applied.
    • Enforce policy as code with OPA in the pipeline.
    • Detect drift between declared and actual infrastructure.
  4. Level 04

    Expert

    1,034 CREDS

    Purpose

    Automate compliance evidence and secure the software supply chain.

    Outcome

    You can produce audit evidence automatically and secure the supply chain.

    What You'll Learn
    • Map controls to SOC 2, ISO 27001, and PCI DSS and automate evidence collection.
    • Sign artefacts and generate an SBOM for each build.
    • Make audit season a query rather than a scramble.