Group Purchasing
Group Purchasing
AI SKILLSUPDATED

SEC540: Cloud Native Security and DevSecOps Automation

SEC540Cloud Security, Artificial Intelligence
  • 5 Days (Instructor-Led)
  • 38 Hours (Self-Paced)
Course authored by:
Eric JohnsonBen AllenFrank Kim
Eric Johnson, Ben Allen & Frank Kim
SEC540: Cloud Security and DevSecOps Automation
Course authored by:
Eric JohnsonBen AllenFrank Kim
Eric Johnson, Ben Allen & Frank Kim
  • GIAC Cloud Security Automation (GCSA)
  • 38 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Advanced Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 19 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Gain the skills and methodology to secure modern Cloud Native, DevSecOps, and Kubernetes environments through hands-on labs using security controls in CI/CD pipelines for cloud systems.

Course Overview

The SANS SEC540 DevSecOps training course prepares security professionals to secure cloud-native and DevOps environments by implementing security controls in automated pipelines. It addresses challenges like insecure CI/CD pipelines, container misconfigurations, software supply chain weaknesses, and Kubernetes vulnerabilities while providing hands-on labs to develop practical skills. The course equips students with the DevSecOps mindset needed to secure cloud native environments.

Secure Your Systems at Cloud Native Speed

Common security challenges for organizations struggling with DevOps culture include issues such as:

  • Malicious code, credential theft, and compromised extensions from improperly protected continuous integration and delivery pipelines.
  • Unenforced peer code reviews and security approvals that do not meet change approval and audit requirements.
  • False positives, noise, and build failures from incorrectly automated security scanners.
  • Understanding how AI tools, such as coding agents, MCP servers, and code review assistants can help use DevOps tools and establish policy guardrails.
  • Configuration drift between environments, resource misconfigurations, and public data exposure from insufficiently managed cloud infrastructure.
  • Failure to standardize golden virtual machine and container base images across the organization.
  • Ignoring software supply chain vulnerabilities inherited from malicious libraries, third-party software, and compromised build artifacts.
  • Granting too many permissions to Kubernetes clusters and workloads running inside them.
  • Operating Kubernetes clusters without policies that stop compromised workloads, prevent lateral movement between workloads, and enable central cluster monitoring.
  • Lacking a centralized identity provider, API Gateway, and network policies to establish zero trust between microservices.
  • Failing to release patches and close vulnerability windows due to code freezes and failed deployments.
  • Inability to consolidate, verify, and enforce policy for pipelines and workloads running across the organization.

Security teams can help organizations prevent these issues by developing a DevOps mindset and learning to apply cloud native and Kubernetes security controls. This course provides development, operations, and security professionals with a deep understanding of and hands-on experience with the DevOps methodology used to build and deliver cloud native infrastructure and software. Students learn how to attack and then harden the entire DevOps workflow, from version control to continuous integration and running workloads in Kubernetes. Each step of the way, students explore the security controls, configuration, and policies required to improve the reliability, integrity, and security of on-premises and cloud-hosted systems. Students learn how to implement more than 20 DevSecOps security controls to build, test, deploy, harden, and monitor cloud native infrastructure and services.

Hands-On DevSecOps Automation Training

  • 19 DevSecOps and Cloud Native Immersive Hands-On Labs:
    • 4 DevOps labs focusing on CI/CD, Infrastructure as Code, and Configuration Management
    • 3 AI labs focusing on securing DevOps workflows using LLMs, MCP, and Agents
    • 9 Cloud native labs focusing on containers, supply chain, and Kubernetes
    • 3 Policy-as-code labs focusing on compliance, guardrails, and auto-remediation

Students can choose to work on the labs using either AWS or Microsoft Azure and their corresponding managed Kubernetes service.

SEC540 training goes well beyond traditional lectures and immerses students in hands-on application of techniques during each section of the course. Each lab includes a step-by-step guide to learning and applying hands-on techniques, as well as a "no hints" approach for students who want to stretch their skills and see how far they can get without following the guide. This allows students, regardless of background, to choose the level of difficulty they feel is best suited for them -- always with a frustration-free fallback path. Immersive hand-on labs ensure that students not only understand theory, but how to configure and implement each security control.

The SEC540 lab environment simulates a real-world DevOps environment, with more than 10 automated pipelines responsible for building DevOps container images, cloud infrastructure, automating gold image creation, orchestrating Kubernetes workloads, executing security and audit scans, and enforcing compliance standards. Students are challenged to sharpen their technical skills and automate more than 20 security-focused challenges using a variety of command line tools, programming languages, and configuration templates.

The SEC540 course labs come in both AWS and Azure versions. Students will choose one cloud provider at the beginning of class to use for the duration of the course. Both options leverage Terraform for Infrastructure as Code (IaC) and the cloud provider's managed Kubernetes service for container orchestration. Students are welcome to do labs for the alternate cloud provider on their own time once they finish the first set of labs.

CloudWars Bonus Callenges (Optional)

For students who want an extra challenge, 2 hours of CloudWars Bonus Challenges are available during extended hours each day. These CloudWars challenges provide additional opportunities for hands-on experience with the cloud and DevOps toolchain.

  • Section 1 Labs: Attacking the DevOps Toolchain, Configuring Pre-Commit Security Controls, AI-Assisted Merge Request Reviews, Protecting Secrets with Vault, CloudWars (Section 1): Cloud Native & DevSecOps Automation Bonus Challenges
  • Section 2: Infrastructure as Code Network Hardening, Gold Image Creation, Container Image Hardening, Container Supply Chain Security, CloudWars (Section 2): Cloud Native & DevSecOps Automation Bonus Challenges
  • Section 3: Kubectl and AI Assistants, Kubernetes Role-Based Access Control, Kubernetes Workload Identity, Kubernetes Admission Control, CloudWars (Section 3): Cloud & DevOps Bonus Challenges
  • Section 4: Keycloak Identity and Access Management, Kong Kubernetes Ingress Controller, Kubernetes Blue / Green Deployments, OpenTelemetry Observability, CloudWars (Section 4): Cloud Native & DevSecOps Automation Bonus Challenges
  • Section 5: Cloud and Kubernetes Compliance, Vulnerability Aggregation and Correlation, Automated Remediation, CloudWars (Section 5): Cloud Native & DevSecOps Automation Bonus Challenges

Syllabus Summary

  • Section 1: Attacking and Hardening DevOps Workflows
  • Section 2: Securing Cloud Infrastructure, Container Images, and the Software Supply Chain
  • Section 3: Managing and Securing Kubernetes Workloads
  • Section 4: Securing Microservices and Kubernetes Observability
  • Section 5: Automating Compliance, Policy, and Remediation

Authors Statement

"DevOps, cloud native, Kubernetes, and AI tools are radically changing the way that organizations design, build, deploy, and operate online systems. Leaders like Amazon, Netflix, Microsoft, and Google deploy hundreds or even thousands of changes every day, continuously learning, improving, and growing - and leaving their competitors far behind. With DevSecOps moving from Internet 'Unicorns' and cloud providers into the enterprise, it is more important than ever for security teams to understand how these systems work.

"Traditional approaches to security can't come close to keeping up with this rate of accelerated change. Engineering and operations teams that have broken down the 'walls of confusion' in their organizations are increasingly leveraging new kinds of automation, including Infrastructure as Code, Kubernetes, microservices, containers, and cloud native services. The question is: How can security take advantage of these tools and automation to better secure its systems?

"Security must be reinvented in a DevOps and cloud native world."

- Eric Johnson, Ben Allen, and Frank Kim

What You'll Learn

  • Understand DevOps principles for secure workflows
  • Integrate AI security tools into developer environments and CI/CD pipelines
  • Manage secrets and automate infrastructure with IaC
  • Harden and monitor containers and Kubernetes workloads
  • Secure software supply chain with SBOMs and artifact signing
  • Defend microservices using cloud native identity provider and API Gateway services
  • Automate compliance with policy guardrails and remediation

Business Takeaways

  • Build a security team skilled in DevSecOps, AI, and cloud-native security
  • Collaborate with DevOps to integrate security and AI guardrails early in development
  • Utilize cloud-native services for deployment, hardening, and monitoring
  • Prepare for container and Kubernetes migrations with adaptability
  • Enhance security with API Gateway and cloud native observability services
  • Implement centralized audit pipelines and policy-as-code

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC540: Cloud Native Security and DevSecOps Automation.

Section 1DevOps Security Automation

This section introduces DevOps practices by analyzing and securing a vulnerable Version Control and Continuous Integration (CI) system, teaching students to configure AI agents that help identify risks and run DevOps tools that harden workflows, automate code analysis, and securely manage secrets.

Topics covered

  • DevOps and Security Challenges
  • DevOps Toolchain
  • Pre-Commit Security Controls
  • Pre-Merge Security Controls
  • Secrets Management

Labs

  • Attacking the DevOps Toolchain 
  • Configuring Pre-Commit Security Controls
  • AI-Assisted Merge Request Reviews
  • Protecting Secrets with Vault 
  • CloudWars Bonus Challenges

Overview

SEC540 starts by introducing DevOps practices, principles, and tools by attacking a vulnerable Version Control and Continuous Integration (CI) system. Students gain an in-depth understanding of how the toolchain works, the risks these systems pose, and key weaknesses that could compromise the workflow. Next, we examine the security features available in various Continuous Integration (CI) and Continuous Delivery (CD) systems, such as GitHub and GitLab, and then start hardening the workflow. Students then see how advanced code analysis capabilities can be included using Large Language Models (LLM), AI Agents, and Model Context Protocol (MCP) servers. Finally, students ensure secrets consumed by the workflows are stored securely in secrets management solutions, such as HashiCorp Vault, AWS Secrets Manager, and Azure Key Vault.

Full Lab Details

  • Attacking the DevOps Toolchain
  • Configuring Pre-Commit Security Controls
  • AI-Assisted Merge Request Reviews
  • Protecting Secrets with Vault
  • CloudWars (Section 1): Cloud Native & DevSecOps Automation Bonus Challenges

Full Topic Details

  • DevOps and Security Challenges
    • Understand the core principles and patterns behind DevOps
    • Recognize how DevOps works and identify keys to success
  • DevOps Toolchain
    • Version control and source code management with git
    • Using GitFlow to manage changes across environments
    • Continuous Integration (CI) versus Continuous Delivery (CD)
    • Continuous Delivery versus Continuous Deployment
    • CI/CD supply chain attacks, risks, and hardening guidelines
    • GitHub Actions and GitLab CI/CD pipeline workflows, reusable workflows, composite actions, secrets management, OpenID Connect identity tokens, marketplace extensions, and runner monitoring
  • Pre-Commit Security Controls
    • Integrate AI LLM, MCP server, and Agent tools in code editors
    • Conduct effective risk assessments and threat modeling in a rapidly changing environment
    • Learn how to analyze a git repository and identity key technology stacks
    • Configure pre-commit git hooks to run required security checks
    • Set up merge request templates and automated merge request pipelines to evaluate code health
    • Enable branch protections to require approvals and change control
    • Enforce high risk code reviews using CodeOwners
  • Pre-Merge Security Controls
    • Design and implement a merge request process for AI and human reviewers
    • Understand the strengths and weaknesses of different automated testing approaches
    • Minimize false positives and create custom rules
    • Parse automated security using the xUnit, JUnit, SARIF, CycloneDX, and SPDX machine readable formats
    • Create merge request comment bots to display test results
    • Install web hooks to integrate AI-Assisted merge request reviews
  • Secrets Management
    • Managing secrets for CI/CD workflows
    • Scan version control repositories for secrets
    • Prevent secrets from being committed to version control
    • Register pre-commit hooks to block commits with secrets
    • Open-source and commercial secrets management systems
    • Provision secrets in the Azure Key Vault, AWS Secrets Manager, and HashiCorp Vault

Section 2Cloud Infrastructure Security

In section two, students deploy cloud infrastructure with Terraform, harden network configurations, automate configuration management with Packer and Ansible, and secure container images for Kubernetes by managing misconfigurations, scanning for vulnerabilities, and securing the software supply chain with SBOMs and artifact signing.

Topics covered

  • Cloud Infrastructure as Code
  • Configuration Management as Code
  • Container Security Lifecycle
  • Software Supply Chain Security

Labs

  • Infrastructure as Code Network Hardening 
  • Gold Image Creation
  • Container Image Hardening
  • Container Software Supply Chain Security
  • CloudWars Bonus Challenges

Overview

Section 2 challenges students to use their DevOps skills to deploy a code-driven cloud infrastructure with Terraform using more than 100 cloud resources. Students scan the cloud infrastructure as code (IaC), identify insecure network configurations and harden the network traffic flow rules. With the cloud infrastructure in place, students learn how automate configuration management and publish golden images using Packer and Ansible. To finish the day, students begin preparing a container image to run on a Kubernetes cluster. Following the container security lifecycle, we review Dockerfiles and Kubernetes manifests for misconfigurations, scan the configuration file code analysis, rebuild the image using trusted suppliers, write container security policies as code, and scan images for vulnerabilities. Finally, students learn how to manage the container image's software supply chain using attestations, provenance, software bill of materials (SBOM), artifact signing, and SBOM vulnerability scanning.

Full Lab Details

  • Infrastructure as Code Network Hardening
  • Gold Image Creation
  • Container Image Hardening
  • Container Software Supply Chain Security
  • CloudWars (Section 2): Cloud Native & DevSecOps Automation Bonus Challenges

Full Topic Details

  • Cloud Infrastructure as Code
    • Introduction to Cloud Infrastructure as Code (IaC)
    • Terraform, OpenTofu, and the pros and cons of multi-cloud IaC
    • Create Terraform resources with HashiCorp Configuration Language (HCL)
    • How to choose a Terraform provider for your cloud
    • Create shared Terraform modules for your organization
    • Automate Terraform deployments in CI/CD
    • Secure Infrastructure as Code (IaC) configurations with Checkov and EasyInfra
  • Configuration Management as Code
    • Introduction to configuration management tools
    • How Ansible templates can help configure a custom virtual machine
    • Build custom virtual machine images with Packer
    • Automate golden image configuration test suites with InSpec
    • Publish golden images using CI/CD workflows
  • Container Security Lifecycle
    • Introduction to the Application Container Security Guide
    • Dockerfile commands, examples, and misconfigurations
    • Linting container configuration files with Trivy
    • Eliminating vulnerabilities with minimal base images, trusted suppliers, and multi-stage builds
    • Writing custom container configuration policies with Conftest
    • Scanning container images for vulnerabilities with Trivy
  • Software Supply Chain Security
    • Introduction to the software supply chain
    • Software provenance attestations with Docker BuildKit
    • Supply-Chain Levels for Software Artifacts (SLSA)
    • Managing vulnerable dependencies with trusted suppliers
    • Create Software Bill of Materials (SBOMs)
    • Sign build artifacts and Software Bill of Materials (SBOMs) with Project Sigstore
    • Scan SBOM artifacts for vulnerabilities and track results using Vulnerability Exploitability eXchange (VEX)

Section 3Cloud Native Security Operations

In section three, students start by learning the Kubernetes control plane, the kubectl command line interface, and how to use AI to interact with clusters hosted in cloud services like AWS EKS and Azure AKS. Then, harden the cluster using security controls such as RBAC, workload identity, and admission control.

Topics covered

  • Kubernetes Architecture, Resources, and Kubectl
  • Kubernetes Risks and Security Controls
  • Kubernetes Workload Security 
  • Kubernetes Runtime Security 
  • Continuous Security Monitoring 

Labs

  • Kubectl and AI Assistants
  • Kubernetes Role-Based Access Control
  • Kubernetes Workload Identity
  • Kubernetes Admission Control
  • CloudWars Bonus Challenges

Overview

Section 3 introduces students to the Kubernetes control plane and core components used to group resources, store configuration data, and run containers. After an introduction to Kubernetes configuration and kubectl, , students learn how to use an AI assistant to examine a cluster and its resources. Then, we shift focus to Kubernetes security controls such as authentication, role-based access control (RBAC), isolation, workload identity, and admission control.

Full Lab Details

  • Kubectl and AI Assistants
  • Kubernetes Role-Based Access Control (RBAC)
  • Kubernetes Workload Identity
  • Kubernetes Admission Control
  • CloudWars (Section 3): Cloud & DevOps Bonus Challenges

Full Topic Details

  • Kubernetes Architecture, Resources, and Deployments
    • Introduction to Kubernetes architecture
    • Interacting with the Kubernetes API server using kubectl
    • Learn to create Kubernetes resource using YAML configuration
    • Inventory Kubernetes resources using metadata labels, and annotations
    • Isolate Kubernetes resources with namespaces and store configuration data in ConfigMap and Secrets
    • Understand ServiceAccount identity and how Pods authenticate to private container registry services
    • Learn to create re-usable configuration with Kustomize
    • Install Kubernetes packages using Helm
    • Use AI agents to interact with kubectl and manage the cluster
  • Kubernetes Risks and Security Controls
    • Understand container runtime and orchestration platforms
    • Review container orchestrator security risks
    • Learn integrated authentication in AWS Elastic Kubernetes Service (EKS) and Azure Kubernetes Service (AKS)
    • Apply Kubernetes role-based access control (RBAC) permissions to a subject (user, group, service account)
    • Grant cloud identities such as IAM Roles and Entra ID Groups RBAC permissions to AWS Elastic Kubernetes Service (EKS) and Azure Kubernetes Service (AKS) clusters.
  • Kubernetes Workload Security
    • Kubernetes cloud controller manager capabilities and permissions
    • Understand how AWS Elastic Kubernetes Service (EKS) and Azure Kubernetes Service (AKS) pods gain permissions to cloud provider APIs
    • Enable Kubernetes workload identity using OpenID Connect (OIDC) for pods running in either Azure Kubernetes Service (AKS) and AWS Elastic Kubernetes Service (EKS)
  • Kubernetes Runtime Security
    • Introduction to pod and container security context options
    • Enable host and process namespacing and workload resource limits
    • Introduction to Kubernetes admission controllers
    • Write validating admission controllers with Common Expression Language (CEL) and Open Policy Agent (OPA), Gatekeeper, and Rego
    • Learn how eBPF enables runtime protection for Kubernetes hosts and containers
    • Compare runtime security options include Cilium, Falco, KubeArmor

Section 4Microservice Security

In section four, students learn how security changes with microservices and how to implement centralized microservice security controls. We establish edge authentication and authorization with cloud native tooling, build network policy to govern service to service communication, deploy microservice patches with zero downtime, and enable OpenTelemetry.

Topics covered

  • Microservice Fundamentals
  • Microservice User Interface and Identity Providers
  • Microservice API Gateways
  • Kubernetes Deployment Orchestration
  • Cloud Native Security Observability

Labs

  • Keycloak Identity and Access Management
  • Kong Kubernetes Ingress Controller
  • Kubernetes Blue/Green Deployments
  • OpenTelemetry Observability
  • CloudWars Bonus Challenges

Overview

Section 4 starts with students learning how security changes in the world of microservices. We explore microservice architectures using edge authentication and authorization with cloud native tooling, such as the Keycloak identity provider, Kong API Gateway, and Kubernetes cloud load balancer controllers. With the perimeter protected, students then learn how to establish intra-cluster microsegmentation using Kubernetes network policy and service mesh. Next, we learn how to leverage Kubernetes blue/green capabilities to transparently deploy a new version of an application. Finally, students learn how Open Telemetry and Grafana's LGTM stack provides microservice observability for the Kubernetes cluster's metrics, logs, and traces.

Full Lab Details

  • Keycloak Identity and Access Management
  • Kong API Gateway, Kubernetes Ingress Controller, and Calico Network Policy
  • Kubernetes Blue/Green Deployments
  • Observability with OpenTelemetry and Grafana
  • CloudWars (Section 4): Cloud Native & DevSecOps Automation Bonus Challenges

Full Topic Details

  • Microservice Fundamentals
    • Compare the attack surfaces for traditional and microservice architectures
    • Understand the pros and cons when moving to microservices
    • Learn the common microservice security challenges
    • Understand how to build zero trust into microservice architectures
  • Microservice User Interface (UI) and Identity Providers
    • Understand how user interfaces, such as mobile apps and single page applications, interact with identity providers and microservices
    • See how Cloud CDN offerings (AWS CloudFront, Azure Front Door) and Kubernetes can host static web sites
    • Learn how Customer Identity and Access Management (CIAM) solutions help assign identities to users accessing microservices
    • Configure Keycloak clients, scopes, users, groups, and attributes to help microservices make access control decisions
  • Microservice API Gateways
    • Understand how API Gateways control traffic and enable centralized security controls for microservices
    • Learn about the Kong API Gateway and the different deployment topologies
    • Understand how to install and configure the Kubernetes Ingress Controller (KIC)
    • Use the Kubernetes Gateway API to configure a Kong Gateway proxy routing traffic to private Kubernetes services
    • Configure Kong routes and plugins verifying OIDC access tokens and enforcing CORS policies
    • Learn how to protect internal service to service communications with mutual TLS
    • Build Kubernetes network policies with Container Network Interface (CNI) and Calico
    • Understand how service mesh offerings can control API traffic at scale
  • Kubernetes Deployment Orchestration
    • Introduction to zero downtime deployments using cloud services and Kubernetes
    • Review public deployment rollouts using DNS and cloud load balancers
    • Learn how to use Kubernetes native deployments for canary rollouts
    • Configure Kubernetes service labels to manage blue/green deployments
    • Use Kubernetes Gateway API HTTPRoute weighting to migrate traffic between services
  • Cloud Native Security Observability
    • Monitoring and feedback loops from production to engineering
    • Understand the difference between logs, metrics, and data tracing
    • Understand Grafana’s monitoring stack including Loki, Mimir, and Tempo
    • Review OpenTelemetry’s framework, protocol (OTLP), and collectors
    • Configure the Kubernetes OpenTelemetry collector and the Kong OpenTelemetry and Prometheus plugins
    • Examine Kubernetes cluster, node, container, and event log sources
    • Grafana notification templates and contact types
    • Test monitoring, alerts, and notifications using automated

Section 5Continuous Compliance

In section five, students learn to automate cloud security and Kubernetes compliance, aggregate and correlate vulnerabilities, and implement policy as code to stop deployments and auto remediate configuration drift.

Topics covered

  • Compliance as Code
  • Policy as Code
  • Automated Remediation 

Labs

  • Cloud and Kubernetes Compliance
  • Vulnerability Aggregation and Correlation
  • Automated Remediation
  • CloudWars Bonus Challenges

Overview

Section 5 starts with a discussion on working in DevOps and how that affects policy and compliance. Students learn to leverage cloud native security tooling to automate cloud and Kubernetes compliance checks. Starting with Cloud Security Posture Management (CSPM), we start detecting security issues in the cloud and Kubernetes infrastructure. Next, students learn how to aggregate and correlate vulnerabilities from CI/CD pipelines into Application Security Posture Management (ASPM) tools. With vulnerability data in a centralized database, valid findings can establish a health score for each product. This allows governance teams to create policy as code that “pulls the andon cord” and marks a build as unhealthy or stops a pod from launching in a Kubernetes cluster. Students finish the course learning how to write policy as code for automated remediation to detect and correct cloud configuration drift.

Full Lab Details

  • Cloud and Kubernetes Compliance with Prowler
  • Vulnerability Aggregation and Correlation with Defect Dojo
  • Automated Remediation with Cloud Custodian
  • CloudWars (Section 5): Cloud Native & DevSecOps Automation Bonus Challenges

Full Topic Details

  • Compliance as Code
    • Introduction to Continuous Compliance in DevSecOps
    • Modern governance, risk, and compliance for cloud native applications
    • Mapping DevOps guardrails to ITIL and PCI controls
    • Kubernetes, Governance, Risk, and Compliance
    • Kubernetes Policy Architecture, Administration, and Enforcement
    • Cloud Security Posture Management (CSPM) with AWS Security Hub, Defender for Cloud, and Prowler
  • Policy as Code
    • Introduction to Application Security Posture Management (ASPM) products
    • Explore the DefectDojo product hierarchy, findings, status, and health score capabilities
    • Using CI/CD components to push findings into ASPM tools
    • Centralizing automated security checks in a dedicated security scanning factory
    • Writing policy as code to evaluate product health scores and “pull the andon cord”
  • Automated Remediation
    • Introduction to automated detection and remediation in the cloud
    • Learn how Azure Event Grid and AWS EventBridge route events to runbooks for remediation and notifications
    • Write policy as code with Cloud Custodian to manage cloud resources
    • Deploy Cloud Custodian policies to remediate Azure Network Security Group and AWS Security Group firewall rule misconfigurations

Things You Need To Know

Important! Bring your own system configured according to these instructions.

Cloud Accounts

Student cloud accounts are provided for students by SANS to complete the course labs. The SEC540 course labs come in both AWS and Azure versions. Time-limited accounts for each cloud are provided by SANS to use for completing the labs.

OnDemand Students

  • Students can dynamically provision their lab range by logging in to their SANS account and visiting the My Labs page.
  • When cloud account provisioning is complete, students can download the range credentials and their time-limited credentials.

Live Events (In Person or Live Online)

  • Students are automatically provisioned a lab range and cloud credentials 24 hours before class starts.
  • Students can log in to their SANS account and visit the My Labs page to download their range and cloud credentials the day before class begins.

Mandatory Laptop Requirement

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.

Students must be in full control of their system's network configuration. The system will need to communicate with the cloud-hosted DevOps server using a combination of HTTPS and SSH traffic. Running VPN, intercepting proxy, or egress firewall filters may cause connection issues communicating with the DevOps server. Students must be able to configure or disable these services to connect to the lab environment.

Bring Your Own Laptop Configured to the Following Directions

A properly configured system is required for each student participating in this course.

Before starting your course, carefully read and follow these instructions exactly:

  • Host Operating System: Latest version of Windows 10, macOS 10.15.x or later, or Linux that also can install and run a browser described below.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.

Mandatory Host Hardware Requirements

  • CPU: 64-bit multi-core processor (ARM and Intel processors are both supported)
  • Memory: 8GB RAM required (16GB recommended)
  • Wireless Ethernet 802.11 B/G/N/AC
  • Local Administrator Access within your host operating system
  • Permission to install and update Chrome or Firefox

Mandatory Software Requirements

  • All labs are browser-based and have been thoroughly tested in Chrome and Firefox.

In Summary

Before beginning the course, you should:

  • Install the latest version of Chrome or Firefox.
  • Download the SEC540 Lab Setup Instructions from your sans.org account.
  • After you have completed those steps, browse to the My Labs page in your sans.org account and download the SANS Cloud Security Flight Simulator range credentials. After authenticating the range, you will be redirected to the lab instructions to finish configuring the lab environment.
  • Students traveling to a live class event may find it helpful to bring a second monitor and/or a tablet device for keeping class materials visible while you are working on your course labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC540 training is recommended for a diverse range of individuals, including:

  • Anyone working in or transitioning to a DevOps environment
  • Anyone working in Kubernetes, containers, and microservices
  • Anyone who wants to understand where to add security checks, testing, and other controls to cloud and DevOps Continuous Delivery pipelines
  • Anyone interested in learning how to migrate and secure DevOps workloads in the cloud, specifically Amazon Web Services (AWS) and Microsoft Azure
  • Developers
  • Software architects
  • Operations engineers
  • System administrators
  • Security analysts
  • Security engineers
  • Auditors
  • Risk managers
  • Security consultants

The GIAC Cloud Security Automation (GCSA) certification validates a practitioner's understanding of the cloud native toolchain, DevSecOps methodology, and security controls throughout CI/CD pipelines. GCSA certification holders have demonstrated knowledge of the tools and skills required to implement configurations that improve the reliability, integrity, and security of cloud native systems.

  • DevOps and DevSecOps fundamentals, Secure Infrastructure and Configuration Management
  • Securing Cloud Architecture, Continuous Security Monitoring
  • Data and Secrets Protection, Compliance
  • Security and Automation related to Deployment, Runtime and Content Delivery

More Certification Details

  • Printed and digital course materials
  • Access to a virtual lab range with DevOps tools installed and ready to use
  • Temporary AWS and Azure cloud accounts for labs
  • GitLab repositories with all lab environment configurations
  • Electronic workbook with lab instructions
  • Option to deploy lab infrastructure in personal cloud accounts after the course

The following are courses or equivalent experiences that are prerequisites for SEC540:

  • Familiarity with Linux command shells and associated commands
  • Basic understanding of version control (git) and continuous integration systems (GitLab CI)
  • Basic understanding of code editors, such as VSCode, and AI extensions
  • Introductory knowledge of containers and Kubernetes is helpful (see references below to get started)
  • Hands-on experience using Amazon Web Services (AWS) or Microsoft Azure is helpful

Preparing for SEC540

Students taking SEC540 will have the opportunity to learn and use a number of DevOps and cloud native tools during the hands-on exercises. Getting a head start on the following tools, technologies, and languages will help students enjoy their lab experience:

The SEC540 training course is part of the Cloud Security Focus Area Learning Path. After completion of this course, here are recommended next courses for a variety of different DevSecOps and Cloud Security professionals:

DevSecOps Professionals:

Cloud Security Engineer:

Cloud Security Architect:

Cloud Security Manager:

DevSecOps automation allows security professionals to introduce continuous security controls, guardrails, and policies in their product delivery workflows. It combines development (Dev), security (Sec), and operations (Ops) with a focus on automation, making it possible to incorporate security protocols without disrupting the speed and efficiency that DevOps provides.

DevSecOps Automation is important for enhanced security compliance, reduced risk of human error, improved agility, scalability, and continuous feedback.

SEC540 training builds practical, marketable skills that directly impact your career and organization.

  • In-Demand Skills: Gain expertise in DevSecOps and cloud native security tools, skills highly sought after as organizations manage AI and cloud workloads
  • Career Mobility: This course opens doors to specialized roles, like DevSecOps Engineer, Cloud Security Engineer, and AI Engineer, offering competitive salaries and growth potential.
  • Immediate Application: The hands-on labs in SEC540 training enable you to apply new skills immediately, helping your organization enhance security without slowing development.
  • Professional Recognition: SANS is globally respected, and completing SEC540 training strengthens your credibility and connects you with a network of cybersecurity experts.
  • Foundation for Advanced Certifications: Prepares you for certifications like GIAC Cloud Security Automation (GCSA), validating your skills and advancing your professional standing.

Relevant Job Roles

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Cloud Security Engineer Training, Salary, and Career Path

Cloud Security

Cloud Security Engineers integrate advanced security measures into cloud and cloud-native environments, maximize security automation within DevOps workflows, and proactively mitigate threats to safeguard modern cloud infrastructures.

Explore learning path

Systems Developer (DCWF 632)

DoD 8140: Cyber IT

Oversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.

Explore learning path

Vulnerability Assessment Analyst (DCWF 541)

DoD 8140: Cybersecurity

Assesses systems and networks to ensure compliance with policies and identify vulnerabilities in support of secure and resilient operations.

Explore learning path

Technology Research and Development (OPM 661)

NICE: Design and Development

Responsible for conducting software and systems engineering and software systems research to develop new capabilities with fully integrated cybersecurity. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems.

Explore learning path

IT Investment/Portfolio Manager (DCWF 804)

DoD 8140: Cyber Enablers

Oversees a portfolio of IT capabilities aligned to enterprise goals, prioritizing needs, solutions, and value delivery to the organization.

Explore learning path

Communications Security (COMSEC) Management (OPM 723)

NICE: Oversight and Governance

Responsible for managing the Communications Security (COMSEC) resources of an organization.

Explore learning path

Information Systems Security Developer (DCWF 631)

DoD 8140: Cybersecurity

Designs and evaluates information system security throughout the software lifecycle to ensure confidentiality, integrity, and availability.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 18

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources