Build crucial cyber security skills through interactive training during SANS Cyber Security Mountain 2021. Save $150 thru 6/30.


To attend this webcast, login to your SANS Account or create your Account.

This webcast has been archived. To view the webcast login into your SANS Portal Account or create an account by clicking the "Get Registered" button on the right. Once you register, you can download the presentation slides below.

Secure DevOps: Faster Feedback with Effective Security Unit Tests in CI / CD

  • Monday, January 15, 2018 at 1:00 PM EST (2018-01-15 18:00:00 UTC)
  • Eric Johnson

You can now attend the webcast using your mobile device!



Fast moving DevOps teams are making hundreds, or even thousands, of changes per day, and traditional approaches to security are struggling to keep up. Most static and dynamic scanners take too long to complete and the results are invalidated after the next commit. The question is, how can security teams build stronger security checks into the DevOps pipeline and obtain fast feedback without slowing down engineering teams?

Here's the good news: DevOps teams are already using Test Driven Development (TDD) frameworks and Continuous Integration (CI) tools to automate unit testing. And even better news: it's time for security teams to get their hands dirty, write some code, and add custom security unit tests to the pipeline.

In this talk, we will explore where security unit testing fits in the SecDevOps model, effective unit testing frameworks, and several examples that can help security teams harden their applications. Live demonstrations will show how to write security unit tests, execute the tests in a Jenkins continuous integration (CI) build pipeline, and evaluate test results.

This is the third in a five-part webcast series on Secure DevOps. Topics covered in these webcasts are directly related to the new SANS DEV540: Secure DevOps and Cloud Application Security course. Upcoming webcasts will cover the following topics:

Microservices and API Security

Encryption in the Cloud with KMS

For additional information about DEV540 visit the course page.

Speaker Bio

Eric Johnson

Eric is a Co-founder and Principal Security Engineer at Puma Security and a Senior Instructor with the SANS Institute. His experience includes cloud security assessments, cloud infrastructure automation, static source code analysis, web and mobile application penetration testing, secure development lifecycle consulting, and secure code review assessments. Eric is the lead author and an instructor for SEC540: Cloud Security and DevOps Automation, a co-author and instructor for both the brand new SEC510: Public Cloud Security: AWS, Azure, and GCP, and the upcoming SEC584: Cloud Native Security: Defending Containers & Kubernetes. Additionally, Eric is a SANS Security Awareness Developer Training Advisory Board Member and SANS Analyst for Application Security and DevSecOps Surveys. Read more about Eric here.

Need Help? Visit our FAQ page or email

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.