Each lab includes a step-by-step guide to learning and applying hands-on techniques, as well as a "no hints" approach for students who want to stretch their skills and see how far they can get without following the guide. CPU: 64-bit 2.5+ GHz multi-core processor or higher, BIOS/UEFI: VT-x, AMD-V, or the equivalent must be enabled in the BIOS/UEFI, Hard Disk: Solid-State Drive (SSD) is MANDATORY with 50GB of free disk space minimum, Memory: 16GB of RAM or higher is mandatory for this class (IMPORTANT! Students start the day reviewing container orchestration options and scanning and testing their cloud infrastructure code for common cloud misconfiguration vulnerabilities. “The GIAC Cloud Security Automation (GCSA) certification covers cloud services and modern DevSecOps practices that are used to build and deploy systems and applications more securely. Additionally, certain classes are using an electronic workbook in addition to the PDFs. The estimated Azure cost for running the lab environment is $20 per week. VMware Workstation Pro and VMware Player on Windows 10 is not compatible with Windows 10 Credential Guard and Device Guard technologies. Please disable these capabilities for the duration of the class, if they're enabled on your system, by following instructions in this document. Since workloads are moving into container services, we'll explore the container security issues associated with tools such as Docker and Kubernetes. - 16GB of RAM is MANDATORY), Local Administrator Access within your host operating system. Download the SEC540 Lab Setup Instructions and Course Media from your sans.org account. Please start your course media downloads as you get the link. You can find more information in our two related posts: AWS Cloud Security Report 2020 for Management: Managing the Rapid Shift to Cloud SANS has begun providing printed materials in PDF form. We then shift focus to production and operations by building continuous security monitoring using Grafana, CloudWatch, and Slack. The lab environment starts with an on-premise CI/CD pipeline that automatically builds, tests, and deploys infrastructure and containerized applications. You must use a 64-bit laptop with one of the following operating systems that have been verified to be compatible with course VMware image: Prior to class, ensure that the following software is installed on the host operating system: In summary, before beginning the course you should: Your course media will now be delivered via download. Now DevOps and the cloud are making their way from Internet 'Unicorns' and cloud providers into enterprises. Log in to the AWS Console with your root account. SEC540 provides development, operations, and security professionals with a methodology to build and deliver secure infrastructure and software using DevOps and cloud services. Please plan to arrive 30 minutes early before your very first session for lab preparation and set-up. It means having a seat at the table with planning, development, and operational teams. It is necessary to fully update your host operating system prior to the class to ensure you have the right drivers and patches installed to utilize the latest USB 3.0 devices. Understand the Core Principles and Patterns behind DevOps, Map and Implement a Continuous Delivery/Continuous Deployment Pipeline, Understand the DevSecOps Methodology and Workflow, Integrate Security into Production Operations, Consume Cloud Services to Secure Cloud Applications. Register for a personal free-tier account. From the left navigation bar, select "Limits.". Courses or equivalent experiences that are prerequisites for SEC540: Students taking SEC540 will have the opportunity to learn and use a number of DevOps and cloud tools during the hands-on exercises. We ask that you do 5 things to prepare prior to class start. Students analyze and fix cloud infrastructure vulnerabilities, perform cloud-hosted application vulnerability scanning, and defend microservices using tools such as API Gateway and FaaS. The question is: Can security take advantage of the tools and automation to better secure its systems? 2. For Live Online, the instructor will be available to assist students with laptop prep and set-up 30 minutes prior to course start time. SEC540 goes well beyond traditional lectures and immerses students in hands-on application of techniques during each section of the course. If your limits are less than 10 vCPUs, please start by creating a new t2.micro instance. During this time, students can confirm that their Amazon Web Services (AWS) account is properly set up, ensure laptops have virtualization enabled, copy the lab files, and start the Linux virtual machine. - Alex Rams. In this new environment, we have found that a second monitor and/or a tablet device can be useful by keeping the class materials visible while the instructor is presenting or while you are working on lab exercises.
