DevSecOps Foundation (DSOF)™

Duration: 2 days Dates: 14 December 2026 15 March 2027 28 June 2027 13 September 2027

In this course you will learn how security and compliance are integrated into DevOps organisations and continuous delivery workflows, rather than being checked only at the end. You will learn the purpose, benefits, concepts and terminology of DevSecOps, understand «Security as Code» and how DevSecOps roles fit into a DevOps culture. The course follows the structure of the DevSecOps Foundation (DSOF) certification from DevOps Institute (PeopleCert Group) and prepares you for the exam.

Why DevSecOps?

  • Key terms and concepts
  • Why DevSecOps matters and the business value it brings
  • Three ways of thinking about DevOps and security
  • Core principles of DevSecOps

Culture and Management

  • Incentive models and resilience
  • Organisational culture and generativeness, models by Erickson, Westrum and Laloux
  • Exercise: Influencing culture

Strategic Considerations

  • How much security is enough?
  • Threat modelling and the importance of context
  • Risk management at high delivery speed
  • Exercise: Measuring success

General Security Considerations

  • Avoiding the checkbox trap
  • Basic security hygiene
  • Architecture considerations and federated identity
  • Log management

IAM: Identity and Access Management

  • Basic concepts and importance of IAM
  • Implementation guidance and automation opportunities
  • Avoiding common IAM mistakes
  • Exercise: Overcoming IAM challenges

Application Security

  • Application Security Testing (AST) and test methods
  • Prioritising test methods and integrating them into issue management
  • Using threat modelling and automation

Operational Security

  • Basic security hygiene practices in operations
  • The role of operations management and the operating environment
  • Exercise: Integrating security into the CI/CD pipeline

Governance, Risk, Compliance (GRC) and Audit

  • What GRC is and why it matters
  • Rethinking policy: Policy as Code
  • Involving audit early (shift left)
  • Three myths about separation of duties and DevOps
  • Exercise: Designing policy, audit and compliance

Logging, Monitoring and Response

  • Setting up log management
  • Incident response and forensics
  • Threat intelligence and information sharing

Exam Preparation

  • Exam requirements and exam process
  • Review of a sample exam
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/12/14, 2027/03/15, 2027/06/28, 2027/09/13, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, flexibel, auf Anfrage

Professionals who integrate security into DevOps and continuous delivery workflows: DevOps and software engineers, IT security professionals, site reliability engineers, testers and quality assurance, release managers, Scrum Masters, project and product owners, IT leaders, compliance teams and managed service providers.

Basic knowledge of common DevOps terms and principles is required, for example from the DevOps Foundation course.

After the course you will be able to:

  • explain the purpose, benefits, concepts and terminology of DevSecOps
  • describe how DevOps security practices differ from other security approaches
  • apply business-oriented security strategies and best practices
  • involve stakeholders across the organisation in DevSecOps practices and improve communication between Dev, Sec and Ops
  • position DevSecOps roles within a DevOps culture and organisation

Exam: DevSecOps Foundation (DSOF) from DevOps Institute (PeopleCert Group)

Duration: 60 minutes

Format: 40 multiple-choice questions, open book, pass mark 65% correct answers

The exam fee is not included in the course price.

Price range: CHF1'990 through CHF6'400 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation