К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Application and DevSecOps · LearnSpace
Назад в каталог
courseraПрограммирование

Application and DevSecOps

Курс от Microsoft
Продвинутый≈ 6.2 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

In this advanced-level course, you will learn to embed security directly into the software development lifecycle, transforming how your organization builds and deploys applications. You'll move beyond traditional development practices to automate security by gating Infrastructure-as-Code (IaC) pipelines, embedding SAST/DAST scanning, and continuously monitoring control baselines to ensure ongoing compliance. You'll leverage generative AI and manual frameworks to lead comprehensive threat-modeling workshops, identifying potential attack vectors before they impact production. You'll also engineer secure containerized and Kubernetes environments, aligning workload protection and orchestration controls with established cloud landing zones, and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors throughout the software delivery lifecycle. This course is for security engineers, DevOps professionals, and software architects with familiarity with the SDLC, basic CI/CD pipeline automation, and introductory experience with application or infrastructure security testing. By the end of this course, you will be able to lead threat-modeling workshops to derive security requirements and structure control gates across complex systems; operationalize SAST, DAST, SCA, and secret-scanning within CI/CD and IaC pipelines to enforce risk-based gating; engineer secure containerized and Kubernetes environments aligned with established cloud landing zones; and design AI-enhanced security gates within Jenkins and GitHub Actions to prevent AI-related attack vectors across the software delivery lifecycle. This course works with tools across the DevSecOps ecosystem, including GitHub Advanced Security for secret scanning and code analysis, the free Microsoft Threat Modeling Tool which are available for public repositories. GitHub Advanced Security features, including Code Security and Secret Protection, require a paid license for private repositories.

Навыки, которые вы освоите

DevSecOpsThreat ModelingKubernetesSecurity ControlsCI/CDInfrastructure as Code (IaC)Open Web Application Security Project (OWASP)Security TestingIT Security ArchitectureApplication SecuritySecurity Requirements AnalysisAI SecurityCompliance ReportingSecurity EngineeringDevOpsAI WorkflowsCloud-Native ComputingAI IntegrationsGitHubSecurity Architecture Review

Программа курса

8 модулей · 41 учебных материалов

01Threat Modeling: Operationalize Secure Design5 материалов
The True Cost of Architectural FlawsВидеоSecure-by-Design PrinciplesЧтениеTranslating Principles to RequirementsЧтениеDefine TechHealth's AppSec BaselineЛабораторная

Учитесь у экспертов

Microsoft

Преподаватель курса

Application and DevSecOps
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 6.2 ч

8 модулей

Язык: Английский

Часть программы вашего университета
Knowledge Check: Secure DesignЗадание
02Threat Modeling: Scope and Methodology5 материалов
The Chaos of Unscoped WorkshopsDIALOGUESelecting Threat Modeling MethodologiesЧтениеHow to Scope a System for Threat ModelingЧтениеPrepare the TechHealth Threat Modeling WorkshopЛабораторнаяKnowledge Check: Scoping and MethodologiesЗадание
03Threat Modeling: Spearhead Workshops6 материалов
The Power of Visualizing Data FlowsЧтениеThe Microsoft Threat Modeling Tool (TMT)ВидеоModeling in Microsoft Threat Modeling Tool (TMT)ЧтениеModel the Patient PortalЛабораторнаяKnowledge Check: TMT and DFDsЗаданиеGraded Quiz: Threat ModelingЗадание
04DevSecOps: Embed SAST and DAST5 материалов
The Vulnerability BottleneckВидеоSAST, DAST, and SCAЧтениеConfiguring GitHub Advanced SecurityЧтениеGate the TechHealth App PipelineЛабораторнаяKnowledge Check: AppSec ScanningЗадание
05DevSecOps: Secure Container Environments5 материалов
The Illusion of Immutable SecurityDIALOGUESecuring Container Environments with Microsoft Defender and Azure PolicyЧтениеDefining Container GuardrailsЧтениеEvaluate the TechHealth AKS ArchitectureЛабораторнаяKnowledge Check: Container SecurityЗадание
06DevSecOps: Gate IaC Pipelines6 материалов
The Peril of Hardcoded SecretsЧтениеIaC Scanning and Secret DetectionВидеоEnabling GitHub Secret Scanning and Push ProtectionЧтениеEnforce IaC Security for TechHealthЛабораторнаяKnowledge Check: IaC and Secret ScanningЗаданиеGraded Quiz: Secure DevSecOps PipelinesЗадание
07GenAI Module: The Danger of Prompt Injection5 материалов
The Danger of Prompt InjectionВидеоOWASP for LLMs and Azure AI Content SafetyЧтениеThreat Modeling an AI AppЧтениеHands-on Activity: Architecting AI Security GuardrailsЗаданиеKnowledge Check: GenAI Threat ModelingЗадание
08Project Module: DevSecOps Pipeline4 материалов
Why This Project MattersЧтениеProject Requirements: Control Placement, Blocking Gates, and the Control MatrixЧтениеProject Instructions: Building the Pipeline Diagram and Security Control MatrixЧтениеDevSecOps Pipeline ArchitectureЗадание