Module 3
DevSecOps & Secure SDLC
Security is not a final-stage activity. It runs alongside every step of delivery.
Traditional mistake vs better approach
Traditional mistake
Build first. Deploy first. Think about security later.
Better approach
Plan security early. Scan code and dependencies. Review infrastructure. Protect secrets. Deploy with controls. Monitor continuously.
Secure SDLC flow
Plan→
Code→
Build→
Test→
Security Scan→
Deploy→
Monitor→
Audit
DevSecOps practices
Code review
Secret scanning
Dependency scanning
SAST
Container scanning
IaC scanning
Policy checks
Deployment approvals
Runtime monitoring
Student project upgrade
Instead of submitting only a working project, add artifacts that create stronger proof of work:
- Architecture diagram
- Threat model
- IAM permission plan
- Logging plan
- Security checklist
- Deployment workflow
Outcome
Reviewers see engineering thinking, not just a demo screen.