Trustworthy Software Lab
Module 3

DevSecOps & Secure SDLC

Security is not a final-stage activity. It runs alongside every step of delivery.

Traditional mistake vs better approach

Traditional mistake

Build first. Deploy first. Think about security later.

Better approach

Plan security early. Scan code and dependencies. Review infrastructure. Protect secrets. Deploy with controls. Monitor continuously.

Secure SDLC flow

Plan→
Code→
Build→
Test→
Security Scan→
Deploy→
Monitor→
Audit

DevSecOps practices

Code review
Secret scanning
Dependency scanning
SAST
Container scanning
IaC scanning
Policy checks
Deployment approvals
Runtime monitoring

Student project upgrade

Instead of submitting only a working project, add artifacts that create stronger proof of work:

  • Architecture diagram
  • Threat model
  • IAM permission plan
  • Logging plan
  • Security checklist
  • Deployment workflow
Outcome
Reviewers see engineering thinking, not just a demo screen.