Draft:Practical DevSecOps
![]() | Review waiting, please be patient.
This may take a week or more, since drafts are reviewed in no specific order. There are 218 pending submissions waiting for review.
Where to get help
How to improve a draft
You can also browse Wikipedia:Featured articles and Wikipedia:Good articles to find examples of Wikipedia's best writing on topics similar to your proposed article. Improving your odds of a speedy review To improve your odds of a faster review, tag your draft with relevant WikiProject tags using the button below. This will let reviewers know a new draft has been submitted in their area of interest. For instance, if you wrote about a female astronomer, you would want to add the Biography, Astronomy, and Women scientists tags. Editor resources
Reviewer tools
|
Practical DevSecOps
Practical DevSecOps is an online DevSecOps, AI, and Application Security training and certification provider based in San Francisco, California. It offers browser‑hosted labs and hands‑on certifications.[1][2]
Overview
Established in 2018, Practical DevSecOps delivers virtual training environments to simulate real‑world DevOps pipelines. Participants complete timed certification exams—typically lasting 6 to 24 hours—designed to assess applied skills in areas such as static and dynamic testing, secure CI/CD, and cloud infrastructure configurations.[3]
The company’s Certified DevSecOps Professional (CDP) certification is listed in the U.S. government’s NICCS Education & Training Catalog, mapping to the NICE Framework.[4]
Although most information about its curriculum comes from its own materials, community discussions and informal reviews suggest that it emphasizes lab‑based learning using typical security tools and workflows.[5]
The company was also listed among top global DevSecOps training providers in an industry publication by TechTarget.[6]
Reception
Review aggregation on Trustpilot shows a rating of 4.8 out of 5 from over 570 reviews. Users frequently highlight the practical lab setup and real‑world focus as key strengths, while noting occasional interface lag and concerns about course cost and content depth.[1]
Discussions on cybersecurity forums such as *r/devsecops* and *r/cybersecurity* reveal mixed feedback. Some users report that the flagship certification (CDP) suits professionals moving into DevSecOps roles, while others critique it as introductory and not suited for experienced professionals.[2][7]
A blog post reviewing the Certified DevSecOps Professional course describes it as providing “a practical learning experience” featuring over 30 guided lab exercises covering tools like Docker, Ansible, GitLab CI/CD, SAST, and DAST.[3]
Industry Context
Practical DevSecOps operates within the broader trend of "shifting security left," where security practices are applied earlier in the development lifecycle. In academic studies, this approach—referred to as DevSecOps—is recognized as critical for balancing rapid software delivery and security outcomes.[8][9]
National standards bodies like NIST have also released guidance and workshops (e.g., NCCoE DevSecOps project and SP 800‑204C) that reflect best practices integrated into Practical DevSecOps’s training offerings.[10][11]
See also
- DevSecOps
- Application security
- Threat modeling
- Container security
- Secure software development lifecycle
- Infrastructure as Code
- AI Security
References
- ^ a b https://www.trustpilot.com/review/practical-devsecops.com
- ^ a b https://www.reddit.com/r/devsecops/comments/15usg00/practical_devsecops/
- ^ a b https://medium.com/@vinit.patil2790/my-certified-devsecops-professional-cdp-course-and-exam-experience-f6488bd0f320
- ^ NICCS/CISA entry, "Certified DevSecOps Professional (CDP)", HYSN Technologies Inc. https://niccs.cisa.gov/training/catalog/hysn/certified-devsecops-professional-cdp
- ^ https://www.reddit.com/r/devsecops/comments/1k04g08/help_with_recommended_devsecops_learning_material/
- ^ Margaret Rouse, "Top DevSecOps certifications and trainings," *TechTarget SearchSecurity*, March 2023. https://www.techtarget.com/searchsecurity/tip/Top-DevSecOps-certifications-and-trainings
- ^ https://www.reddit.com/r/cybersecurity/comments/suyykz/appsec_devsecops_training_advice/
- ^ Roshan N. Rajapakse et al., “Challenges and solutions when adopting DevSecOps: A systematic review,” *arXiv*, 2021.
- ^ Michael Fu et al., “AI for DevSecOps: A Landscape and Future Opportunities,” *arXiv*, 2024.
- ^ NCCoE, "Software Supply Chain and DevOps Security Practices," *NIST*, 2022.
- ^ NIST SP 800‑204C: "DevSecOps for a Microservices-based Application," NIST, 2022.