Jump to content

Draft:Practical DevSecOps

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by AP0796 (talk | contribs) at 10:17, 20 June 2025 (Reception: “Resubmitting with NICCS official listing and enhanced third-party citations.”). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Practical DevSecOps

Practical DevSecOps is an online DevSecOps, AI, and Application Security training and certification provider based in San Francisco, California. It offers browser‑hosted labs and hands‑on certifications.[1][2]

Overview

Established in 2018, Practical DevSecOps delivers virtual training environments to simulate real‑world DevOps pipelines. Participants complete timed certification exams—typically lasting 6 to 24 hours—designed to assess applied skills in areas such as static and dynamic testing, secure CI/CD, and cloud infrastructure configurations.[3]

The company’s Certified DevSecOps Professional (CDP) certification is listed in the U.S. government’s NICCS Education & Training Catalog, mapping to the NICE Framework.[4]

Although most information about its curriculum comes from its own materials, community discussions and informal reviews suggest that it emphasizes lab‑based learning using typical security tools and workflows.[5]

The company was also listed among top global DevSecOps training providers in an industry publication by TechTarget.[6]

Reception

Review aggregation on Trustpilot shows a rating of 4.8 out of 5 from over 570 reviews. Users frequently highlight the practical lab setup and real‑world focus as key strengths, while noting occasional interface lag and concerns about course cost and content depth.[1]

Discussions on cybersecurity forums such as *r/devsecops* and *r/cybersecurity* reveal mixed feedback. Some users report that the flagship certification (CDP) suits professionals moving into DevSecOps roles, while others critique it as introductory and not suited for experienced professionals.[2][7]

A blog post reviewing the Certified DevSecOps Professional course describes it as providing “a practical learning experience” featuring over 30 guided lab exercises covering tools like Docker, Ansible, GitLab CI/CD, SAST, and DAST.[3]

Industry Context

Practical DevSecOps operates within the broader trend of "shifting security left," where security practices are applied earlier in the development lifecycle. In academic studies, this approach—referred to as DevSecOps—is recognized as critical for balancing rapid software delivery and security outcomes.[8][9]

National standards bodies like NIST have also released guidance and workshops (e.g., NCCoE DevSecOps project and SP 800‑204C) that reflect best practices integrated into Practical DevSecOps’s training offerings.[10][11]

See also

References

  1. ^ a b https://www.trustpilot.com/review/practical-devsecops.com
  2. ^ a b https://www.reddit.com/r/devsecops/comments/15usg00/practical_devsecops/
  3. ^ a b https://medium.com/@vinit.patil2790/my-certified-devsecops-professional-cdp-course-and-exam-experience-f6488bd0f320
  4. ^ NICCS/CISA entry, "Certified DevSecOps Professional (CDP)", HYSN Technologies Inc. https://niccs.cisa.gov/training/catalog/hysn/certified-devsecops-professional-cdp
  5. ^ https://www.reddit.com/r/devsecops/comments/1k04g08/help_with_recommended_devsecops_learning_material/
  6. ^ Margaret Rouse, "Top DevSecOps certifications and trainings," *TechTarget SearchSecurity*, March 2023. https://www.techtarget.com/searchsecurity/tip/Top-DevSecOps-certifications-and-trainings
  7. ^ https://www.reddit.com/r/cybersecurity/comments/suyykz/appsec_devsecops_training_advice/
  8. ^ Roshan N. Rajapakse et al., “Challenges and solutions when adopting DevSecOps: A systematic review,” *arXiv*, 2021.
  9. ^ Michael Fu et al., “AI for DevSecOps: A Landscape and Future Opportunities,” *arXiv*, 2024.
  10. ^ NCCoE, "Software Supply Chain and DevOps Security Practices," *NIST*, 2022.
  11. ^ NIST SP 800‑204C: "DevSecOps for a Microservices-based Application," NIST, 2022.