Draft:Certified DevSecOps Professional

The Certified DevSecOps Professional (CDP) is a practitioner-level certification in DevSecOps issued by Practical DevSecOps, a subsidiary of HYSN Technologies Inc. The certification evaluates competency in integrating security practices into continuous integration and continuous delivery (CI/CD) pipelines and is listed in the CISA national training catalog.

Issuing organization

Practical DevSecOps is operated by HYSN Technologies Inc., incorporated in Delaware with offices in Newark, New Jersey, and Singapore. The company was founded by Mohammed A. Imran, a security professional who delivered training at Black Hat USA 2018 titled "Practical DevSecOps: Continuous Security in the Age of Cloud."[1] Practical DevSecOps instructors have also delivered training at Hack In The Box (HITB) international security conferences, including HITBSecConf Singapore and HITB CyberWeek.[2][3]

Certification

The CDP is included in the Cybersecurity and Infrastructure Security Agency (CISA) National Initiative for Cybersecurity Careers and Studies (NICCS) training catalog.[4] TechTarget's SearchSecurity listed the CDP among recommended DevSecOps certifications for cybersecurity professionals, alongside offerings from DevOps Institute, EXIN, and EC-Council.[5]

Exam format

The CDP exam consists of five scenario-based challenges administered within a 12-hour hands-on window, followed by a 24-hour period for report submission. Candidates must achieve a minimum score of 80% to pass. The examination contains no multiple-choice questions; performance is assessed entirely within a live lab environment.[6]

Course curriculum

The preparatory course covers nine modules including CI/CD pipeline security, static application security testing (SAST), dynamic application security testing (DAST), infrastructure as code (IaC), compliance as code (CaC), software composition analysis (SCA), and vulnerability management.[6] The certification carries no expiration date and does not require periodic recertification.[6]

See also

References

  1. ^ "Practical DevSecOps – Continuous Security in the Age of Cloud". Black Hat. Retrieved 2026-06-18.
  2. ^ "Mohammed A. Imran – HITBSecTrain". Hack In The Box. Retrieved 2026-06-18.
  3. ^ "Secure Coding and DevSecOps – HITB CyberWeek 2020". HITBSecTrain. Retrieved 2026-06-18.
  4. ^ "Certified DevSecOps Professional (CDP) – NICCS Training Catalog". National Initiative for Cybersecurity Careers and Studies, Cybersecurity and Infrastructure Security Agency. Retrieved 2026-06-18.
  5. ^ "Top DevSecOps certifications and trainings". SearchSecurity. TechTarget. Retrieved 2026-06-18.
  6. ^ a b c "Certified DevSecOps Professional (CDP)". Practical DevSecOps. Retrieved 2026-06-18.

Category:Computer security certifications Category:DevOps Category:Professional certifications in computing

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.