Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC525 DevSecOps and Automation
This unit covers key principles and practices of DevSecOps, which integrates security practices within the DevOps lifecycle. It explores the automation of security processes and continuous monitoring to ensure that security is embedded from the outset of software development through to deployment. Students will gain hands-on experience in implementing security automation tools, performing vulnerability scans, and ensuring compliance within an agile development environment. The unit focuses on securing the DevOps pipeline, continuous integration/continuous deployment (CI/CD) processes, and using automation to detect, mitigate, and respond to security vulnerabilities efficiently.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
ITC404 Foundations of Cybersecurity OR ITC507 Secure Software Development and Code Auditing and ITC511 Networking and Systems Security
UNIT LEARNING OUTCOMES
- Critically review and interpret principles and practices of DevSecOps
- Critically assess the role of security in continuous integration and continuous deployment (CI/CD) processes
- Devise and implement security automation strategies, including vulnerability management, security scanning, and automated testing, within DevOps environments
- Critically evaluate the effectiveness of security practices and tools used in DevSecOps pipelines, identifying vulnerabilities and proposing solutions to enhance security and compliance
- Propose and articulate emerging trends and challenges in DevSecOps to persuade specialists and non-specialists
CONTENT
- The role of security in the DevOps lifecycle
- Continuous integration and continuous deployment (CI/CD) with GitHub Actions
- Container security & image scanning
- Tools for security automation in DevOps
- Vulnerability management and security scanning
- Automating security testing and code quality analysis in DevOps pipelines
- Managing secrets, configurations, and compliance in DevSecOps
- Compliance automation: ISO 27001 controls mapping
- IaC security & policy-as-code
- Guest-speaker webinar 1 – ISO 27001 in automated pipelines (AWS CISO)
- Future trends in DevSecOps and security automation
ASSESSMENT METHODS
- DevSecOps Pipeline Security Assessment & Demo – 30%
- Group Compliance-as-Code Blueprint – 30%
- DevSecOps Implementation Portfolio – 40%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












