4Develop a Security and Compliance Plan
- 4.1Integrating Security into Pipelines (DevSecOps)
Understand shifting security left—SAST/DAST, dependency scanning, container image scanning, IaC scanning, and GitHub Advanced Security. Detect vulnerabilities early in the pipeline.
- 4.2Managing Secrets and Credentials
Understand handling secrets safely—Key Vault, variable groups/secret variables, managed identity/workload identity federation, secret scanning, and least privilege. Prevent credential leakage.
- 4.3Compliance and Governance
Understand control and trails—approvals/audit logs, Azure Policy, environment protection (checks), license/compliance management, and separation of duties. Meet regulatory requirements while shipping fast.

