19장. 8주 DevSecOps 캡스톤
1주는 자산·흐름·위협, 2주는 ASVS 요구 mapping, 3주는 인증·세션, 4주는 tenant 인가·입력, 5주는 file·SSRF·비밀, 6주는 공급망·Kubernetes, 7주는 scanner와 수동 검토, 8주는 incident drill이다.
제출물은 위협 모델, ASVS matrix, negative authorization tests, secret rotation runbook, SBOM·scan 결과, security headers, log redaction evidence, incident timeline이다. 발견 0건이 아니라 알려진 위험과 승인된 처리 상태를 보여 준다.