Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of DevSecOps and the ECDE Framework
- Core fundamentals and guiding principles of DevSecOps.
- Addressing security challenges within DevOps environments.
- An overview of the ECDE exam structure and key domains.
Cultivating a Secure DevOps Mindset
- Establishing security as a shared team responsibility.
- The concept of shifting security left within the SDLC.
- Aligning stakeholders and defining clear team roles.
Embedding Security in CI/CD Pipelines
- Securing workflows in Jenkins, GitLab CI, and Azure DevOps.
- Managing secrets and configuring environments securely.
- Performing secure container builds and conducting image scans.
Application Security in a DevSecOps Context
- Implementing Static and Dynamic Application Security Testing (SAST/DAST).
- Utilizing Software Composition Analysis (SCA) tools for open-source dependency scanning.
- Conducting secure code reviews and adhering to best coding practices.
Infrastructure as Code and Cloud Security
- Hardening configurations for Terraform, Ansible, and Kubernetes.
- Applying Identity and Access Management (IAM) and policy-as-code.
- Implementing DevSecOps strategies in hybrid and multi-cloud setups.
Monitoring, Compliance, and Incident Preparedness
- Enhancing security monitoring and logging capabilities in CI/CD.
- Automating compliance processes for standards like NIST, ISO, and SOC 2.
- Designing automated remediation and incident response workflows.
ECDE Exam Readiness and Capstone Lab
- Understanding the ECDE exam format and effective preparation strategies.
- Completing a comprehensive capstone DevSecOps pipeline lab.
- Participating in knowledge checks and readiness assessments.
Wrap-up and Future Directions
Requirements
- A solid grasp of fundamental DevOps workflows and associated tools.
- Working knowledge of the software development lifecycle (SDLC).
- While not mandatory, a background in application security principles is beneficial.
Target Audience
- DevOps Engineers.
- Application Security Specialists.
- Software Developers focused on integrating security into their pipelines.
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated