Get in Touch

Course Outline

Introduction to DevSecOps and the ECDE Framework

  • Foundations and core principles of DevSecOps.
  • Addressing security challenges within DevOps environments.
  • A comprehensive overview of the ECDE exam structure and domains.

Cultivating a Secure DevOps Culture and Mindset

  • Embracing security as a collective responsibility.
  • Implementing the "shift left" strategy within the SDLC.
  • Aligning stakeholders and defining team roles.

Security Integration in CI/CD Pipelines

  • Enhancing security in Jenkins, GitLab CI, and Azure DevOps pipelines.
  • Managing secrets and configuring environments securely.
  • Building secure containers and conducting image scanning.

Application Security within DevSecOps

  • Utilizing Static and Dynamic Application Security Testing (SAST/DAST).
  • Scanning open-source dependencies using SCA tools.
  • Conducting secure code reviews and adhering to best coding practices.

Infrastructure as Code and Cloud Security

  • Securing configurations for Terraform, Ansible, and Kubernetes.
  • Implementing IAM and policy-as-code strategies.
  • Applying DevSecOps principles in hybrid and multi-cloud settings.

Monitoring, Compliance, and Incident Preparedness

  • Setting up security monitoring and logging within CI/CD.
  • Automating compliance for standards like NIST, ISO, and SOC 2.
  • Designing automated remediation and incident response workflows.

ECDE Exam Preparation and Final Laboratory

  • Analyzing the ECDE exam structure and sharing preparation strategies.
  • Completing a capstone DevSecOps pipeline laboratory.
  • Undertaking knowledge checks and readiness assessments.

Summary and Future Directions

Requirements

  • A solid grasp of fundamental DevOps workflows and associated tools.
  • Basic familiarity with the software development lifecycle (SDLC).
  • Background knowledge of application security principles is advantageous.

Target Audience

  • DevOps engineers.
  • Application security professionals.
  • Software developers aiming to embed security into their pipelines.
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories