Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Zero Trust Fundamentals
- Transition from perimeter-based security to Zero Trust
- Core Zero Trust principles: never trust, always verify, and least privilege
- The NIST SP 800-207 Zero Trust Architecture framework
- Zero Trust compared to traditional network security models
- The open-source ecosystem supporting Zero Trust implementation
Components of Zero Trust Architecture
- Identity as the new security perimeter
- Device trust and posture validation
- Network segmentation and micro-segmentation
- Protection of application workloads
- Data classification and protection strategies
- Policy enforcement and decision points
Identity Foundation for Zero Trust
- Identity providers: Keycloak, Authentik, and Dex
- Integration of OAuth 2.0, OIDC, and SAML
- Implementation of multi-factor authentication
- Risk-based authentication and step-up authentication
- Management of the identity lifecycle
- Identity proofing and verification processes
Device Trust and Posture
- Device enrollment and attestation
- Device compliance checks using tools like Kolide and OSQuery
- Integration of Endpoint Detection and Response (EDR)
- Certificate-based device authentication
- MDM integration for collecting posture data
- Continuous assessment of device trust
Network-Level Zero Trust
- Concepts of Software-Defined Perimeter (SDP)
- Open-source SDP implementations
- Micro-segmentation using OVN, Cilium, and Calico
- Zero Trust Network Access (ZTNA) architecture
- Replacing traditional VPNs with Zero Trust access
- Managing network policies as code
Identity-Aware Proxies and Access Gateways
- Pomerium: architecture of identity-aware proxies
- Using vouch-proxy for nginx/Apache integration
- Deployment and configuration of OAuth2 Proxy
- Traefik with forward authentication capabilities
- Kong Gateway utilizing OIDC plugins
- Configuration and enforcement of access policies
Service Mesh for Zero Trust
- Service mesh as a Zero Trust fabric
- Zero Trust configuration in Istio
- Secure deployment patterns with Linkerd
- Universal mTLS: service-to-service authentication
- SPIFFE/SPIRE for workload identity management
- Authorization policies within the service mesh
- Trust domains for multi-cluster service meshes
PKI and Certificate Management
- Certificate-based authentication in a Zero Trust context
- Smallstep CA for managing workload identities
- HashiCorp Vault PKI engine
- Automation of certificate rotation and lifecycle
- Establishing internal trust via Private CA
- Certificate transparency and monitoring
Secrets Management
- Managing secrets with HashiCorp Vault
- Sealed Secrets for Kubernetes environments
- External Secrets Operator
- SOPS: Secrets OPerationS
- Dynamic secrets and automatic rotation
- Patterns for injecting secrets into applications
Policy as Code and Authorization
- Open Policy Agent (OPA) fundamentals
- Basics of the Rego policy language
- Using OPA with Kubernetes admission control
- Using OPA with Envoy for service authorization
- Integrating OPA with API gateways
- Testing and validating policies
- Apache APISIX with OPA integration
API Security in Zero Trust
- Security patterns for API gateways
- Kong open source with security plugins
- Implementing rate limiting and DDoS protection
- API authentication and authorization
- Security considerations for GraphQL
- API discovery and detection of shadow APIs
Data Protection and DLP
- Frameworks for data classification
- Integration of open-source DLP tools
- Encryption in transit and at rest
- Strategies for tokenization and masking
- Data loss prevention policies
- Sovereign data handling within Zero Trust
Continuous Authentication and Authorization
- Session management in Zero Trust environments
- Mechanisms for continuous authentication
- Context-aware access decisions
- Risk scoring and dynamic authorization
- Triggers for step-up authentication
- Real-time policy enforcement
Monitoring and Observability in Zero Trust
- Collection of security telemetry
- SIEM integration with open-source tools
- User and entity behavior analytics (UEBA)
- Audit logging and compliance reporting
- Anomaly detection leveraging machine learning
- Security dashboards and alerting systems
Zero Trust for Cloud-Native Workloads
- Container security in a Zero Trust context
- Management of ephemeral workload identities
- Admission controllers for enforcing Zero Trust
- Runtime security using Falco and Tetragon
- Network policies for container segmentation
- Patterns for immutable infrastructure
Implementing a Zero Trust Roadmap
- Maturity assessment and gap analysis
- Phased implementation strategy
- Design and execution of pilot projects
- Change management and user adoption
- Measuring Zero Trust success metrics
- Avoiding common challenges and pitfalls
Production Deployment and Operations
- High availability design patterns
- Disaster recovery for Zero Trust infrastructure
- Performance optimization strategies
- Troubleshooting authentication and authorization issues
- Upgrading and patching Zero Trust components
- Creating documentation and runbooks
The Future of Zero Trust and Open Source
- Emerging standards and protocols
- Quantum-safe Zero Trust considerations
- Role of AI/ML in Zero Trust decisions
- Federated Zero Trust architectures
- Community resources and ongoing development
- Summary and next steps
Requirements
- Solid grasp of network security concepts and principles
- Hands-on experience with identity and access management systems
- Understanding of PKI, certificates, and encryption fundamentals
- Aquaintance with microservices and container-based architectures
- Track record in deploying and managing open-source software
Intended Audience
- Security Architects and Engineers
- Infrastructure Architects shaping modern security postures
- DevSecOps Engineers integrating security into pipelines
- Network Administrators shifting towards Zero Trust models
35 Hours