Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Foundations and principles of DevSecOps.
- Security challenges inherent in DevOps environments.
- Overview of the ECDE examination and its domains.
Fostering a Secure DevOps Culture and Mindset
- Emphasizing security as a collective responsibility.
- Implementing 'shift-left' security within the SDLC.
- Aligning stakeholders and defining team roles.
Integrating Security into CI/CD Pipelines
- Securing pipelines in Jenkins, GitLab CI, and Azure DevOps.
- Managing secrets and configuring environments securely.
- Conducting secure container builds and image scanning.
Application Security in DevSecOps
- Static and dynamic application security testing (SAST/DAST).
- Scanning for vulnerabilities in open-source dependencies (SCA tools).
- Practicing secure code reviews and coding standards.
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes.
- Implementing Identity and Access Management (IAM) and policy-as-code.
- Deploying DevSecOps in hybrid and multi-cloud environments.
Monitoring, Compliance, and Incident Readiness
- Establishing security monitoring and logging within CI/CD.
- Automating compliance with standards such as NIST, ISO, and SOC 2.
- Streamlining automated remediation and incident response processes.
ECDE Exam Preparation and Final Lab
- Understanding the ECDE exam structure and preparation strategies.
- Completing a capstone DevSecOps pipeline lab.
- Engaging in knowledge checks and readiness assessments.
Summary and Next Steps
Requirements
- Familiarity with fundamental DevOps workflows and tools.
- Understanding of the software development lifecycle (SDLC).
- Knowledge of application security principles is advantageous.
Target Audience
- DevOps engineers.
- Application security specialists.
- Software developers integrating security into their pipelines.
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated