Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Foundations and core principles of DevSecOps.
- Navigating security challenges within modern DevOps environments.
- A comprehensive overview of the ECDE exam structure and domains.
Building a Secure DevOps Culture and Mindset
- Embracing security as a collective, shared responsibility.
- Implementing the “shift-left” approach in the SDLC.
- Aligning stakeholders and defining clear team roles.
Embedding Security in CI/CD Pipelines
- Hardening Jenkins, GitLab CI, and Azure DevOps pipelines.
- Managing secrets and configuring environments securely.
- Ensuring secure container builds and conducting image scanning.
Application Security within DevSecOps
- Utilizing Static and Dynamic Application Security Testing (SAST/DAST).
- Scanning open-source dependencies using SCA tools.
- Conducting secure code reviews and adhering to best coding practices.
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes.
- Implementing IAM and policy-as-code strategies.
- Applying DevSecOps principles in hybrid and multi-cloud settings.
Monitoring, Compliance, and Incident Readiness
- Establishing security monitoring and logging within CI/CD.
- Automating compliance for frameworks such as NIST, ISO, and SOC 2.
- Designing workflows for automated remediation and incident response.
ECDE Exam Preparation and Final Laboratory
- Strategies for ECDE exam structure and effective preparation.
- Completing a capstone DevSecOps pipeline project.
- Conducting knowledge checks and readiness assessments.
Summary and Future Directions
Requirements
- A foundational understanding of standard DevOps workflows and associated tools.
- General familiarity with the Software Development Lifecycle (SDLC).
- While not mandatory, prior knowledge of application security principles is beneficial.
Target Audience
- DevOps Engineers.
- Application Security Professionals.
- Software Developers focused on integrating security into their pipelines.
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated