Get in Touch

Course Outline

Introduction to DevSecOps and the ECDE Framework

  • DevSecOps fundamentals and core principles
  • Security challenges within DevOps environments
  • Overview of the ECDE exam structure and domains

Building a Secure DevOps Culture and Mindset

  • Security as a collective responsibility
  • Shifting security left within the SDLC
  • Aligning stakeholders and defining team roles

Integrating Security into CI/CD Pipelines

  • Securing Jenkins, GitLab CI, and Azure DevOps pipelines
  • Managing secrets and configuring environments
  • Ensuring secure container builds and image scanning

Application Security in a DevSecOps Context

  • Static and Dynamic Application Security Testing (SAST/DAST)
  • Scanning open-source dependencies using SCA tools
  • Conducting secure code reviews and adhering to best coding practices

Infrastructure as Code and Cloud Security

  • Securing Terraform, Ansible, and Kubernetes configurations
  • Implementing IAM and policy-as-code
  • Applying DevSecOps in hybrid and multi-cloud environments

Monitoring, Compliance, and Incident Readiness

  • Security monitoring and logging within CI/CD
  • Automating compliance (e.g., NIST, ISO, SOC 2)
  • Workflow automation for remediation and incident response

ECDE Exam Preparation and Final Lab

  • ECDE exam format and preparation strategies
  • Capstone DevSecOps pipeline project
  • Knowledge checks and readiness assessments

Summary and Next Steps

Requirements

  • A solid grasp of fundamental DevOps workflows and associated tools
  • Familiarity with the Software Development Life Cycle (SDLC)
  • Background knowledge of application security principles is beneficial

Target Audience

  • DevOps Engineers
  • Application Security Specialists
  • Software Developers integrating security into their pipelines
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories