Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Foundations and principles of DevSecOps.
- Security challenges prevalent in DevOps environments.
- Overview of the ECDE exam structure and domains.
Fostering a Secure DevOps Culture and Mindset
- Recognising security as a shared responsibility.
- Implementing the 'shift left' approach to security within the SDLC.
- Aligning stakeholders and defining team roles.
Integrating Security into CI/CD Pipelines
- Securing pipelines in Jenkins, GitLab CI, and Azure DevOps.
- Managing secrets and environment configurations.
- Ensuring secure container builds and image scanning.
Application Security within DevSecOps
- Conducting Static and Dynamic Application Security Testing (SAST/DAST).
- Scanning open-source dependencies using SCA tools.
- Adopting secure code review processes and coding best practices.
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes.
- Implementing IAM and policy-as-code strategies.
- Navigating DevSecOps in hybrid and multi-cloud environments.
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD.
- Automating compliance (e.g., NIST, ISO, SOC 2).
- Establishing automated remediation and incident response workflows.
ECDE Exam Preparation and Final Lab
- ECDE exam structure and preparation tips.
- Capstone DevSecOps pipeline lab exercise.
- Knowledge checks and readiness assessment.
Summary and Next Steps
Requirements
- Understanding of fundamental DevOps workflows and tools.
- Familiarity with the software development lifecycle (SDLC).
- Knowledge of application security principles is advantageous.
Audience
- DevOps engineers.
- Application security professionals.
- Software developers integrating security into their pipelines.
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated