Get in Touch

Course Outline

Introduction to DevSecOps and the ECDE Framework

  • Foundational concepts and principles of DevSecOps
  • Common security challenges within DevOps environments
  • Overview of the ECDE examination structure and key domains

Fostering a Secure DevOps Culture and Mindset

  • Establishing security as a collective responsibility
  • The concept of 'shifting left' to incorporate security earlier in the SDLC
  • Aligning stakeholders and defining team roles

Integrating Security into CI/CD Pipelines

  • Hardening Jenkins, GitLab CI, and Azure DevOps pipelines
  • Managing secrets and configuring environments securely
  • Executing secure container builds and performing image scanning

Application Security within DevSecOps

  • Conducting Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  • Scanning open-source dependencies using Software Composition Analysis (SCA) tools
  • Performing secure code reviews and adhering to best coding practices

Infrastructure as Code and Cloud Security

  • Securing configurations for Terraform, Ansible, and Kubernetes
  • Implementing Identity and Access Management (IAM) and policy-as-code
  • Navigating DevSecOps in hybrid and multi-cloud settings

Monitoring, Compliance, and Incident Readiness

  • Implementing security monitoring and logging within CI/CD processes
  • Automating compliance with standards such as NIST, ISO, and SOC 2
  • Establishing automated remediation and incident response workflows

ECDE Exam Preparation and Final Lab Session

  • Understanding the ECDE exam structure and preparation strategies
  • Completing a capstone DevSecOps pipeline lab
  • Undergoing knowledge checks and readiness assessments

Summary and Next Steps

Requirements

  • Fundamental understanding of DevOps workflows and associated tools
  • Familiarity with the Software Development Lifecycle (SDLC)
  • Prior knowledge of application security principles is advantageous

Target Audience

  • DevOps engineers
  • Application security specialists
  • Software developers focused on integrating security into CI/CD pipelines
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories