Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and ECDE Framework
- Foundational concepts and principles of DevSecOps
- Security challenges prevalent in DevOps environments
- Overview of the ECDE examination and its domains
Secure DevOps Culture and Mindset
- Understanding security as a shared organisational responsibility
- Implementing 'shift-left' security strategies in the SDLC
- Aligning stakeholders and defining team roles
Integrating Security in CI/CD Pipelines
- Securing pipelines in Jenkins, GitLab CI, and Azure DevOps
- Managing secrets and configuring environments securely
- Ensuring secure container builds and conducting image scanning
Application Security in DevSecOps
- Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
- Scanning open-source dependencies using Software Composition Analysis (SCA) tools
- Conducting secure code reviews and adhering to best coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing Identity and Access Management (IAM) and policy-as-code
- Implementing DevSecOps in hybrid and multi-cloud environments
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD pipelines
- Automating compliance with standards such as NIST, ISO, and SOC 2
- Establishing automated remediation and incident response workflows
ECDE Exam Preparation and Final Lab
- Understanding the ECDE exam structure and receiving preparation tips
- Completing a capstone DevSecOps pipeline lab
- Undergoing knowledge checks and readiness assessments
Summary and Next Steps
Requirements
- Understanding of fundamental DevOps workflows and tools
- Familiarity with the software development lifecycle (SDLC)
- Knowledge of application security principles is advantageous
Audience
- DevOps engineers
- Application security professionals
- Software developers integrating security measures into pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated