Get in Touch

Course Outline

Foundations of DevSecOps and the ECDE Framework

  • Core DevSecOps concepts and guiding principles.
  • Addressing security challenges within DevOps environments.
  • A comprehensive overview of the ECDE exam structure and key domains.

Cultivating a Secure DevOps Mindset

  • Viewing security as a collective team responsibility.
  • Shifting security efforts left within the SDLC.
  • Aligning stakeholder expectations and defining team roles.

Embedding Security into CI/CD Pipelines

  • Enhancing security in Jenkins, GitLab CI, and Azure DevOps pipelines.
  • Managing secrets and configuring environments securely.
  • Building secure containers and performing image scans.

Application Security within DevSecOps

  • Executing static and dynamic application security testing (SAST/DAST).
  • Scanning open-source dependencies using SCA tools.
  • Conducting secure code reviews and following best coding practices.

Infrastructure as Code and Cloud Security

  • Hardening Terraform, Ansible, and Kubernetes configurations.
  • Implementing IAM controls and policy-as-code strategies.
  • Applying DevSecOps principles in hybrid and multi-cloud settings.

Monitoring, Compliance, and Incident Preparedness

  • Setting up security monitoring and logging within CI/CD workflows.
  • Automating compliance with standards like NIST, ISO, and SOC 2.
  • Developing automated remediation and incident response procedures.

ECDE Exam Readiness and Final Practical Lab

  • Understanding the ECDE exam format and effective study tips.
  • Completing a capstone DevSecOps pipeline lab.
  • Undertaking knowledge checks and readiness assessments.

Conclusion and Path Forward

Requirements

  • A solid grasp of fundamental DevOps workflows and associated tools.
  • Working familiarity with the software development lifecycle (SDLC).
  • Basic knowledge of application security principles is advantageous.

Target Audience

  • DevOps engineers
  • Application security professionals
  • Software developers focused on integrating security into their pipelines
 28 Hours

Testimonials (3)

Related Categories