Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Fundamentals and core principles of DevSecOps.
- Security challenges specific to DevOps environments.
- Overview of the ECDE exam structure and key domains.
Building a Secure DevOps Culture and Mindset
- Treating security as a shared organizational responsibility.
- Shifting security activities earlier in the SDLC.
- Aligning stakeholders and defining team roles.
Integrating Security into CI/CD Pipelines
- Securing pipelines in Jenkins, GitLab CI, and Azure DevOps.
- Managing secrets and configuring secure environments.
- Executing secure container builds and performing image scans.
Application Security within DevSecOps
- Conducting static and dynamic application security testing (SAST/DAST).
- Scanning open-source dependencies using SCA tools.
- Performing secure code reviews and adhering to best practices.
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes.
- Implementing IAM and policy-as-code strategies.
- Applying DevSecOps in hybrid and multi-cloud settings.
Monitoring, Compliance, and Incident Readiness
- Implementing security monitoring and logging in CI/CD.
- Automating compliance with standards such as NIST, ISO, and SOC 2.
- Setting up automated remediation and incident response workflows.
ECDE Exam Preparation and Final Lab
- Tips for understanding the ECDE exam structure and preparation.
- A comprehensive capstone DevSecOps pipeline lab.
- Knowledge checks and final readiness assessments.
Summary and Next Steps
Requirements
- A solid understanding of fundamental DevOps workflows and associated tools.
- Familiarity with the software development lifecycle (SDLC).
- Background knowledge of application security principles is beneficial.
Target Audience
- DevOps engineers.
- Professionals specializing in application security.
- Software developers seeking to integrate security into their pipelines.
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions