Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Core fundamentals and principles of DevSecOps
- Addressing security challenges within DevOps environments
- An overview of the ECDE exam structure and key domains
Establishing a Secure DevOps Culture and Mindset
- Viewing security as a collective responsibility across teams
- Applying a 'shift left' approach to security within the SDLC
- Aligning stakeholders and defining clear team roles
Integrating Security into CI/CD Pipelines
- Hardening Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments securely
- Ensuring secure container builds and performing image scanning
Application Security within the DevSecOps Context
- Conducting Static and Dynamic Application Security Testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Practising secure code reviews and robust coding standards
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM policies and policy-as-code strategies
- Managing DevSecOps in hybrid and multi-cloud landscapes
Monitoring, Compliance, and Incident Readiness
- Implementing security monitoring and logging within CI/CD
- Automating compliance for frameworks such as NIST, ISO, and SOC 2
- Designing automated remediation and incident response workflows
ECDE Exam Preparation and Final Laboratory
- Understanding the ECDE exam format and preparing with strategic tips
- Completing a comprehensive capstone DevSecOps pipeline lab
- Assessing knowledge and readiness for certification
Summary and Recommended Next Steps
Requirements
- A solid understanding of fundamental DevOps workflows and associated tools
- Familiarity with the Software Development Life Cycle (SDLC)
- Existing knowledge of application security principles is beneficial but not mandatory
Target Audience
- DevOps Engineers
- Application Security Professionals
- Software Developers who integrate security controls into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated