Course Outline
Introduction to DevSecOps and the ECDE Framework
- Fundamentals and principles of DevSecOps
- Security challenges inherent in DevOps environments
- Overview of the ECDE examination structure and domains
Establishing a Secure DevOps Culture and Mindset
- Embracing security as a shared organizational responsibility
- Implementing 'shift-left' security practices within the SDLC
- Aligning stakeholders and defining team roles
Integrating Security into CI/CD Pipelines
- Hardening Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments securely
- Securing container builds and performing image scanning
Application Security within DevSecOps
- Static and Dynamic Application Security Testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Conducting secure code reviews and adhering to secure coding standards
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Managing Identity and Access Management (IAM) and policy-as-code
- Implementing DevSecOps in hybrid and multi-cloud environments
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD processes
- Automating compliance requirements (e.g., NIST, ISO, SOC 2)
- Establishing automated remediation and incident response workflows
ECDE Exam Preparation and Final Laboratory
- ECDE exam structure and strategic preparation tips
- Capstone lab project for a DevSecOps pipeline
- Knowledge checks and readiness assessments
Summary and Next Steps
Requirements
- Basic understanding of DevOps workflows and tools
- Familiarity with the Software Development Lifecycle (SDLC)
- Knowledge of application security principles is advantageous
Target Audience
- DevOps engineers
- Application security professionals
- Software developers integrating security into their pipelines
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions