Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to DevSecOps and the ECDE Framework
- Foundations and principles of DevSecOps
- Security challenges inherent in DevOps environments
- Overview of the ECDE exam and its domains
Cultivating a Secure DevOps Culture and Mindset
- Security as a collective responsibility
- Moving security left within the SDLC
- Aligning stakeholders and defining team roles
Integrating Security into CI/CD Pipelines
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments
- Secure container builds and image scanning
Application Security within DevSecOps
- Static and dynamic application security testing (SAST/DAST)
- Open-source dependency scanning using SCA tools
- Conducting secure code reviews and adhering to best practices
Infrastructure as Code and Cloud Security
- Securing Terraform, Ansible, and Kubernetes configurations
- IAM policies and policy-as-code
- Implementing DevSecOps in hybrid and multi-cloud settings
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD
- Automating compliance (e.g., NIST, ISO, SOC 2)
- Automated remediation and incident response workflows
ECDE Exam Preparation and Final Lab
- Structure of the ECDE exam and preparation strategies
- Capstone DevSecOps pipeline lab exercise
- Knowledge checks and readiness assessment
Summary and Next Steps
Requirements
- Knowledge of fundamental DevOps workflows and tools
- Understanding of the software development lifecycle (SDLC)
- Familiarity with application security principles is advantageous
Target Audience
- DevOps engineers
- Application security specialists
- Software developers tasked with embedding security into pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated