Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of DevSecOps and the ECDE Framework
- Core DevSecOps fundamentals and guiding principles
- Addressing security challenges within DevOps environments
- Overview of the ECDE exam structure and key domains
Cultivating a Secure DevOps Culture and Mindset
- Security as a collective team responsibility
- Shifting security practices left within the SDLC
- Aligning stakeholders and defining team roles
Embedding Security in CI/CD Pipelines
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments securely
- Building secure containers and performing image scanning
Application Security within DevSecOps
- Static and dynamic application security testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Conducting secure code reviews and adhering to best coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM and policy-as-code strategies
- Applying DevSecOps in hybrid and multi-cloud settings
Monitoring, Compliance, and Incident Readiness
- Implementing security monitoring and logging within CI/CD
- Automating compliance for standards such as NIST, ISO, and SOC 2
- Developing automated remediation and incident response workflows
ECDE Exam Preparation and Final Laboratory
- Understanding the ECDE exam structure and effective preparation tips
- Executing a capstone DevSecOps pipeline lab
- Completing knowledge checks and readiness assessments
Course Summary and Future Pathways
Requirements
- A solid understanding of fundamental DevOps workflows and associated tools.
- Familiarity with the Software Development Life Cycle (SDLC).
- A working knowledge of application security principles is advantageous.
Target Audience
- DevOps Engineers
- Application Security Professionals
- Software Developers integrating security measures into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated