Course Outline
Introduction to DevSecOps and the ECDE Framework
- Fundamentals and principles of DevSecOps
- Security challenges within DevOps environments
- Overview of the ECDE exam and its domains
Cultivating a Secure DevOps Culture and Mindset
- Adopting security as a shared responsibility
- Implementing 'shift-left' security within the SDLC
- Aligning stakeholders and defining team roles
Integrating Security into CI/CD Pipelines
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and environment configurations
- Ensuring secure container builds and image scanning
Application Security within DevSecOps
- Static and dynamic application security testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Conducting secure code reviews and adhering to secure coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Managing IAM and policy-as-code
- Implementing DevSecOps in hybrid and multi-cloud environments
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD processes
- Automating compliance (e.g., NIST, ISO, SOC 2)
- Establishing automated remediation and incident response workflows
ECDE Exam Preparation and Final Lab
- Understanding the ECDE exam structure and preparation strategies
- Completing the capstone DevSecOps pipeline lab
- Undergoing knowledge checks and readiness assessments
Summary and Next Steps
Requirements
- Understanding of fundamental DevOps workflows and tools
- Familiarity with the software development lifecycle (SDLC)
- Knowledge of application security principles is beneficial
Audience
- DevOps engineers
- Application security professionals
- Software developers integrating security into pipelines
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 5200 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated