Course Outline
Introduction to DevSecOps and the ECDE Framework
- Core concepts and principles of DevSecOps
- Security challenges specific to DevOps environments
- Overview of the ECDE exam structure and key domains
Cultivating a Secure DevOps Culture and Mindset
- Viewing security as a collective responsibility
- Shifting security left within the SDLC
- Aligning stakeholders and defining team roles
Integrating Security into CI/CD Pipelines
- Securing pipelines in Jenkins, GitLab CI, and Azure DevOps
- Managing secrets and configuring environments securely
- Building secure containers and scanning images
Application Security within DevSecOps
- Conducting static and dynamic application security testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Performing secure code reviews and adhering to best practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM and policy-as-code strategies
- Applying DevSecOps principles in hybrid and multi-cloud settings
Monitoring, Compliance, and Incident Preparedness
- Establishing security monitoring and logging within CI/CD
- Automating compliance for standards such as NIST, ISO, and SOC 2
- Setting up automated remediation and incident response workflows
ECDE Exam Preparation and Final Laboratory
- Understanding the ECDE exam format and preparation strategies
- Completing a capstone DevSecOps pipeline lab
- Participating in knowledge checks and readiness assessments
Summary and Future Directions
Requirements
- A solid grasp of fundamental DevOps workflows and associated tools
- Familiarity with the Software Development Life Cycle (SDLC)
- Background knowledge in application security principles is an advantage
Target Audience
- DevOps engineers
- Application security specialists
- Software developers looking to integrate security into their pipelines
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions