Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of DevSecOps and the ECDE Framework
- Core DevSecOps fundamentals and guiding principles
- Addressing security challenges within DevOps environments
- Overview of the ECDE examination structure and subject domains
Cultivating a Secure DevOps Culture and Mindset
- Recognizing security as a collective team responsibility
- Implementing 'shift-left' security strategies within the SDLC
- Aligning stakeholders and defining team roles for security
Embedding Security in CI/CD Pipelines
- Securing workflows in Jenkins, GitLab CI, and Azure DevOps
- Managing secrets and configuring secure environments
- Ensuring secure container builds and conducting image scanning
Application Security in a DevSecOps Context
- Utilizing Static and Dynamic Application Security Testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Conducting secure code reviews and enforcing best coding practices
Infrastructure as Code and Cloud Security Considerations
- Securing configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM strategies and policy-as-code
- Applying DevSecOps practices in hybrid and multi-cloud settings
Monitoring, Compliance, and Incident Preparedness
- Implementing security monitoring and logging within CI/CD
- Automating compliance with frameworks such as NIST, ISO, and SOC 2
- Establishing automated remediation and incident response workflows
ECDE Examination Preparation and Practical Assessment
- Understanding the ECDE exam format and study strategies
- Executing a comprehensive capstone DevSecOps pipeline lab
- Assessing knowledge and readiness through final checks
Conclusion and Path Forward
Requirements
- A solid understanding of fundamental DevOps workflows and associated tools
- Working knowledge of the software development lifecycle (SDLC)
- Basic familiarity with application security principles is advantageous
Target Audience
- DevOps engineers
- Application security specialists
- Software developers seeking to integrate security measures into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated