Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of DevSecOps and the ECDE Framework
- Core concepts and principles of DevSecOps
- Addressing security challenges within DevOps ecosystems
- Introduction to the ECDE examination structure and subject areas
Cultivating a Secure DevOps Culture
- Fostering a mindset of shared security responsibility
- Implementing the 'shift-left' security approach within the SDLC
- Aligning stakeholders and defining team roles
Embedding Security in CI/CD Pipelines
- Enhancing security in Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments securely
- Executing secure container builds and scanning images
Application Security within DevSecOps
- Conducting Static and Dynamic Application Security Testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Performing secure code reviews and adhering to best coding practices
Securing Infrastructure as Code and Cloud Environments
- Hardening configurations for Terraform, Ansible, and Kubernetes
- Implementing IAM strategies and policy-as-code
- Managing DevSecOps in hybrid and multi-cloud settings
Monitoring, Compliance, and Incident Preparedness
- Establishing security monitoring and logging within CI/CD
- Automating compliance adherence (e.g., NIST, ISO, SOC 2)
- Designing automated remediation and incident response workflows
ECDE Certification Prep and Capstone Lab
- Understanding the ECDE exam format and strategic preparation advice
- Completing a comprehensive DevSecOps pipeline capstone lab
- Undergoing knowledge checks and readiness assessments
Conclusion and Future Directions
Requirements
- A solid grasp of fundamental DevOps workflows and associated tools
- Familiarity with the Software Development Lifecycle (SDLC)
- Basic knowledge of application security principles is advantageous
Target Audience
- DevOps Engineers
- Application Security Specialists
- Software Developers looking to integrate security into their pipelines
28 Hours
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated