Get in Touch

Course Outline

Introduction to DevSecOps and the ECDE Framework

  • Core fundamentals and principles of DevSecOps
  • Security challenges within DevOps environments
  • Overview of the ECDE exam structure and domains

Establishing a Secure DevOps Culture

  • Security as a shared team responsibility
  • Shifting security left in the SDLC
  • Aligning stakeholders and defining team roles

Security Integration in CI/CD Pipelines

  • Hardening Jenkins, GitLab CI, and Azure DevOps pipelines
  • Managing secrets and configuring secure environments
  • Securing container builds and performing image scanning

Application Security in the DevSecOps Context

  • Static and dynamic application security testing (SAST/DAST)
  • Scanning open-source dependencies using SCA tools
  • Conducting secure code reviews and adhering to coding best practices

Infrastructure as Code and Cloud Security

  • Securing configurations for Terraform, Ansible, and Kubernetes
  • Implementing IAM and policy-as-code
  • Applying DevSecOps in hybrid and multi-cloud settings

Monitoring, Compliance, and Incident Readiness

  • Implementing security monitoring and logging within CI/CD
  • Automating compliance for frameworks like NIST, ISO, and SOC 2
  • Developing automated remediation and incident response workflows

ECDE Exam Preparation and Final Lab

  • Understanding the ECDE exam format and preparation strategies
  • Completing a capstone DevSecOps pipeline lab
  • Participating in knowledge checks and readiness assessments

Conclusion and Next Steps

Requirements

  • Fundamental understanding of DevOps workflows and associated tools
  • Awareness of the Software Development Life Cycle (SDLC)
  • Background knowledge of application security principles is advantageous

Intended Audience

  • DevOps Engineers
  • Application Security Specialists
  • Software Developers focusing on security integration in pipelines
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories