Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Zero Trust Fundamentals
- Evolving from perimeter security to Zero Trust
- Core principles of Zero Trust: never trust, always verify, least privilege
- NIST SP 800-207 Zero Trust Architecture framework
- Differences between Zero Trust and traditional network security models
- The open-source ecosystem for implementing Zero Trust
Zero Trust Architecture Components
- Identity as the new perimeter
- Device trust and posture validation
- Network segmentation and micro-segmentation
- Protection for application workloads
- Data classification and protection
- Policy enforcement points and policy decision points
Identity Foundation for Zero Trust
- Identity providers: Keycloak, Authentik, Dex
- Integration of OAuth 2.0, OIDC, and SAML
- Implementation of multi-factor authentication
- Risk-based authentication and step-up auth
- Identity lifecycle management
- Identity proofing and verification
Device Trust and Posture
- Device enrollment and attestation
- Device compliance checking using tools such as Kolide, OSQuery
- Integration of endpoint detection and response
- Certificate-based device authentication
- MDM integration for posture data
- Continuous assessment of device trust
Network-Level Zero Trust
- Concepts of Software-defined perimeter (SDP)
- Open-source SDP implementations
- Micro-segmentation utilizing OVN, Cilium, Calico
- Zero Trust Network Access (ZTNA) architecture
- Replacing VPN with zero trust access
- Network policy as code
Identity-Aware Proxies and Access Gateways
- Pomerium: architecture of identity-aware proxies
- vouch-proxy for nginx/Apache integration
- Deployment and configuration of OAuth2 Proxy
- Traefik with forward authentication
- Kong Gateway with OIDC plugins
- Configuration and enforcement of access policies
Service Mesh for Zero Trust
- Service mesh as the zero trust fabric
- Istio zero trust configuration
- Secure deployment patterns for Linkerd
- mTLS everywhere: service-to-service authentication
- SPIFFE/SPIRE for workload identity
- Authorization policies within the service mesh
- Trust domains for multi-cluster service mesh
PKI and Certificate Management
- Certificate-based authentication in zero trust
- Smallstep CA for workload identities
- HashiCorp Vault PKI engine
- Automation of certificate rotation and lifecycle
- Private CA for establishing internal trust
- Certificate transparency and monitoring
Secrets Management
- HashiCorp Vault for secrets management
- Sealed Secrets for Kubernetes
- External Secrets Operator
- SOPS: Secrets OPerationS
- Dynamic secrets and automatic rotation
- Secret injection patterns for applications
Policy as Code and Authorization
- Fundamentals of Open Policy Agent (OPA)
- Basics of the Rego policy language
- OPA with Kubernetes admission control
- OPA with Envoy for service authorization
- OPA with API gateways
- Testing and validation of policies
- Integration of Apache APISIX with OPA
API Security in Zero Trust
- Security patterns for API gateways
- Kong open source with security plugins
- Rate limiting and DDoS protection
- Authentication and authorization for APIs
- Security considerations for GraphQL
- API discovery and detection of shadow APIs
Data Protection and DLP
- Data classification frameworks
- Open-source DLP tools and integration
- Encryption in transit and at rest
- Strategies for tokenization and masking
- Policies for data loss prevention
- Sovereign data handling within zero trust
Continuous Authentication and Authorization
- Session management in zero trust environments
- Mechanisms for continuous authentication
- Context-aware access decisions
- Risk scoring and dynamic authorization
- Triggers for step-up authentication
- Real-time policy enforcement
Monitoring and Observability in Zero Trust
- Collection of security telemetry
- SIEM integration with open-source tools
- User and entity behavior analytics (UEBA)
- Audit logging and compliance reporting
- Anomaly detection using machine learning
- Security dashboards and alerting
Zero Trust for Cloud-Native Workloads
- Container security within the zero trust context
- Management of ephemeral workload identity
- Admission controllers for enforcing zero trust
- Runtime security with Falco and Tetragon
- Network policies for container segmentation
- Patterns for immutable infrastructure
Implementing Zero Trust Roadmap
- Maturity assessment and gap analysis
- Phased approach to implementation
- Design and execution of pilot projects
- Change management and user adoption
- Measuring success metrics for zero trust
- Challenges and pitfalls to avoid
Production Deployment and Operations
- Design patterns for high availability
- Disaster recovery for zero trust infrastructure
- Strategies for performance optimization
- Troubleshooting authentication and authorization issues
- Upgrading and patching zero trust components
- Documentation and runbook creation
Future of Zero Trust and Open Source
- Emerging standards and protocols
- Considerations for quantum-safe zero trust
- AI/ML in zero trust decision-making
- Federated zero trust architectures
- Community resources and ongoing development
- Summary and next steps
Requirements
- Strong understanding of network security concepts and principles
- Experience with identity and access management systems
- Knowledge of PKI, certificates, and encryption fundamentals
- Familiarity with microservices and container architectures
- Experience deploying and managing open-source software
Audience
- Security Architects and Engineers
- Infrastructure Architects designing modern security postures
- DevSecOps Engineers implementing security pipelines
- Network Administrators transitioning to zero trust models
35 Hours