Course Outline
Introduction to DevSecOps and the ECDE Framework
- Fundamentals and principles of DevSecOps
- Security challenges inherent in DevOps environments
- Overview of the ECDE exam structure and domains
Cultivating a Secure DevOps Culture and Mindset
- Establishing security as a shared responsibility
- Shifting security left within the SDLC
- Aligning stakeholders and defining team roles
Integrating Security into CI/CD Pipelines
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines
- Managing secrets and configuring environments securely
- S conducting secure container builds and image scanning
Application Security within DevSecOps
- Static and dynamic application security testing (SAST/DAST)
- Scanning open-source dependencies using SCA tools
- Implementing secure code review processes and coding practices
Infrastructure as Code and Cloud Security
- Securing configurations for Terraform, Ansible, and Kubernetes
- Managing IAM and policy-as-code
- Deploying DevSecOps in hybrid and multi-cloud environments
Monitoring, Compliance, and Incident Readiness
- Security monitoring and logging within CI/CD pipelines
- Automating compliance with standards such as NIST, ISO, and SOC 2
- Establishing automated remediation and incident response workflows
ECDE Exam Preparation and Final Laboratory
- Understanding the ECDE exam structure and preparation tips
- Capstone DevSecOps pipeline laboratory exercise
- Knowledge checks and readiness assessment
Summary and Next Steps
Requirements
- Familiarity with fundamental DevOps workflows and tools
- Understanding of the Software Development Lifecycle (SDLC)
- Knowledge of application security principles is advantageous
Audience
- DevOps engineers
- Application security specialists
- Software developers integrating security into their pipelines
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6400 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions
Adam - Fireup.PRO
Course - Advanced Java Security
The topic is current and I needed to be updated