Course Outline

Introduction to DevSecOps for Government

  • The significance of integrating security into the DevOps process
  • Fundamental principles and practices of DevSecOps for government

Continuous Integration (CI) Security

  • Ensuring secure code repositories through GitLab integration with Jenkins
  • Automated code quality and security analysis using SonarQube
  • Incorporating static code analysis into the Jenkins CI pipeline

Container Security with Docker for Government

  • Developing secure Docker images for government use
  • Managing Docker image repositories with Harbor for enhanced security
  • Best practices for vulnerability scanning and image version control in a governmental context

Setting up Secure CI/CD Pipelines for Government

  • Configuring Jenkins to integrate security measures for government applications
  • Executing SonarQube analysis to ensure code integrity and security
  • Generating and securing Docker images within the CI/CD pipeline for government systems

Securing the Deployment Process with Kubernetes for Government

  • Security practices for Kubernetes orchestration in government environments
  • The role of Kubernetes orchestrator in secure progressive deployment for government applications
  • Implementing Role-Based Access Control (RBAC) and securing service communication within government systems

Integrating RabbitMQ, PostgreSQL, and MongoDB for Government

  • Ensuring secure communication between services in a governmental context
  • Data security practices for PostgreSQL and MongoDB to meet government standards
  • Hardening RabbitMQ to support secure messaging for government operations

Identity and Access Management with Keycloak for Government

  • Configuring Keycloak for user authentication and authorization in government systems
  • Managing identity for Kubernetes clusters to align with government security protocols

Implementing Security in Kubernetes for Government

  • Deploying applications securely on Kubernetes to meet governmental requirements
  • Integrating Keycloak with Docker and Kubernetes for robust identity management in government environments

Monitoring and Auditing in DevSecOps for Government

  • Continuous monitoring tools and techniques for government systems
  • Auditing deployments to maintain compliance with governmental regulations
  • A practical guide to automating rollback procedures on security failures within government applications

Summary and Next Steps

Requirements

  • An understanding of the DevOps process for government
  • Basic working knowledge of Docker containers and Kubernetes orchestration

Audience

  • DevOps professionals in the public sector
 14 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories