Course Outline
Overview of DevSecOps and the ECDE Framework
- Core concepts and principles of DevSecOps
- Security complexities within DevOps operational environments
- Structure and domains of the ECDE certification examination
Fostering a Secure DevOps Culture and Mindset
- Adopting security as a collective responsibility
- Implementing early-stage security controls in the Software Development Life Cycle (SDLC)
- Aligning stakeholder objectives and defining team responsibilities
Integrating Security Controls into CI/CD Pipelines
- Securing pipeline infrastructure across Jenkins, GitLab CI, and Azure DevOps platforms
- Managing secrets and configuring secure environments
- Ensuring integrity of container builds through image scanning
Application Security Practices in DevSecOps
- Execution of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
- Scanning open-source dependencies using Software Composition Analysis (SCA) tools
- Conducting secure code reviews and adhering to best practices for coding standards
Infrastructure as Code and Cloud Security Posture
- Securing configurations for Terraform, Ansible, and Kubernetes
- Managing Identity and Access Management (IAM) and policy-as-code enforcement
- Implementing DevSecOps strategies within hybrid and multi-cloud architectures for government operations
Continuous Monitoring, Regulatory Compliance, and Incident Response Preparedness
- Establishing security monitoring and logging protocols within CI/CD workflows
- Automating compliance with standards such as NIST, ISO, and SOC 2
- Executing automated remediation procedures and incident response playbooks
ECDE Examination Strategy and Capstone Laboratory Exercise
- Understanding the ECDE examination format and study recommendations
- Completion of a comprehensive DevSecOps pipeline laboratory exercise
- Knowledge verification and readiness evaluations
Program Summary and Forward Pathway
Requirements
- Proficiency in foundational DevOps processes and associated utilities
- Knowledge of the software development life cycle (SDLC)
- Familiarity with application security standards is advantageous
Audience
- DevOps practitioners
- Application security specialists
- Software engineers responsible for embedding security controls into CI/CD pipelines for government applications
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions