Course Outline
Introduction to DevSecOps and ECDE Framework for Government
- Fundamentals and principles of DevSecOps for government
- Security challenges in DevOps environments for government operations
- Overview of the ECDE exam and its domains for government professionals
Secure DevOps Culture and Mindset for Government
- Security as a shared responsibility within government agencies
- Shifting security left in the Software Development Life Cycle (SDLC) for government applications
- Stakeholder alignment and team roles in government DevSecOps practices
Integrating Security in CI/CD Pipelines for Government
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines for government use cases
- Secrets management and environment configuration for government systems
- Secure container builds and image scanning for government applications
Application Security in DevSecOps for Government
- Static and dynamic application security testing (SAST/DAST) for government software
- Open-source dependency scanning using Software Composition Analysis (SCA) tools for government projects
- Secure code review and coding practices for government applications
Infrastructure as Code and Cloud Security for Government
- Securing Terraform, Ansible, and Kubernetes configurations in government infrastructure
- Identity and Access Management (IAM) and policy-as-code for government cloud environments
- DevSecOps practices in hybrid/multi-cloud environments for government agencies
Monitoring, Compliance, and Incident Readiness for Government
- Security monitoring and logging in CI/CD pipelines for government operations
- Compliance automation (e.g., NIST, ISO, SOC 2) for government standards
- Automated remediation and incident response workflows for government systems
ECDE Exam Preparation and Final Lab for Government Professionals
- Structure of the ECDE exam and preparation tips for government professionals
- Capstone DevSecOps pipeline lab for government participants
- Knowledge checks and readiness assessment for government candidates
Summary and Next Steps for Government
Requirements
- Comprehension of fundamental DevOps workflows and tools for government
- Familiarity with the software development lifecycle (SDLC)
- Knowledge of application security principles is beneficial
Audience
- DevOps engineers in the public sector
- Application security professionals for government
- Software developers integrating security into pipelines within government agencies
Testimonials (5)
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
General course information
Paulo Gouveia - EID
Course - C/C++ Secure Coding
Trainer willing to answer questions and give bunch of examples for us to learn.
Eldrick Ricamara - Human Edge Software Philippines, Inc. (part of Tribal Group)
Course - Security Testing
It opens up a lot and gives lots of insight what security
Nolbabalo Tshotsho - Vodacom SA
Course - Advanced Java Security
Instructor delivery of information; At the end of the day it was Gaurav who pulled off this topic focusing on building strong fundamentals and devising a methodology to be retained with us