Course Outline
Introduction to DevSecOps and ECDE Framework for Government
- Fundamentals and principles of DevSecOps in government environments
- Security challenges within DevOps workflows for government
- Overview of the ECDE exam and its relevant domains for government professionals
Secure DevOps Culture and Mindset for Government
- Security as a shared responsibility across all government teams
- Incorporating security early in the Software Development Life Cycle (SDLC) for government projects
- Aligning stakeholders and defining team roles within government agencies
Integrating Security in CI/CD Pipelines for Government
- Securing Jenkins, GitLab CI, and Azure DevOps pipelines for government use
- Managing secrets and configuring environments securely for government systems
- Ensuring secure container builds and image scanning for government applications
Application Security in DevSecOps for Government
- Conducting static and dynamic application security testing (SAST/DAST) for government software
- Performing open-source dependency scanning using Software Composition Analysis (SCA) tools for government projects
- Implementing secure code review and coding practices within government agencies
Infrastructure as Code and Cloud Security for Government
- Securing Terraform, Ansible, and Kubernetes configurations in government infrastructure
- Managing Identity and Access Management (IAM) and policy-as-code for government cloud environments
- Implementing DevSecOps practices in hybrid/multi-cloud government settings
Monitoring, Compliance, and Incident Readiness for Government
- Security monitoring and logging within CI/CD pipelines for government systems
- Automating compliance with standards such as NIST, ISO, and SOC 2 for government agencies
- Developing automated remediation and incident response workflows for government operations
ECDE Exam Preparation and Final Lab for Government
- Structure of the ECDE exam and preparation tips for government professionals
- Capstone DevSecOps pipeline lab designed for government scenarios
- Knowledge checks and readiness assessments tailored for government roles
Summary and Next Steps for Government
Requirements
- Understanding of fundamental DevOps workflows and tools for government
- Familiarity with the software development lifecycle (SDLC)
- Knowledge of application security principles is beneficial
Audience
- DevOps engineers in public sector organizations
- Application security professionals for government
- Software developers integrating security into pipelines within the public sector
Testimonials (5)
The really lot of extra tools that was mentioned and the real life examples form Mane's experience.
Tamas Adam - Ericsson
Course - Certified Ethical Hacker CEH v.13 AI
General course information
Paulo Gouveia - EID
Course - C/C++ Secure Coding
Trainer willing to answer questions and give bunch of examples for us to learn.
Eldrick Ricamara - Human Edge Software Philippines, Inc. (part of Tribal Group)
Course - Security Testing
It opens up a lot and gives lots of insight what security
Nolbabalo Tshotsho - Vodacom SA
Course - Advanced Java Security
Instructor delivery of information; At the end of the day it was Gaurav who pulled off this topic focusing on building strong fundamentals and devising a methodology to be retained with us