Get in Touch

Course Outline

Overview of DevSecOps and the ECDE Framework

  • Core concepts and principles of DevSecOps
  • Security complexities within DevOps operational environments
  • Structure and domains of the ECDE certification examination

Fostering a Secure DevOps Culture and Mindset

  • Adopting security as a collective responsibility
  • Implementing early-stage security controls in the Software Development Life Cycle (SDLC)
  • Aligning stakeholder objectives and defining team responsibilities

Integrating Security Controls into CI/CD Pipelines

  • Securing pipeline infrastructure across Jenkins, GitLab CI, and Azure DevOps platforms
  • Managing secrets and configuring secure environments
  • Ensuring integrity of container builds through image scanning

Application Security Practices in DevSecOps

  • Execution of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  • Scanning open-source dependencies using Software Composition Analysis (SCA) tools
  • Conducting secure code reviews and adhering to best practices for coding standards

Infrastructure as Code and Cloud Security Posture

  • Securing configurations for Terraform, Ansible, and Kubernetes
  • Managing Identity and Access Management (IAM) and policy-as-code enforcement
  • Implementing DevSecOps strategies within hybrid and multi-cloud architectures for government operations

Continuous Monitoring, Regulatory Compliance, and Incident Response Preparedness

  • Establishing security monitoring and logging protocols within CI/CD workflows
  • Automating compliance with standards such as NIST, ISO, and SOC 2
  • Executing automated remediation procedures and incident response playbooks

ECDE Examination Strategy and Capstone Laboratory Exercise

  • Understanding the ECDE examination format and study recommendations
  • Completion of a comprehensive DevSecOps pipeline laboratory exercise
  • Knowledge verification and readiness evaluations

Program Summary and Forward Pathway

Requirements

  • Proficiency in foundational DevOps processes and associated utilities
  • Knowledge of the software development life cycle (SDLC)
  • Familiarity with application security standards is advantageous

Audience

  • DevOps practitioners
  • Application security specialists
  • Software engineers responsible for embedding security controls into CI/CD pipelines for government applications
 28 Hours

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses