Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Fundamentals of Zero Trust
- The transition from perimeter-based defenses to Zero Trust paradigms
- Core tenets of Zero Trust: assume breach, verify explicitly, and enforce least privilege
- NIST SP 800-207 framework for Zero Trust Architecture
- Differentiating Zero Trust from traditional network security models
- Utilization of open-source ecosystems for Zero Trust deployment
Components of Zero Trust Architecture
- Establishing identity as the primary security boundary
- Validating device trust and compliance posture
- Implementing network and micro-segmentation strategies
- Securing application workloads
- Classifying and protecting sensitive data
- Defining policy decision and enforcement points
Identity Foundations for Zero Trust
- Identity providers including Keycloak, Authentik, and Dex
- Integration of OAuth 2.0, OIDC, and SAML protocols
- Implementation of multi-factor authentication (MFA)
- Risk-based authentication and step-up verification mechanisms
- Management of identity lifecycles
- Identity proofing and verification processes
Device Trust and Posture Validation
- Device enrollment and attestation procedures
- Compliance checking using tools such as Kolide and OSQuery
- Integration with endpoint detection and response (EDR) systems
- Certificate-based device authentication methods
- Integration with Mobile Device Management (MDM) for posture data
- Continuous assessment of device trustworthiness
Network-Level Zero Trust Implementation
- Concepts and principles of Software-Defined Perimeter (SDP)
- Open-source SDP implementations available for government use
- Micro-segmentation technologies including OVN, Cilium, and Calico
- Architecture of Zero Trust Network Access (ZTNA)
- Migration from traditional VPNs to zero trust access models
- Implementation of network policies as code
Identity-Aware Proxies and Access Gateways
- Pomerium architecture for identity-aware proxying
- vouch-proxy integration with nginx and Apache
- Deployment and configuration of OAuth2 Proxy
- Traefik implementation with forward authentication
- Kong Gateway integration with OIDC plugins
- Configuration and enforcement of access policies
Service Mesh for Zero Trust Environments
- Utilizing service mesh as a zero trust fabric
- Zero Trust configuration within Istio
- Secure deployment patterns using Linkerd
- Implementation of mutual TLS (mTLS) for service-to-service authentication
- SPIFFE/SPIRE for workload identity management
- Authorization policies within service mesh contexts
- Trust domains in multi-cluster service mesh architectures
Public Key Infrastructure and Certificate Management
- Certificate-based authentication within zero trust frameworks
- Smallstep CA for managing workload identities
- HashiCorp Vault PKI engine capabilities
- Automation of certificate rotation and lifecycle management
- Private Certificate Authorities (CA) for internal trust establishment
- Certificate transparency logs and monitoring
Secrets Management Systems
- HashiCorp Vault for enterprise secrets management
- Sealed Secrets implementation for Kubernetes environments
- External Secrets Operator integration
- SOPS (Secrets OPerationS) usage
- Dynamic secrets generation and automatic rotation
- Patterns for secure secret injection into applications
Policy as Code and Authorization Frameworks
- Fundamentals of Open Policy Agent (OPA)
- Basics of the Rego policy language
- OPA integration with Kubernetes admission control
- OPA usage with Envoy for service authorization
- Integration with API gateways via OPA
- Policy testing and validation methodologies
- Apache APISIX integration with OPA
API Security in Zero Trust Architectures
- Security patterns for API gateways
- Kong open-source implementation with security plugins
- Rate limiting and distributed denial-of-service (DDoS) mitigation
- Authentication and authorization mechanisms for APIs
- Security considerations for GraphQL implementations
- API discovery and detection of shadow APIs
Data Protection and Data Loss Prevention (DLP)
- Frameworks for data classification
- Open-source DLP tools and integration strategies
- Encryption standards for data in transit and at rest
- Strategies for tokenization and data masking
- Data loss prevention policy formulation
- Sovereign data handling requirements in zero trust contexts
Continuous Authentication and Authorization
- Session management within zero trust environments
- Mechanisms for continuous authentication
- Context-aware access decision-making
- Risk scoring and dynamic authorization adjustments
- Triggers for step-up authentication protocols
- Real-time policy enforcement capabilities
Monitoring and Observability in Zero Trust Systems
- Collection of security telemetry data
- Integration with Security Information and Event Management (SIEM) systems using open-source tools
- User and Entity Behavior Analytics (UEBA)
- Audit logging and compliance reporting requirements
- Anomaly detection utilizing machine learning algorithms
- Development of security dashboards and alerting mechanisms
Zero Trust for Cloud-Native Workloads
- Container security within zero trust frameworks
- Management of ephemeral workload identities
- Admission controllers for enforcing zero trust controls
- Runtime security monitoring with Falco and Tetragon
- Network policies for container segmentation
- Implementation of immutable infrastructure patterns
Zero Trust Implementation Roadmap
- Conducting maturity assessments and gap analyses
- Adopting a phased implementation approach
- Designing and executing pilot projects
- Managing change and driving user adoption
- Defining success metrics for zero trust initiatives
- Identifying challenges and avoiding common pitfalls
Production Deployment and Operational Practices
- High availability design patterns
- Disaster recovery planning for zero trust infrastructure
- Strategies for performance optimization
- Troubleshooting authentication and authorization failures
- Procedures for upgrading and patching components
- Documentation standards and runbook development
Future Directions for Zero Trust and Open Source Technologies
- Evolving standards and protocols relevant to government operations
- Considerations for quantum-safe zero trust mechanisms
- Integration of AI/ML in zero trust decision-making processes
- Federated zero trust architecture models
- Community resources and ongoing development trends
- Summary and recommended next steps
Requirements
- Demonstrated proficiency in core network security theories and operational frameworks
- Practical application of identity and access management solutions
- Comprehensive grasp of public key infrastructure, certificate administration, and encryption protocols
- Familiarity with distributed microservices and containerized deployment architectures
- Proven capability in the deployment and lifecycle management of open-source technologies
Target Audience
- Security Architects and Engineers responsible for threat mitigation
- Infrastructure Architects developing modernized security postures
- DevSecOps Engineers integrating security controls into automated pipelines
- Network Administrators facilitating migration to zero-trust frameworks
35 Hours