課程簡介

Introduction to DevSecOps and ECDE Framework

  • DevSecOps fundamentals and principles
  • Security challenges in DevOps environments
  • Overview of the ECDE exam and domains

Secure DevOps Culture and Mindset

  • Security as a shared responsibility
  • Shifting security left in the SDLC
  • Stakeholder alignment and team roles

Integrating Security in CI/CD Pipelines

  • Securing Jenkins, GitLab CI, and Azure DevOps pipelines
  • Secrets management and environment configuration
  • Secure container builds and image scanning

Application Security in DevSecOps

  • Static and dynamic application security testing (SAST/DAST)
  • Open-source dependency scanning (SCA tools)
  • Secure code review and coding practices

Infrastructure as Code and Cloud Security

  • Securing Terraform, Ansible, and Kubernetes configurations
  • IAM and policy-as-code
  • DevSecOps in hybrid/multi-cloud environments

Monitoring, Compliance, and Incident Readiness

  • Security monitoring and logging in CI/CD
  • Compliance automation (e.g., NIST, ISO, SOC 2)
  • Automated remediation and incident response workflows

ECDE Exam Preparation and Final Lab

  • ECDE exam structure and preparation tips
  • Capstone DevSecOps pipeline lab
  • Knowledge checks and readiness assessment

Summary and Next Steps

最低要求

  • Understanding of basic DevOps workflows and tools
  • Familiarity with software development lifecycle (SDLC)
  • Knowledge of application security principles is helpful

Audience

  • DevOps engineers
  • Application security professionals
  • Software developers integrating security into pipelines
 28 時間:

人數


每位參與者的報價

客戶評論 (5)

Provisional Upcoming Courses (Require 5+ participants)

課程分類