top of page
EC-Council DevSecOps Essentials

EC-Council DevSecOps Essentials

Course Code

Duration

ECC-DSE

3 days

About the Course

The DevSecOps Essentials (DSE) covers fundamentals skills in DevSecOps, providing key insights into identifying application development risks and securing and testing applications within on-premises, cloud providers, and infrastructures. No IT/cybersecurity experience is required for this course.


Target Audience


  • High school students, graduates, professionals, career starters, and changers.

  • IT, technology, cybersecurity teams with little or no work experience.

  • Anyone who wants to start a career in cybersecurity, application security, and development and is interested in cloud technology.

  • Any professional involved in developing, testing, and deploying applications to production environments, including on-premises, public cloud, and hybrid environments. This program is also beneficial for application developers, risk managers, project managers, application administrators, administrators, engineers, and architects.


Skills You'll Learn


  • Learn the fundamentals of application development.

  • Gain knowledge of application security.

  • Understand DevOps and DevSecOps.

  • Explore the DevSecOps toolchain.

  • Gain insights into DevSecOps and CI/CD pipelines.

  • Learn about implementing and using tools for DevSecOps in CI/CD pipelines.


Course Outline


Module 1: Application Development Concepts

  • History of application development.

  • Evolution of application development methodologies.

  • Introduction to application architectures.

  • Introduction to the application development lifecycle.

  • Application testing and quality assurance.

  • Application monitoring, maintenance, and support.


Module 2: Application Security Fundamentals

  • What is secure application development?

  • Need for application security.

  • Common application security risks and threats.

  • OWASP Top 10.

  • Application security techniques.

  • Secure design principles.

  • Threat modeling.

  • Secure coding.

  • Secure code review.

  • SAST and DAST testing.

  • Secure configurations.

  • Educating developers.

  • Role of risk management in secure development.

  • Project management role in secure application development.


Module 3: Introduction to DevOps

  • Introduction to DevOps.

  • DevOps principles.

  • DevOps pipelines.

  • DevOps and project management.


Module 4: Introduction to DevSecOps

  • Understanding DevSecOps.

  • DevOps vs DevSecOps.

  • DevSecOps principles.

  • DevSecOps culture.

  • Shift-Left security.

  • DevSecOps pipelines.

  • Pillars of DevSecOps.

  • DevSecOps benefits and challenges.


Module 5: Introduction to DevSecOps Management Tools

  • Project management tools.

  • Integrated Development Environment (IDE) tools.

  • Source-code management tools.

  • Build tools.

  • Continuous testing tools.


Module 6: Introduction to DevSecOps Code and CI/CD Tools

  • Continuous integration tools.

  • Infrastructure as code tools.

  • Configuration management tools.

  • Continuous monitoring tools.


Module 7: Introduction to DevSecOps Pipelines

  • Role of DevSecOps in the CI/CD pipeline.

  • DevSecOps tools.

  • Embracing the DevSecOps lifecycle.

  • DevSecOps ecosystem.

  • Key elements of the DevSecOps pipeline.

  • Integrating security into the DevOps pipeline.


Module 8: Introduction to DevSecOps CI/CD Testing and Assessments

  • Implementing security into the CI/CD pipeline and security controls.

  • Continuous security in DevSecOps with security as code.

  • Continuous application testing for CI/CD pipeline security.

  • Application assessments and penetration testing.


Module 9: Implementing DevSecOps Testing and Threat Modeling

  • Integrating security threat modeling in plan stage.

  • Integrating secure coding in code stage.

  • Integrating SAST, DAST, and IAST in Build and Test stages.

  • Integrating RASP and VAPT in Release and Deploy stages.


Module 10: Implementing DevSecOps Monitoring Feedback

  • Implementing Infrastructure as Code (IaC).

  • Integrating configuration orchestration.

  • Integrating security in Operate and Monitor stage.

  • Integrating compliance as code (CaC).

  • Integrating logging, monitoring, and alerting.

  • Integrating continuous feedback loop.


Exam Details


Pre-requisite: No prior cybersecurity knowledge or IT work experience required.

Exam Code: 112-55

Number of Questions: 75

Duration: 2 hours

Test Format: Multiple Choice

bottom of page