Get in Touch

Course Outline

Foundations of Zero Trust

  • The progression from perimeter-based security to Zero Trust
  • Core Zero Trust principles: never trust, always verify, least privilege
  • The NIST SP 800-207 Zero Trust Architecture framework
  • Comparing Zero Trust with traditional network security models
  • The open-source ecosystem supporting Zero Trust implementation

Core Components of Zero Trust Architecture

  • Identity as the new security perimeter
  • Device trust validation and posture assessment
  • Network segmentation and micro-segmentation strategies
  • Protection for application workloads
  • Data classification and protective measures
  • Defining policy enforcement and decision points

Identity Infrastructure for Zero Trust

  • Identity providers: Keycloak, Authentik, and Dex
  • Integrating OAuth 2.0, OIDC, and SAML
  • Implementing multi-factor authentication
  • Risk-based and step-up authentication mechanisms
  • Managing the identity lifecycle
  • Processes for identity proofing and verification

Device Trust and Posture Management

  • Device enrollment and attestation procedures
  • Device compliance verification using tools such as Kolide and OSQuery
  • Integrating endpoint detection and response
  • Certificate-based device authentication
  • MDM integration for collecting posture data
  • Ongoing assessment of device trust status

Network-Level Zero Trust Implementation

  • Concepts of the Software-defined Perimeter (SDP)
  • Open-source implementations of SDP
  • Micro-segmentation using OVN, Cilium, and Calico
  • Zero Trust Network Access (ZTNA) architecture
  • Substituting traditional VPNs with zero trust access
  • Managing network policies as code

Identity-Aware Proxies and Access Gateways

  • Pomerium: architecture of the identity-aware proxy
  • Utilizing vouch-proxy for nginx/Apache integration
  • Deploying and configuring OAuth2 Proxy
  • Configuring Traefik with forward authentication
  • Kong Gateway with OIDC plugins
  • Setting and enforcing access policies

Service Mesh for Zero Trust

  • Service mesh as a zero trust fabric
  • Configuring Istio for zero trust
  • Secure deployment patterns with Linkerd
  • mTLS everywhere: service-to-service authentication
  • Using SPIFFE/SPIRE for workload identity
  • Authorization policies within the service mesh
  • Trust domains in multi-cluster service mesh

PKI and Certificate Management

  • Certificate-based authentication in zero trust
  • Smallstep CA for managing workload identities
  • HashiCorp Vault PKI engine
  • Automating certificate rotation and lifecycle
  • Establishing internal trust via Private CA
  • Certificate transparency and monitoring

Secrets Management

  • HashiCorp Vault for central secrets management
  • Sealed Secrets for Kubernetes
  • External Secrets Operator
  • SOPS: Secrets OPerationS
  • Dynamic secrets and automatic rotation
  • Patterns for injecting secrets into applications

Policy as Code and Authorization

  • Open Policy Agent (OPA) fundamentals
  • Basics of the Rego policy language
  • Using OPA with Kubernetes admission control
  • Using OPA with Envoy for service authorization
  • Integrating OPA with API gateways
  • Testing and validating policies
  • Apache APISIX integrated with OPA

API Security in a Zero Trust Context

  • Security patterns for API gateways
  • Kong open source with security plugins
  • Rate limiting and DDoS protection
  • API authentication and authorization
  • Security considerations for GraphQL
  • API discovery and identifying shadow APIs

Data Protection and DLP

  • Frameworks for data classification
  • Open-source DLP tools and their integration
  • Encryption in transit and at rest
  • Strategies for tokenization and data masking
  • Data loss prevention policies
  • Handling sovereign data in zero trust environments

Continuous Authentication and Authorization

  • Session management in zero trust environments
  • Mechanisms for continuous authentication
  • Context-aware access decision making
  • Risk scoring and dynamic authorization
  • Triggers for step-up authentication
  • Real-time policy enforcement

Monitoring and Observability in Zero Trust

  • Collecting security telemetry
  • Integrating with SIEM using open-source tools
  • User and Entity Behavior Analytics (UEBA)
  • Audit logging and compliance reporting
  • Anomaly detection leveraging machine learning
  • Security dashboards and alerting systems

Zero Trust for Cloud-Native Workloads

  • Container security within a zero trust context
  • Managing ephemeral workload identities
  • Admission controllers for enforcing zero trust
  • Runtime security using Falco and Tetragon
  • Network policies for container segmentation
  • Patterns for immutable infrastructure

Developing a Zero Trust Roadmap

  • Maturity assessment and gap analysis
  • Phased approach to implementation
  • Designing and executing pilot projects
  • Change management and user adoption
  • Measuring success through zero trust metrics
  • Common challenges and pitfalls to avoid

Production Deployment and Operations

  • High availability design patterns
  • Disaster recovery for zero trust infrastructure
  • Strategies for performance optimization
  • Troubleshooting authentication and authorization issues
  • Upgrading and patching zero trust components
  • Creating documentation and runbooks

The Future of Zero Trust and Open Source

  • Emerging standards and protocols
  • Considerations for quantum-safe zero trust
  • The role of AI/ML in zero trust decisions
  • Federated zero trust architectures
  • Community resources and ongoing development
  • Summary and recommended next steps

Requirements

  • A solid grasp of network security concepts and principles
  • Practical experience with identity and access management systems
  • Understanding of PKI, digital certificates, and encryption fundamentals
  • Familiarity with microservices and container-based architectures
  • Background in deploying and managing open-source software

Target Audience

  • Security Architects and Engineers
  • Infrastructure Architects shaping modern security postures
  • DevSecOps Engineers integrating security into pipelines
  • Network Administrators transitioning to zero trust models
 35 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories