Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Foundations of Zero Trust
- The progression from perimeter-based security to Zero Trust
- Core Zero Trust principles: never trust, always verify, least privilege
- The NIST SP 800-207 Zero Trust Architecture framework
- Comparing Zero Trust with traditional network security models
- The open-source ecosystem supporting Zero Trust implementation
Core Components of Zero Trust Architecture
- Identity as the new security perimeter
- Device trust validation and posture assessment
- Network segmentation and micro-segmentation strategies
- Protection for application workloads
- Data classification and protective measures
- Defining policy enforcement and decision points
Identity Infrastructure for Zero Trust
- Identity providers: Keycloak, Authentik, and Dex
- Integrating OAuth 2.0, OIDC, and SAML
- Implementing multi-factor authentication
- Risk-based and step-up authentication mechanisms
- Managing the identity lifecycle
- Processes for identity proofing and verification
Device Trust and Posture Management
- Device enrollment and attestation procedures
- Device compliance verification using tools such as Kolide and OSQuery
- Integrating endpoint detection and response
- Certificate-based device authentication
- MDM integration for collecting posture data
- Ongoing assessment of device trust status
Network-Level Zero Trust Implementation
- Concepts of the Software-defined Perimeter (SDP)
- Open-source implementations of SDP
- Micro-segmentation using OVN, Cilium, and Calico
- Zero Trust Network Access (ZTNA) architecture
- Substituting traditional VPNs with zero trust access
- Managing network policies as code
Identity-Aware Proxies and Access Gateways
- Pomerium: architecture of the identity-aware proxy
- Utilizing vouch-proxy for nginx/Apache integration
- Deploying and configuring OAuth2 Proxy
- Configuring Traefik with forward authentication
- Kong Gateway with OIDC plugins
- Setting and enforcing access policies
Service Mesh for Zero Trust
- Service mesh as a zero trust fabric
- Configuring Istio for zero trust
- Secure deployment patterns with Linkerd
- mTLS everywhere: service-to-service authentication
- Using SPIFFE/SPIRE for workload identity
- Authorization policies within the service mesh
- Trust domains in multi-cluster service mesh
PKI and Certificate Management
- Certificate-based authentication in zero trust
- Smallstep CA for managing workload identities
- HashiCorp Vault PKI engine
- Automating certificate rotation and lifecycle
- Establishing internal trust via Private CA
- Certificate transparency and monitoring
Secrets Management
- HashiCorp Vault for central secrets management
- Sealed Secrets for Kubernetes
- External Secrets Operator
- SOPS: Secrets OPerationS
- Dynamic secrets and automatic rotation
- Patterns for injecting secrets into applications
Policy as Code and Authorization
- Open Policy Agent (OPA) fundamentals
- Basics of the Rego policy language
- Using OPA with Kubernetes admission control
- Using OPA with Envoy for service authorization
- Integrating OPA with API gateways
- Testing and validating policies
- Apache APISIX integrated with OPA
API Security in a Zero Trust Context
- Security patterns for API gateways
- Kong open source with security plugins
- Rate limiting and DDoS protection
- API authentication and authorization
- Security considerations for GraphQL
- API discovery and identifying shadow APIs
Data Protection and DLP
- Frameworks for data classification
- Open-source DLP tools and their integration
- Encryption in transit and at rest
- Strategies for tokenization and data masking
- Data loss prevention policies
- Handling sovereign data in zero trust environments
Continuous Authentication and Authorization
- Session management in zero trust environments
- Mechanisms for continuous authentication
- Context-aware access decision making
- Risk scoring and dynamic authorization
- Triggers for step-up authentication
- Real-time policy enforcement
Monitoring and Observability in Zero Trust
- Collecting security telemetry
- Integrating with SIEM using open-source tools
- User and Entity Behavior Analytics (UEBA)
- Audit logging and compliance reporting
- Anomaly detection leveraging machine learning
- Security dashboards and alerting systems
Zero Trust for Cloud-Native Workloads
- Container security within a zero trust context
- Managing ephemeral workload identities
- Admission controllers for enforcing zero trust
- Runtime security using Falco and Tetragon
- Network policies for container segmentation
- Patterns for immutable infrastructure
Developing a Zero Trust Roadmap
- Maturity assessment and gap analysis
- Phased approach to implementation
- Designing and executing pilot projects
- Change management and user adoption
- Measuring success through zero trust metrics
- Common challenges and pitfalls to avoid
Production Deployment and Operations
- High availability design patterns
- Disaster recovery for zero trust infrastructure
- Strategies for performance optimization
- Troubleshooting authentication and authorization issues
- Upgrading and patching zero trust components
- Creating documentation and runbooks
The Future of Zero Trust and Open Source
- Emerging standards and protocols
- Considerations for quantum-safe zero trust
- The role of AI/ML in zero trust decisions
- Federated zero trust architectures
- Community resources and ongoing development
- Summary and recommended next steps
Requirements
- A solid grasp of network security concepts and principles
- Practical experience with identity and access management systems
- Understanding of PKI, digital certificates, and encryption fundamentals
- Familiarity with microservices and container-based architectures
- Background in deploying and managing open-source software
Target Audience
- Security Architects and Engineers
- Infrastructure Architects shaping modern security postures
- DevSecOps Engineers integrating security into pipelines
- Network Administrators transitioning to zero trust models
35 Hours