Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Zero Trust Fundamentals
- Evolving from perimeter security to Zero Trust
- Core Zero Trust principles: never trust, always verify, least privilege
- NIST SP 800-207 Zero Trust Architecture framework
- Comparing Zero Trust with traditional network security models
- The open source ecosystem for implementing Zero Trust
Zero Trust Architecture Components
- Identity as the new perimeter
- Device trust and posture validation
- Network segmentation and micro-segmentation
- Application workload protection
- Data classification and protection
- Policy enforcement points and policy decision points
Identity Foundation for Zero Trust
- Identity providers: Keycloak, Authentik, Dex
- Integration of OAuth 2.0, OIDC, and SAML
- Implementation of multi-factor authentication
- Risk-based authentication and step-up auth
- Identity lifecycle management
- Identity proofing and verification
Device Trust and Posture
- Device enrollment and attestation
- Device compliance checking using tools such as Kolide, OSQuery
- Integration of endpoint detection and response
- Certificate-based device authentication
- MDM integration for posture data
- Continuous device trust assessment
Network-Level Zero Trust
- Concepts of software-defined perimeter (SDP)
- Open source SDP implementations
- Micro-segmentation utilizing OVN, Cilium, Calico
- Zero Trust Network Access (ZTNA) architecture
- Replacing VPN with zero trust access
- Network policy as code
Identity-Aware Proxies and Access Gateways
- Pomerium: identity-aware proxy architecture
- vouch-proxy for integration with nginx/Apache
- Deployment and configuration of OAuth2 Proxy
- Traefik with forward authentication
- Kong Gateway with OIDC plugins
- Configuration and enforcement of access policies
Service Mesh for Zero Trust
- Service mesh functioning as zero trust fabric
- Zero Trust configuration in Istio
- Secure deployment patterns in Linkerd
- mTLS everywhere: service-to-service authentication
- SPIFFE/SPIRE for workload identity
- Authorization policies within service mesh
- Multi-cluster service mesh trust domains
PKI and Certificate Management
- Certificate-based authentication in zero trust environments
- Smallstep CA for workload identities
- HashiCorp Vault PKI engine
- Automated certificate rotation and lifecycle management
- Private CA for establishing internal trust
- Certificate transparency and monitoring
Secrets Management
- HashiCorp Vault for secrets management
- Sealed Secrets for Kubernetes
- External Secrets Operator
- SOPS: Secrets OPerationS
- Dynamic secrets and automatic rotation
- Secret injection patterns for applications
Policy as Code and Authorization
- Fundamentals of Open Policy Agent (OPA)
- Basics of the Rego policy language
- OPA utilized with Kubernetes admission control
- OPA applied to service authorization with Envoy
- OPA in conjunction with API gateways
- Policy testing and validation
- Integration of Apache APISIX with OPA
API Security in Zero Trust
- Security patterns for API gateways
- Kong open source with security plugins
- Rate limiting and DDoS protection
- API authentication and authorization
- Considerations for GraphQL security
- API discovery and detection of shadow APIs
Data Protection and DLP
- Frameworks for data classification
- Open source DLP tools and integration
- Encryption in transit and at rest
- Strategies for tokenization and masking
- Data loss prevention policies
- Sovereign data handling within zero trust frameworks
Continuous Authentication and Authorization
- Session management in zero trust environments
- Mechanisms for continuous authentication
- Context-aware access decisions
- Risk scoring and dynamic authorization
- Triggers for step-up authentication
- Real-time policy enforcement
Monitoring and Observability in Zero Trust
- Collection of security telemetry
- SIEM integration with open source tools
- User and entity behavior analytics (UEBA)
- Audit logging and compliance reporting
- Anomaly detection leveraging machine learning
- Security dashboards and alerting
Zero Trust for Cloud-Native Workloads
- Container security within the zero trust context
- Ephemeral workload identity management
- Admission controllers for zero trust enforcement
- Runtime security using Falco and Tetragon
- Network policies for container segmentation
- Patterns for immutable infrastructure
Implementing Zero Trust Roadmap
- Maturity assessment and gap analysis
- Phased implementation approach
- Design and execution of pilot projects
- Change management and user adoption
- Evaluating success metrics for zero trust
- Challenges and pitfalls to avoid
Production Deployment and Operations
- High availability design patterns
- Disaster recovery for zero trust infrastructure
- Strategies for performance optimization
- Troubleshooting authentication and authorization issues
- Upgrading and patching zero trust components
- Documentation and creation of runbooks
Future of Zero Trust and Open Source
- Emerging standards and protocols
- Considerations for quantum-safe zero trust
- AI/ML in zero trust decision-making
- Federated zero trust architectures
- Community resources and ongoing development
- Summary and next steps
Requirements
- Solid grasp of network security concepts and principles
- Experience with identity and access management systems
- Understanding of PKI, certificates, and encryption fundamentals
- Familiarity with microservices and container architectures
- Experience in deploying and managing open-source software
Audience
- Security Architects and Engineers
- Infrastructure Architects crafting modern security postures
- DevSecOps Engineers building security pipelines
- Network Administrators transitioning to zero trust models
35 Hours