Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Zero Trust Fundamentals
- Evolving from perimeter security to Zero Trust
- Core Zero Trust principles: never trust, always verify, least privilege
- NIST SP 800-207 Zero Trust Architecture framework
- Zero Trust versus traditional network security models
- The open-source ecosystem for Zero Trust implementation
Components of Zero Trust Architecture
- Identity as the new perimeter
- Device trust and posture validation
- Network segmentation and micro-segmentation
- Protection of application workloads
- Data classification and protection
- Policy enforcement points and policy decision points
Identity Foundation for Zero Trust
- Identity providers: Keycloak, Authentik, Dex
- Integration of OAuth 2.0, OIDC, and SAML
- Implementation of multi-factor authentication
- Risk-based authentication and step-up auth
- Identity lifecycle management
- Identity proofing and verification
Device Trust and Posture
- Device enrollment and attestation
- Device compliance checking with tools like Kolide, OSQuery
- Integration of endpoint detection and response
- Certificate-based device authentication
- MDM integration for posture data
- Continuous assessment of device trust
Network-Level Zero Trust
- Concepts of Software-defined perimeter (SDP)
- Open-source SDP implementations
- Micro-segmentation using OVN, Cilium, Calico
- Zero Trust Network Access (ZTNA) architecture
- Replacing VPN with zero trust access
- Network policy as code
Identity-Aware Proxies and Access Gateways
- Pomerium: identity-aware proxy architecture
- vouch-proxy for nginx/Apache integration
- Deployment and configuration of OAuth2 Proxy
- Traefik with forward authentication
- Kong Gateway with OIDC plugins
- Configuration and enforcement of access policies
Service Mesh for Zero Trust
- Service mesh as a zero trust fabric
- Istio zero trust configuration
- Linkerd secure deployment patterns
- mTLS everywhere: service-to-service authentication
- SPIFFE/SPIRE for workload identity
- Authorization policies within the service mesh
- Multi-cluster service mesh trust domains
PKI and Certificate Management
- Certificate-based authentication in zero trust
- Smallstep CA for workload identities
- HashiCorp Vault PKI engine
- Automated certificate rotation and lifecycle management
- Private CA for internal trust establishment
- Certificate transparency and monitoring
Secrets Management
- HashiCorp Vault for secrets management
- Sealed Secrets for Kubernetes
- External Secrets Operator
- SOPS: Secrets OPerationS
- Dynamic secrets and automatic rotation
- Secret injection patterns for applications
Policy as Code and Authorization
- Fundamentals of Open Policy Agent (OPA)
- Basics of Rego policy language
- OPA with Kubernetes admission control
- OPA with Envoy for service authorization
- OPA with API gateways
- Policy testing and validation
- Apache APISIX with OPA integration
API Security in Zero Trust
- Security patterns for API gateways
- Kong open source with security plugins
- Rate limiting and DDoS protection
- API authentication and authorization
- Considerations for GraphQL security
- API discovery and shadow API detection
Data Protection and DLP
- Data classification frameworks
- Open-source DLP tools and integration
- Encryption in transit and at rest
- Strategies for tokenization and masking
- Data loss prevention policies
- Sovereign data handling in zero trust
Continuous Authentication and Authorization
- Session management in zero trust environments
- Mechanisms for continuous authentication
- Context-aware access decisions
- Risk scoring and dynamic authorization
- Triggers for step-up authentication
- Real-time policy enforcement
Monitoring and Observability in Zero Trust
- Collection of security telemetry
- SIEM integration with open-source tools
- User and entity behavior analytics (UEBA)
- Audit logging and compliance reporting
- Anomaly detection using machine learning
- Security dashboards and alerting
Zero Trust for Cloud-Native Workloads
- Container security within a zero trust context
- Management of ephemeral workload identity
- Admission controllers for zero trust enforcement
- Runtime security with Falco and Tetragon
- Network policies for container segmentation
- Immutable infrastructure patterns
Implementing a Zero Trust Roadmap
- Maturity assessment and gap analysis
- Phased implementation approach
- Design and execution of pilot projects
- Change management and user adoption
- Measuring success metrics for zero trust
- Challenges and pitfalls to avoid
Production Deployment and Operations
- High availability design patterns
- Disaster recovery for zero trust infrastructure
- Strategies for performance optimization
- Troubleshooting authentication and authorization issues
- Upgrading and patching zero trust components
- Documentation and runbook creation
The Future of Zero Trust and Open Source
- Emerging standards and protocols
- Quantum-safe zero trust considerations
- AI/ML in zero trust decisions
- Federated zero trust architectures
- Community resources and ongoing development
- Summary and next steps
Requirements
- Strong understanding of network security concepts and principles
- Experience with identity and access management systems
- Knowledge of PKI, certificates, and encryption fundamentals
- Familiarity with microservices and container architectures
- Experience deploying and managing open-source software
Audience
- Security Architects and Engineers
- Infrastructure Architects designing modern security postures
- DevSecOps Engineers implementing security pipelines
- Network Administrators transitioning to zero trust models
35 Hours