Get in Touch

Course Outline

Fundamentals of Zero Trust

  • Evolution from perimeter security to Zero Trust
  • Core principles of Zero Trust: never trust, always verify, least privilege
  • NIST SP 800-207 Zero Trust Architecture framework
  • Differences between Zero Trust and traditional network security models
  • Open source ecosystem for implementing Zero Trust

Components of Zero Trust Architecture

  • Identity as the new perimeter
  • Device trust and posture validation
  • Network segmentation and micro-segmentation
  • Application workload protection
  • Data classification and protection
  • Policy enforcement points and policy decision points

Identity Foundation for Zero Trust

  • Identity providers: Keycloak, Authentik, Dex
  • Integration of OAuth 2.0, OIDC, and SAML
  • Implementation of multi-factor authentication
  • Risk-based authentication and step-up auth
  • Identity lifecycle management
  • Identity proofing and verification

Device Trust and Posture

  • Device enrollment and attestation
  • Device compliance checking using tools like Kolide, OSQuery
  • Integration with endpoint detection and response
  • Certificate-based device authentication
  • MDM integration for posture data
  • Continuous assessment of device trust

Network-Level Zero Trust

  • Concepts of Software-defined perimeter (SDP)
  • Open source SDP implementations
  • Micro-segmentation with OVN, Cilium, Calico
  • Zero Trust Network Access (ZTNA) architecture
  • Replacing VPN with zero trust access
  • Network policy as code

Identity-Aware Proxies and Access Gateways

  • Pomerium: architecture of identity-aware proxy
  • vouch-proxy for nginx/Apache integration
  • Deployment and configuration of OAuth2 Proxy
  • Traefik with forward authentication
  • Kong Gateway with OIDC plugins
  • Configuration and enforcement of access policies

Service Mesh for Zero Trust

  • Service mesh as a zero trust fabric
  • Zero Trust configuration in Istio
  • Secure deployment patterns in Linkerd
  • mTLS everywhere: service-to-service authentication
  • SPIFFE/SPIRE for workload identity
  • Authorization policies within service mesh
  • Multi-cluster service mesh trust domains

PKI and Certificate Management

  • Certificate-based authentication in zero trust
  • Smallstep CA for workload identities
  • HashiCorp Vault PKI engine
  • Automation of certificate rotation and lifecycle
  • Private CA for internal trust establishment
  • Certificate transparency and monitoring

Secrets Management

  • HashiCorp Vault for secrets management
  • Sealed Secrets for Kubernetes
  • External Secrets Operator
  • SOPS: Secrets OPerationS
  • Dynamic secrets and automatic rotation
  • Patterns for secret injection into applications

Policy as Code and Authorization

  • Fundamentals of Open Policy Agent (OPA)
  • Basics of Rego policy language
  • OPA with Kubernetes admission control
  • OPA with Envoy for service authorization
  • OPA with API gateways
  • Testing and validation of policies
  • Integration of Apache APISIX with OPA

API Security in Zero Trust

  • Security patterns for API gateways
  • Kong open source with security plugins
  • Rate limiting and DDoS protection
  • Authentication and authorization of APIs
  • Security considerations for GraphQL
  • API discovery and detection of shadow APIs

Data Protection and DLP

  • Data classification frameworks
  • Open source DLP tools and integration
  • Encryption in transit and at rest
  • Strategies for tokenization and masking
  • Policies for data loss prevention
  • Sovereign data handling in zero trust

Continuous Authentication and Authorization

  • Session management in zero trust environments
  • Mechanisms for continuous authentication
  • Context-aware access decisions
  • Risk scoring and dynamic authorization
  • Triggers for step-up authentication
  • Real-time policy enforcement

Monitoring and Observability in Zero Trust

  • Collection of security telemetry
  • Integration with SIEM using open source tools
  • User and entity behavior analytics (UEBA)
  • Audit logging and compliance reporting
  • Anomaly detection utilizing machine learning
  • Security dashboards and alerting

Zero Trust for Cloud-Native Workloads

  • Container security within a zero trust context
  • Management of ephemeral workload identity
  • Admission controllers for enforcing zero trust
  • Runtime security with Falco and Tetragon
  • Network policies for container segmentation
  • Patterns for immutable infrastructure

Implementing a Zero Trust Roadmap

  • Maturity assessment and gap analysis
  • Phased implementation approach
  • Design and execution of pilot projects
  • Change management and user adoption
  • Measuring success metrics for zero trust
  • Pitfalls to avoid and associated challenges

Production Deployment and Operations

  • Design patterns for high availability
  • Disaster recovery for zero trust infrastructure
  • Strategies for performance optimization
  • Troubleshooting authentication and authorization issues
  • Upgrading and patching zero trust components
  • Creation of documentation and runbooks

The Future of Zero Trust and Open Source

  • Emerging standards and protocols
  • Quantum-safe considerations for zero trust
  • Application of AI/ML in zero trust decisions
  • Federated zero trust architectures
  • Community resources and ongoing development
  • Summary and next steps

Requirements

  • Solid understanding of network security concepts and principles
  • Experience with identity and access management systems
  • Knowledge of PKI, certificates, and encryption fundamentals
  • Familiarity with microservices and container architectures
  • Experience in deploying and managing open-source software

Audience

  • Security Architects and Engineers
  • Infrastructure Architects designing modern security postures
  • DevSecOps Engineers implementing security pipelines
  • Network Administrators transitioning to zero trust models
 35 Hours

Number of participants


Price per participant

Upcoming Courses

Related Categories