Public Sector

We've had the pleasure of working with UK and overseas central and local government departments, including Healthcare (NHS and Foundation Trusts), Defence, Education (Universities and colleges), many of the main Civil Service departments, Emergency Services; also public-owned corporations including the BBC, Bank of England, Ordnance Survey, and regulatory bodies such as Ofgem.

We are registered on Crown Commercial Service’s (CCS) Dynamic Purchasing System (RM6219 Training and Learning) and also with numerous tender portals such as Ariba, Coupa and Delta E-Sourcing.

Read more...

Graduate Training Schemes

Framework Training has a strong track record of providing a solid introduction into the working world for technical graduates across myriad industries. We provide the opportunity to learn and gain valuable hands-on experience in a supportive, friendly and sociable training environment.

Attract & retain the brightest new starters

We know it is vital for our clients to invest in the future of their talented grads; not only to provide them with high-quality, professional training essential for their roles, but to embed them within the organisation’s culture and guide them on the right path to a successful career.

After all, your new hires could well be the next leaders and their creative ideas and unique insights are invaluable to your business.

Read more ...

Learning & Development

Our unique portfolio of high-quality technical courses and training programmes are industry-respected. They’re carefully designed so that delegates can seamlessly apply what they’ve learnt back in the workplace. Our team of domain experts, trainers, and support teams know our field — and all things tech — inside out, and we work hard to keep ourselves up to speed with the latest innovations. 

We’re proud to develop and deliver innovative learning solutions that actually work and make a tangible difference to your people and your business, driving through positive lasting change. Our training courses and programmes are human-centred. Everything we do is underpinned by our commitment to continuous improvement and learning and generally making things much better.

Read more...

Corporate & Volume Pricing

Whether you are looking to book multiple places on public scheduled courses (attended remotely or in our training centres in London) or planning private courses for a team within your organisation, we will be happy to discuss preferential pricing which maximise your staff education budget.

Enquire today about:

  • Training programme pricing models  

  • Multi-course voucher schemes

Read more...

Custom Learning Paths

We understand that your team training needs don't always fit into a "one size fits all" mould, and we're very happy to explore ways in which we can tailor a bespoke learning path to fit your learning needs.

Find out about how we can customise everything from short overviews, intensive workshops, and wider training programmes that give you coverage of the most relevant topics based on what your staff need to excel in their roles.

Read more...

Docker Security Deep Dive: Hardening Containerized Workflows

Learn to implement defense-in-depth strategies to secure your software supply chain and container runtime environments.

About the course

This intensive one-day masterclass focuses on the specialized domain of container security, moving beyond basic configuration to advanced supply chain protection. As organizations increasingly rely on third-party base images and automated pipelines, understanding how to verify provenance and enforce policy is critical.

We dive deep into the mechanics of Software Bill of Materials (SBOMs), image signing, and the practical application of the CIS Docker Benchmark to reduce the attack surface of your infrastructure - all of which will play a vital part in compliance with UK and EU Cybersecurity and Resilience legislation.

Participants will learn how to transition from reactive vulnerability patching to a proactive "Policy as Code" posture. By integrating tools like Docker Scout and Sigstore/cosign directly into CI/CD workflows, you will gain the skills to achieve SLSA Level 3 compliance and ensure that only verified, scanned, and authorized artifacts reach your production environment.

Instructor-led online and in-house face-to-face options are available - as part of a wider customised training programme, or as a standalone workshop, on-site at your offices or at one of many flexible meeting spaces in the UK and around the World.

  • By the end of this course, attendees will be able to:

    • Hardening Dockerfiles using non-root execution, read-only filesystems, and secure secret handling.
    • Implementing automated vulnerability management and remediation workflows using Docker Scout.
    • Generating and analyzing SBOMs in SPDX and CycloneDX formats to track software dependencies.
    • Establishing a trusted supply chain through image signing, verification, and SLSA provenance attestations.
    • Auditing and benchmarking Docker configurations against the CIS Docker Benchmark.
  • This course is designed for Security Engineers, DevOps Leads, and Senior Developers tasked with securing cloud-native applications. It is ideal for professionals working in regulated industries or those aiming to implement rigorous DevSecOps practices within their CI/CD pipelines.

  • Attendees should have attended our Docker Training Course or have equivalent skills: a solid grasp of Docker fundamentals, including building images and managing containers. Familiarity with CI/CD concepts (such as GitHub Actions or GitLab CI) and basic cryptographic principles (public/private keys) is highly recommended.

  • This Docker Security course is available for private / custom delivery for your team - as an in-house face-to-face workshop at your location of choice, or as online instructor-led training via MS Teams (or your own preferred platform).

    Get in touch to find out how we can deliver tailored training which focuses on your project requirements and learning goals.

  • Hardening the Container Foundation

    • Base Image Hygiene: Identifying and migrating to minimal footprints like Alpine and Distroless.

    • Immutable Tagging: Moving from semantic tags to immutable digest pinning (sha256).

    • Update Strategies: Patterns for automated base image patching and rebuilds.

    Secure Image Engineering

    • Dockerfile Best Practices: Implementing the USER instruction and multi - stage builds for dependency isolation.

    • Filesystem Security: Configuring read - only containers and using temporary filesystems (tmpfs) for volatile data.

    • Secret Management: Preventing credential leakage via build - time secret mounts and environment variable avoidance.

    Vulnerability Management and Transparency

    • Continuous Scanning: Integrated vulnerability detection with Docker Scout.

    • SBOM Fundamentals: Generating and utilizing Software Bill of Materials in SPDX and CycloneDX formats.

    • Remediation Workflows: Interpreting scan results and prioritizing fixes based on exploitability.

    Supply Chain Security and Attestations

    • Image Signing: Using Sigstore/cosign for digital signatures and keyless signing.

    • Verification: Enforcing signature checks at the registry and runtime levels.

    • SLSA Framework: Achieving SLSA Level 3 through build provenance attestations.

    • Attestation Storage: Managing signatures and metadata alongside images in the registry.

    Policy and Compliance

    • Policy as Code: Defining and enforcing security gates in CI/CD pipelines.

    • Registry Hardening: Access control, image lifecycle policies, and private registry security.

    • CIS Docker Benchmark: Auditing the host, daemon, and container configurations against industry standards.

Trusted by

Amadeus Services company logo BBC logo IBM company logo Crown Commercial Service Supplier (CCS) logo

Public Courses Dates and Rates

Standard duration: 1 day

Please get in touch for pricing and availability.

Course enquiry

Send us a no-obligation enquiry about this course

Choose how you first heard about Framework Training.

Related courses