Application Security

I.       Overview:

The training program provides critical security skills and knowledge required throughout a typical software development life cycle (SDLC), focusing on the importance of the implementation of secure methodologies and practices in today’s insecure operating environment. It was developed to prepare software professionals with the capabilities that are expected by employers and academia globally. It is designed to be a hands-on, comprehensive application security training course to teach software professionals to create secure applications. The training program encompasses security activities involved in all phases of the secure SDLC: planning, creating, testing, and deploying an application.  Unlike other application security trainings, it goes beyond just the guidelines on secure coding practices and includes secure requirement gathering, robust application design, and handling security issues in the post development phases of application development. It’s desired by software application engineers, analysts, and testers from around the world and is respected by hiring authorities.

II.    Duration: 

5 days ( 40 hours)

III. Objectives:

      After completing this course, students will be able to:

-       In-depth understanding of secure SDLC and secure SDLC models

-       Knowledge of OWASP Top 10, threat modelling, SAST and DAST

-       Capturing security requirements of an application in development

-       Defining, maintaining, and enforcing application security best practices

-       Performing manual and automated code review of application

-       Conducting application security testing for web applications to assess the vulnerabilities

-       Driving development of a holistic application security program

-       Rating the severity of defects and publishing comprehensive reports, detailing associated risks and mitigations

-       Working in teams to improve security posture

-       Application security scanning technologies such as AppScan, Fortify, WebInspect, static application security testing (SAST), dynamic application security testing (DAST), single sign on, and encryption

-       Following secure coding standards that are based on industry-accepted best practices such as

-       OWASP Guide, or CERT Secure Coding to address common coding vulnerabilities.

-       Creating a software source code review process that is a part of the development cycles (SDLC, Agile, CI/CD)

IV. Intended Audience:

-       NET and Java Developers with a minimum of 2 years of experience and individuals who want to become application security engineers, analysts, or testers.

-       Individuals involved in the role of developing, testing, managing, or protecting applications

V.    Course outlines:

1.      Application Security

  • Understanding Application Security, Threat, and Attacks
  • Security Requirements Gathering
  • Security Application Design and Architecture
  • Secure Coding Practices for Input Validation
  • Secure Coding Practices for Authentication and Authorization
  • Secure Coding Practices for Cryptography
  • Secure Coding Practices for  Session Management
  • Secure Coding Practices for Error Handling
  • Static and Dynamic Application Security Testing (SAST and DAST)
  • Secure Deployment and Maintenance

2.      Database Security

  • Fundamentals of access control
  • Database Access Control
  • Using Views for Access Control
  • Security Logs, Audit trails
  • Encryption
  • Statistical DB security
  • DB and internet
  • Discretionary Control
  • Data Exchange Example : ABC Bank

3.      API Security

  • API Security in a Nutshell
  • API security
  • Web API Security
  • SOAP API security
  • REST API security
  • API Security Vulnerabilities
  • Authentication and Authorization
  • API Monitoring
  • Use quotas and Rate-Limiting
  • Transport Security
  • Error Handling
  • JWT Security
  • Threat models of API security risks
  • Học trực tuyến

  • Học tại Hồ Chí Minh

  • Học tại Hà Nội

Các khóa học khác