Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Application Security Foundations
- The role of application security in contemporary software development
- An overview of prevalent cyber threats and attack vectors
- Recognizing security risks across web and mobile platforms
Secure Software Development Lifecycle (SDLC)
- Embedding security into every stage of the development process
- Conducting threat modeling and risk assessments
- Incorporating automated security tests within CI/CD pipelines
Identifying Common Security Vulnerabilities
- An introduction to the OWASP Top 10 security risks
- Recognizing coding errors that result in vulnerabilities
- Practicing the exploitation of insecure applications (hands-on sessions with DVWA/WebGoat)
Input Validation and Secure Coding Standards
- Guarding against SQL injection, cross-site scripting (XSS), and command injection
- Applying best practices for input sanitization and validation
- Developing robust authentication and authorization mechanisms
Session Management and Data Security
- Managing session security through cookies, tokens, and JWT best practices
- Applying data encryption techniques and secure storage methods
- Building secure APIs and mitigating API abuse
Security Testing and Vulnerability Analysis
- Leveraging OWASP ZAP and Burp Suite for comprehensive security testing
- Performing Static and Dynamic Application Security Testing (SAST/DAST)
- Understanding the fundamentals of penetration testing for developers
Establishing Secure DevOps (DevSecOps)
- Automating security controls within DevOps workflows
- Enhancing container security and protecting cloud-based applications
- Managing incident response and continuous security monitoring
Conclusion and Path Forward
- Reviewing the primary lessons learned in the course
- Accessing resources for ongoing professional development
- Open Q&A and concluding comments
Requirements
- Foundational knowledge of any programming language
- Practical experience in developing applications
Target Audience
- Software developers
- Application security engineers
- DevOps and security teams
21 Hours
Testimonials (1)
Lot's of information explained very well. Good examples, interesting exercises. Trainer showed us his real world experience.