Course Outline
- Introduction
- Explanation of Application Security and Vulnerabilities for Government
- Secure Programming
- Description of ABAP Best Practices and Handling of SY-SUBRC for Government
- Understanding Injection Vulnerabilities (SQL Injection, Code Injection, Call Injection, Operating System Command Injection, Directory Traversal, Web-Based Threats, Cross-Site Scripting, Cross-Site Request Forgery, Inaccurate Programming) for Government
- Security Testing Tools
- Description of Security Testing Tools for Government
- Explanation of ATC and CVA for Government
- Troubleshooting
- Summary and Conclusion
Requirements
- Knowledge of ABAP programming
- Basic knowledge of security concepts
Audience
- Developers
- Technology Consultants
This course is designed to equip developers with the essential skills and understanding needed to develop secure ABAP code. Participants will learn about various types of vulnerabilities and how to effectively implement appropriate countermeasures to safeguard applications against external threats.
Participants will also gain proficiency in using the ABAP Testing Cockpit (ATC) and the SAP NetWeaver Application service add-on for code vulnerability analysis (CVA) to ensure the security and compliance of custom-developed code. These tools are critical for government agencies seeking to enhance their cybersecurity practices and maintain high standards of governance and accountability.
Testimonials (5)
Multiple examples for each module and great knowledge of the trainer.
Sebastian - BRD
Course - Secure Developer Java (Inc OWASP)
Module3 Applications Attacks and Exploits, XSS, SQL injection Module4 Servers Attacks and Exploits, DOS, BOF
Tshifhiwa - Vodacom
Course - How to Write Secure Code
General course information
Paulo Gouveia - EID
Course - C/C++ Secure Coding
The trainer's subject knowledge was excellent, and the way the sessions were set out so that the audience could follow along with the demonstrations really helped to cement that knowledge, compared to just sitting and listening.
Jack Allan - RSM UK Management Ltd.
Course - Secure Developer .NET (Inc OWASP)
Nothing it was perfect.