Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Application Security
- The critical role of application security in contemporary software engineering
- A survey of prevalent cyber threats and attack vectors
- An analysis of security risks associated with web and mobile applications
Secure Software Development Lifecycle (SDLC)
- Embedding security measures throughout all development phases
- Conducting threat modeling and risk assessments
- Deploying automated security testing within CI/CD pipelines
Understanding Common Security Vulnerabilities
- An overview of the OWASP Top 10 security risks
- Identification of common coding errors that result in vulnerabilities
- Practical exercises on exploiting insecure applications using DVWA and WebGoat
Input Validation and Secure Coding Practices
- Mitigation strategies for SQL injection, cross-site scripting (XSS), and command injection
- Guidelines for input sanitization and validation
- Deployment of secure authentication and authorization protocols
Session Management and Data Protection
- Best practices for session security, including cookies, tokens, and JWTs
- Techniques for data encryption and secure storage
- Secure API development and protection against misuse
Security Testing and Vulnerability Assessment
- Utilizing OWASP ZAP and Burp Suite for security testing
- Static and dynamic application security testing (SAST/DAST)
- Fundamentals of penetration testing for developers
Implementing Secure DevOps (DevSecOps)
- Integrating security automation into DevOps workflows
- Container security and securing cloud-based applications
- Incident response procedures and security monitoring
Summary and Next Steps
- Key takeaways from the course material
- Curated resources for continued education in application security for government contexts
- Q&A session and closing remarks
Requirements
- Fundamental principles of programming languages
- Practical experience in application development
Target Audience for government professionals:
- Software developers
- Application security engineers
- DevOps and security teams
21 Hours
Testimonials (1)
Lot's of information explained very well. Good examples, interesting exercises. Trainer showed us his real world experience.