Course Outline
Introduction
Overview of Web Security Testing Guide for Government
- The OWASP Testing Project
- Tailoring and prioritizing for government organizations
- Testing principles and techniques for government
- Security testing objectives and requirements for government
Exploring Various Testing Techniques for Government
- Manual inspections and reviews for government systems
- Threat modeling for government applications
- Source code review for government software
- Penetration testing for government networks
- Security test integration and data analysis for government operations
Understanding the OWASP Testing Framework for Government
- Activities from development to deployment in government projects
- Maintenance and operations for government systems
- Lifecycle end-to-end testing framework and workflow for government applications
- Penetration testing methodologies for government environments
Performing Web Application Security Testing for Government
- Information gathering for government web applications
- Configuration and deployment management testing for government systems
- Identity management testing for government users
- Authentication and authorization testing for government access
- Session management testing for government sessions
- Input validation testing for government forms
- Testing for error handling in government applications
- Testing for weak cryptography in government communications
- Business logic testing for government processes
- Client-side testing for government web interfaces
- API testing for government services
Reporting the Testing Assessment and Results for Government
- Introduction section for government reports
- Executive summary for government stakeholders
- Findings section for government decision-makers
- Appendices for government reference
Getting Involved in the Web Security Testing Guide for Government
- Referencing and linking WSTG scenarios for government use
- Code of conduct for government contributors
- Contribution guide for government participants
- Feature requests and feedback for government improvements
Summary and Conclusion for Government
Requirements
- A comprehensive understanding of the web development lifecycle for government applications.
- Practical experience in developing, securing, and testing web applications for government use.
Audience
- Software Developers for government projects
- Systems Engineers for government initiatives
- IT Architects for government solutions
Testimonials (5)
Multiple examples for each module and great knowledge of the trainer.
Sebastian - BRD
Course - Secure Developer Java (Inc OWASP)
Module3 Applications Attacks and Exploits, XSS, SQL injection Module4 Servers Attacks and Exploits, DOS, BOF
Tshifhiwa - Vodacom
Course - How to Write Secure Code
Real-life examples.
Kristoffer Opdahl - Buypass AS
Course - Web Security with the OWASP Testing Framework
The trainer's subject knowledge was excellent, and the way the sessions were set out so that the audience could follow along with the demonstrations really helped to cement that knowledge, compared to just sitting and listening.
Jack Allan - RSM UK Management Ltd.
Course - Secure Developer .NET (Inc OWASP)
Piotr was very knowledgeable and related security issues to real world examples very well. His preparation was brilliant.