Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction to Application Security
- The significance of application security in contemporary software development
- An overview of prevalent cyber threats and attack vectors
- Identifying security risks in web and mobile applications
Secure Software Development Lifecycle (SDLC)
- Embedding security throughout every phase of development
- Threat modeling and risk assessment strategies
- Automated security testing within CI/CD pipelines
Recognizing Common Security Vulnerabilities
- An introduction to the OWASP Top 10 security risks
- Typical coding flaws that result in vulnerabilities
- Practicing the exploitation of insecure applications (hands-on exercises using DVWA/WebGoat)
Input Validation and Secure Coding Standards
- Preventing SQL injection, cross-site scripting (XSS), and command injection
- Best practices for input sanitization and validation
- Implementing secure authentication and authorization mechanisms
Session Management and Data Protection
- Managing session security: cookies, tokens, and JWT best practices
- Data encryption techniques and secure storage methods
- Secure API development and protection against API abuses
Security Testing and Vulnerability Assessment
- Employing OWASP ZAP and Burp Suite for security testing
- Static and dynamic application security testing (SAST/DAST)
- Foundations of penetration testing for developers
Adopting Secure DevOps (DevSecOps)
- Security automation within DevOps workflows
- Container security and securing cloud-based applications
- Incident response protocols and security monitoring
Summary and Next Steps
- Key takeaways from the course
- Resources for continued learning
- Q&A session and concluding remarks
Requirements
- Foundational knowledge of any programming language
- Practical experience in developing applications
Target Audience
- Software developers
- Application security engineers
- DevOps and security teams
21 Hours
Testimonials (1)
Lot's of information explained very well. Good examples, interesting exercises. Trainer showed us his real world experience.