Get in Touch

Course Outline

Introduction

Overview of the Web Security Testing Guide

  • The OWASP Testing Project
  • Tailoring and prioritizing frameworks for organizations
  • Core testing principles and techniques
  • Defining security testing objectives and requirements

Exploring Various Testing Techniques

  • Manual inspections and code reviews
  • Threat modeling practices
  • Source code analysis
  • Penetration testing strategies
  • Integrating security tests and analyzing data

Understanding the OWASP Testing Framework

  • Activities spanning from development to deployment
  • Maintenance and operational considerations
  • End-to-end lifecycle testing framework and workflow
  • Methodologies for penetration testing

Executing Web Application Security Testing

  • Gathering relevant information
  • Testing configuration and deployment management
  • Identity management verification
  • Authentication and authorization controls
  • Session management integrity
  • Input validation checks
  • Error handling mechanisms
  • Weak cryptography detection
  • Business logic vulnerabilities
  • Client-side security checks
  • API security testing

Reporting on Testing Assessments and Results

  • Composing the introduction section
  • Drafting the executive summary
  • Detailing the findings section
  • Including relevant appendices

Engaging with the Web Security Testing Guide

  • Referencing and linking WSTG scenarios
  • Adhering to the code of conduct
  • Following the contribution guide
  • Submitting feature requests and feedback

Summary and Conclusion

Requirements

  • A foundational understanding of the web development lifecycle
  • Practical experience in web application development, security, and testing

Target Audience

  • Developers
  • Engineers
  • Architects
 21 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories