Profile
This course aims to provide the participants with knowledge and skills in developing secure software through the application of well-established methods, processes, technologies, and tools. It is a practice-oriented course conducted with lectures and hands-on workshops. Course participants will be able to explain the pillars of information security, apply secure development life cycle in traditional and agile software development processes, explain the Dev-Sec-Op and software supply chain security concepts, elicit and develop security requirements, explain code security and reliability metrics and measures, apply secure coding principles and practices for high-level programming languages, apply Web and mobile application security concepts from OWASP top-10 list, apply design time security concepts using attack surface analysis and threat modeling tools, conduct the white box and black box security testing with appropriate software tools, and explain the Dec-Sec-Op security operations concepts.
What You'll Learn
This four-day course takes on a practice-oriented approach and is conducted with lectures and hands-on workshops. To reinforce the learners' knowledge and skills, short quiz and assignments will be conducted at the end of each day. A final assessment (approximately 1.5 hours) is conducted on the last day of the course to provide a holistic review of the course for the learners.