Cybersecurity and Secure Development

Inquire now

The Cybersecurity and Secure Development Training Course provides participants with a practical understanding of cybersecurity principles and the secure software development practices required to build, deploy, and maintain resilient applications.

The course covers common cyber threats, application vulnerabilities, secure coding principles, identity and access management, data protection, application and API security, vulnerability management, and security throughout the Software Development Life Cycle (SDLC). Participants will learn how security can be integrated into requirements, design, development, testing, deployment, and maintenance rather than being treated only as a final-stage activity.

The program is designed for developers, engineers, technical teams, and IT professionals who need to understand both cybersecurity fundamentals and their application to modern software development environments.

 

Duration 5 Days – 35 hrs.

 

Objectives

  • Understand fundamental cybersecurity concepts, terminology, threats, and risks.
  • Recognize common attack techniques and software security vulnerabilities.
  • Understand the principles of confidentiality, integrity, and availability.
  • Apply secure development principles throughout the SDLC.
  • Identify and mitigate common application security vulnerabilities.
  • Apply secure coding practices when developing applications.
  • Understand authentication, authorization, access control, and identity security.
  • Protect sensitive information through appropriate encryption and data protection practices.
  • Understand common web application and API security risks.
  • Apply input validation, output encoding, and secure error-handling techniques.
  • Understand dependency, library, and software supply-chain security risks.
  • Incorporate security testing into software development and delivery processes.
  • Understand vulnerability identification, prioritization, remediation, and management.
  • Apply DevSecOps concepts to CI/CD and modern development environments.
  • Improve security awareness when designing, developing, deploying, and maintaining applications.

 

Target Audience

  • Software Developers
  • Application Developers
  • Web Developers
  • Software Engineers
  • DevOps Engineers
  • DevSecOps Engineers
  • QA Engineers and Software Testers
  • Systems Analysts
  • Application Support Engineers
  • IT Security Professionals
  • Cybersecurity Analysts
  • Technical Leads
  • Solution and Software Architects
  • IT Professionals involved in application development and deployment
  • Technical Project Team Members
  • IT professionals transitioning into secure software development roles

 

Prerequisites

  • Basic understanding of computers, operating systems, networks, and applications.
  • Basic familiarity with software development concepts.
  • General understanding of the Software Development Life Cycle (SDLC).
  • Basic programming or scripting knowledge is beneficial but not mandatory.
  • No advanced cybersecurity experience is required.

 

 

Course Outline

Day 1 – Cybersecurity Fundamentals and the Modern Threat Landscape

Module 1: Introduction to Cybersecurity

  • Cybersecurity concepts and terminology
  • Confidentiality, integrity, and availability
  • Assets, threats, vulnerabilities, and risks
  • Attack surface and attack vectors
  • Security controls and defense-in-depth
  • People, process, and technology in cybersecurity

Module 2: Understanding Cyber Threats and Attacks

  • Malware and ransomware
  • Phishing and social engineering
  • Credential and password attacks
  • Network-based attacks
  • Web and application attacks
  • Insider threats
  • Data breaches and information exposure
  • Emerging cybersecurity threats

Module 3: Application Security Fundamentals

  • Why applications become security targets
  • Application attack surfaces
  • Common application security weaknesses
  • OWASP Top 10 overview
  • Security vulnerabilities versus software defects
  • Security responsibilities of development teams

Module 4: Security Principles for Software Development

  • Secure by design
  • Secure by default
  • Least privilege
  • Separation of duties
  • Defense-in-depth
  • Minimize attack surface
  • Fail securely
  • Zero Trust concepts in application environments

 

Day 2 – Secure SDLC, Threat Modeling, and Secure Design

Module 5: Secure Software Development Life Cycle

  • Traditional SDLC and Secure SDLC
  • Security requirements
  • Secure architecture and design
  • Secure development
  • Security testing
  • Secure deployment
  • Operations and maintenance
  • Integrating security throughout development

Module 6: Security Requirements and Risk Analysis

  • Identifying security requirements
  • Functional versus security requirements
  • Data classification
  • Privacy and security considerations
  • Risk identification
  • Risk-based security decisions
  • Security acceptance criteria

Module 7: Threat Modeling

  • Introduction to threat modeling
  • Identifying assets and trust boundaries
  • Understanding application data flows
  • Identifying potential threats
  • STRIDE concepts
  • Attack trees and abuse cases
  • Prioritizing threats
  • Selecting appropriate security controls

Module 8: Secure Architecture and Application Design

  • Secure architecture principles
  • Trust boundaries
  • Application segmentation
  • Secure communication between components
  • Reducing attack surfaces
  • Security considerations for distributed applications
  • Cloud and microservices security considerations
  • Designing for resilience

 

Day 3 – Secure Coding and Application Security

Module 9: Secure Coding Fundamentals

  • Secure coding principles
  • Validating untrusted input
  • Input validation
  • Output encoding
  • Secure data handling
  • Error and exception handling
  • Logging considerations
  • Avoiding information leakage

Module 10: Common Application Vulnerabilities

  • Injection vulnerabilities
  • SQL injection
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Broken access control
  • Security misconfiguration
  • Insecure design
  • Server-Side Request Forgery (SSRF)
  • Path traversal
  • File upload vulnerabilities

Module 11: Authentication and Authorization Security

  • Authentication versus authorization
  • Secure password handling
  • Password hashing and salting
  • Multi-factor authentication
  • Session management
  • Role-Based Access Control
  • Principle of least privilege
  • Token-based authentication
  • Common authentication vulnerabilities

Module 12: Cryptography and Data Protection

  • Encryption fundamentals
  • Data at rest and data in transit
  • Symmetric and asymmetric encryption
  • Hashing
  • Digital signatures
  • Certificates and PKI concepts
  • TLS and secure communications
  • Key and secret management
  • Common cryptographic implementation mistakes

 

Day 4 – Web, API, Dependency, and Security Testing

Module 13: Web Application Security

  • Web application architecture and attack surfaces
  • Browser and server security considerations
  • Cookies and session security
  • HTTP security headers
  • Secure file handling
  • Security configuration
  • Preventing common web application attacks

Module 14: API Security

  • API security fundamentals
  • Authentication and authorization for APIs
  • API access control
  • Input and request validation
  • Rate limiting
  • API keys and tokens
  • Secure REST API practices
  • Common API security vulnerabilities
  • OWASP API Security concepts

Module 15: Third-Party Components and Software Supply Chain Security

  • Open-source and third-party dependencies
  • Vulnerable libraries and components
  • Dependency management
  • Package and repository risks
  • Software Composition Analysis
  • Software Bill of Materials concepts
  • Dependency updates and patch management
  • Software supply-chain attacks

Module 16: Application Security Testing

  • Security testing throughout the SDLC
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)
  • Interactive Application Security Testing concepts
  • Penetration testing
  • Code review for security
  • Vulnerability scanning
  • False positives and validation of findings

 

Day 5 – DevSecOps, Vulnerability Management, and Secure Operations

Module 17: Introduction to DevSecOps

  • DevOps versus DevSecOps
  • Shift-left security
  • Continuous security
  • Security responsibilities within development teams
  • Integrating security into development workflows
  • Security automation
  • Security gates

Module 18: Securing CI/CD Pipelines

  • CI/CD security risks
  • Secure source-code repositories
  • Access control for pipelines
  • Secrets management
  • Dependency scanning
  • Code and application security scanning
  • Container and image scanning concepts
  • Protecting build and deployment environments

Module 19: Vulnerability Management and Remediation

  • Vulnerability identification
  • Vulnerability classification
  • Understanding vulnerability severity
  • CVE and CVSS concepts
  • Risk-based vulnerability prioritization
  • Remediation planning
  • Patch management
  • Vulnerability verification
  • Tracking and managing security findings

Module 20: Secure Deployment, Monitoring, and Incident Readiness

  • Secure configuration and hardening
  • Environment separation
  • Secure production deployment
  • Application logging
  • Security monitoring
  • Detection of suspicious application behavior
  • Incident response fundamentals
  • Developer responsibilities during security incidents
  • Post-incident remediation and lessons learned

Module 21: Building a Secure Development Culture

  • Security ownership within development teams
  • Developer security awareness
  • Security champions
  • Secure development standards
  • Security checklists
  • Continuous improvement
  • Incorporating security into everyday development practices
  • Building sustainable Secure SDLC and DevSecOps practices

 

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy