Web Application Security with Secure Development Lifecycle (SDL)

Inquire now

Duration 2 days – 14 hours

 

Overview

 

This Web Application Security with SDL training equips participants with the essential knowledge and practical skills to build and maintain secure web applications by integrating security into every phase of the Secure Development Lifecycle (SDL).

 

Participants will learn how common web vulnerabilities happen (based on modern industry threats), how to prevent them through secure coding practices, and how to apply SDL controls such as threat modeling, secure design reviews, security testing (SAST/DAST), code review, and release security gates. The course combines hands-on demonstrations, real-world scenarios, and practical checklists to help teams implement security-by-design and reduce application security risks.

 

Objectives

 

  • Explain web application security risks and why SDL is critical
  • Identify common web vulnerabilities and attack paths
  • Apply secure coding and secure design principles for web apps
  • Conduct basic threat modeling and security requirement definition
  • Implement SDL checkpoints (planning → build → test → release → operations)
  • Use secure code review practices and vulnerability prevention techniques
  • Understand security testing approaches (SAST, DAST, dependency scanning)
  • Establish practical security controls for continuous improvement and compliance

 

Target Audience

 

  • Web Developers (Front-End / Back-End / Full Stack)
  • Software Engineers and Technical Leads
  • QA / Test Engineers (especially Security Testing roles)
  • DevOps / DevSecOps Engineers
  • Application Support / Production Support Teams
  • Software Architects
  • IT Security / InfoSec Professionals involved in application security
  • Project Managers / Delivery Managers managing software releases

 

Prerequisites 

  • Basic knowledge of web application concepts (HTTP/HTTPS, APIs, cookies, sessions)
  • Familiarity with modern web development practices (any language/framework)
  • Basic understanding of SDLC is helpful but not required
  • Laptop recommended for hands-on demos/tools (optional)

 

Course Outline 

 

Day 1 — Web Application Security Fundamentals + Core Vulnerabilities

 

Module 1: Introduction to Web Application Security

 

  • Why web apps are prime targets
  • Security goals: Confidentiality, Integrity, Availability
  • Common attack surfaces (web, API, auth, data, 3rd party components)
  • Security mindset: “Shift Left” + security-by-design

 

Module 2: Secure Development Lifecycle (SDL) Overview

 

  • What is SDL and how it reduces security risks
  • SDL phases and security gates
  • Roles & responsibilities (Dev, QA, Security, Product, Ops)
  • Defining “Done”: security acceptance criteria

 

Module 3: Top Web Vulnerabilities (Modern and Practical)

 

  • Injection (SQL/NoSQL, command injection)
  • Cross-Site Scripting (XSS) and input/output encoding
  • Broken authentication & session management
  • Access control failures (IDOR, privilege escalation)
  • CSRF basics and mitigation
  • Security misconfiguration and exposed secrets
  • Vulnerable components / dependency risks
  • Data exposure risks (PII, encryption basics)
    Activity: Vulnerability recognition workshop (real scenarios)

 

Module 4: Secure Coding Foundations

 

  • Input validation (server-side vs client-side)
  • Output encoding and safe rendering
  • Password storage best practices (hashing + salt)
  • Secure logging practices (avoid sensitive leakage)
  • Safe error handling (avoid information disclosure)
    Lab/Demo: Secure vs insecure patterns and prevention

 

Day 2 — Integrating Security into SDL + Security Testing & Controls

 

Module 5: Threat Modeling & Secure Design

  • Threat modeling fundamentals (assets, actors, threats, mitigations)
  • STRIDE approach (simple and usable version)
  • Secure design principles (least privilege, defense in depth)
  • Designing secure APIs and web services
    Workshop: Threat model a sample web app + define controls

 

Module 6: Authentication & Authorization Security

 

  • Authentication vs Authorization
  • Multi-factor authentication basics
  • Role-based access control (RBAC) and permission validation
  • Secure session handling, token security (JWT basics)
  • Security considerations for OAuth/SSO (overview)

 

Module 7: Security Testing in the SDL (Shift Left Testing)

 

  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA) / dependency scanning
  • Secrets scanning and config validation
  • Penetration testing vs vulnerability scanning
  • Choosing tools and defining test coverage

 

Module 8: Secure Code Review & Release Readiness

 

  • What to look for during secure code reviews
  • Common red flags and recurring coding mistakes
  • Security checklist for pre-release approval
  • Secure configuration baselines and hardening
  • Security documentation and traceability

 

Module 9: Monitoring, Incident Readiness, and Continuous Improvement

 

  • Monitoring and alerting basics
  • Handling vulnerability reports and patch workflows
  • Secure operations: patching, logging, incident response alignment
  • Metrics: vulnerability trends, risk scoring, time-to-fix
    Output: SDL security checklist + team action plan

 

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy