Secure Development and Application Security
Developers, testers and technical leads who build or review web applications and APIs. You should be able to read code in at least one web language.
- Cybersecurity
- Intermediate
- 6 days, or 12 half-day sessions
- Instructor-led cohort · In-house for your team · Online, live
What you will be able to do
- Recognise the vulnerabilities in the OWASP Top 10 and the OWASP API Security Top 10 in real code.
- Fix common flaws such as injection, broken access control and insecure authentication.
- Model the threats to a new feature before it is built, and agree what controls it needs.
- Handle secrets, sessions, tokens and personal data safely in web applications and APIs.
- Add security checks to the delivery pipeline, from dependency scanning to automated scans.
- Review code and test applications for security problems, and report them so they get fixed.
Security is cheaper when it is built in
A vulnerability found in design costs a conversation. The same vulnerability found after launch can cost customer data, money and trust, especially in banking, payments and any system that holds personal data.
This course teaches developers and testers to find and fix security problems while the code is still being written.
How it is taught
You work on a deliberately vulnerable sample application with a web front end and a REST API, modelled on the kind of systems built across the region: customer portals, payment callbacks and back-office tools. You attack it in a lab, fix what you find, and add checks to its pipeline so the same flaws do not come back.
Examples are in common web languages, and the techniques apply to any stack. If you are new to security, start with Cybersecurity Fundamentals.
Syllabus
Why applications get breached
- How attackers approach a web application or API
- The OWASP Top 10, with examples from real incidents
- Security as part of the delivery life cycle
Threat modelling
- Data flow diagrams and trust boundaries
- Identifying threats with STRIDE
- Turning threats into requirements and tests
Injection and input handling
- SQL, command and template injection
- Cross-site scripting and output encoding
- Validating input and handling file uploads safely
Authentication, sessions and access control
- Password storage, multi-factor authentication and account recovery
- Sessions, JSON Web Tokens and OAuth 2.0 in practice
- Broken access control and how to test for it
API security
- The OWASP API Security Top 10
- Rate limiting, input schemas and API gateways
- Securing payment callbacks and webhooks
Secrets, data and dependencies
- Keeping keys and passwords out of code
- Encryption in transit and at rest
- Personal data and the Kenya Data Protection Act 2019 for developers
- Vulnerable dependencies and the software supply chain
Security testing in the pipeline
- Static analysis and dependency scanning
- Dynamic scanning with OWASP ZAP
- Security code review checklists
Handling vulnerabilities
- Rating severity and prioritising fixes
- Writing findings developers can act on
- Logging and monitoring for application attacks
Assessment and certificate
- A practical assessment: you find and fix vulnerabilities in a sample application and its API, write a short threat model for a new feature, and report your findings to an assessor.
- Deefrent Academy certificate, awarded on passing the course assessment.
- Ask for dates and fees. Tell us the course and the format you prefer, and we reply with the next dates and the fee.
Training a whole team?
This course can run privately for your organisation, at your premises or online, with examples drawn from your own systems.
Ready to join the next cohort?
Tell us how you would like to attend. We reply with the next dates, the fee and what you need before you start.