This course is designed to equip students with the knowledge and tools needed to identify and defend against security vulnerabilities in software applications. Students will put theory to practice by completing real world labs that include testing applications for software vulnerabilities, identifying weaknesses in design through architecture risks analysis and threat modeling, conducting secure code reviews and more. On the final day of training, students will complete a real world hacking exercise on a live web application.
Upon completion, attendees should have the skills to perform the following:
- Identify application security vulnerabilities in any software application
- Review software architecture diagrams and identify attack points
- Perform web application penetration testing
- Design controls to defend against application vulnerabilities
- Identify vulnerabilities as they relate to the OWASP Top 10
- Perform advanced attacks against web applications
- Perform security code reviews
- Develop security test scripts
- Build a web hacking toolbox
- Integrate security best practices into the Software Development Lifecycle (SDLC)
- Communicate to both technical and non-technical individuals concerning application vulnerabilities
Objective Of Labs:
This is an intensive hands-on class; you will spend 50% of student class time performing labs focusing on both the OWASP model as well as the technicalities that detail PCI compliance in respects to secure coding.
This 4-day course retails for $3,500.
Learning Objectives
Upon completion, Certified Secure Web Application Engineer students will be able to establish industry acceptable auditing standards with current best practices and policies. Students will also be prepared to competently take the C)SWAE exam.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Competency Areas
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.