• Online, Self-Paced
Course Description
In this course, you will learn how to mitigate the risks associated with Insecure Authorization which allows an adversary to execute functionality they should not be entitled to using an authenticated but lower-privilege user of the mobile app.

Learning Objectives

On successful completion of this course, learners should have the knowledge and skills to:

  • Identing the best practices for implementing secure authorization for mobile Internet of Things
  • How to mitigate the threat of insecure authorization
  • Identify and mitigate insecure direct object reference (IDOR) vulnerabilities

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Risk Management
  • Software Development

Feedback

If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.