Introduction
Intro video to course
()
1. Building Security from the Ground Up
Chapter introduction
()
Secure by design principles
()
Secure coding practices
()
Secure configuration and defaults
()
2. OWASP Top 10 Prevention
Prevention of OWASP Top 10
()
Stopping insecure design and misconfiguration failures
()
Defending against supply chain attacks and logging failures
()
3. Application Security Testing and Protection
Code testing for vulnerabilities
()
Testing an application for run-time vulnerabilities
()
Run-time protection
()
4. Threat Modelling
Chapter introduction
()
Threats vs. risks
()
Intro to threat modelling
()
Utilizing STRIDE for threat modelling
()
5. Utilizing Threat Modeling Tools
Threat modelling with OWASP Threat Dragon
()
Using attack trees in threat modelling
()
Completing a rapid threat modelling prototyping (RTMP)
()
6. Managing Findings from Threat Modeling
Risk rating using OWASP risk rating
()
CVSS scoring for vulnerability management
()
Transforming threats into secure designs
()
7. Understanding the Software Supply Chain
Chapter introduction
()
Software supply chain threat landscape
()
Software bill of materials (SBOM) fundamentals
()
Dependency management and open-source risk assessment
()
8. Collecting Artifacts and Understanding Risk
SLSA framework and build provenance
()
Artifact integrity and code signing
()
Vendor risk assessment and third-party security
()
9. Managing and Monitoring the Supply Chain
Continuous supply chain monitoring
()
Compliance and regulatory requirements
()
Supply chain incident response and recovery
()
10. Understanding Cloud and Container Fundamentals
Chapter introduction
()
Cloud-native security fundamentals
()
Container and serverless security
()
Cloud security automation and infrastructure as code (IaC) security
()
11. Understanding Container Security Practices
Kubernetes security architecture and RBAC
()
Container and registry security
()
Runtime protection and behavioral monitoring
()
12. Understanding Cloud Security Defenses
Network security and micro-segmentation
()
Secrets management and data protection
()
Compliance and governance in cloud-native environments
()
Conclusion
Course wrap-up video
()
Ex_Files_Advanced_Practices.zip
(918 KB)