Introduction
Welcome to the course
()
The application security landscape
()
OWASP DevSecOps Guideline
()
1. Securing Web Apps
OWASP Top 10: The most critical risks
()
Broken access control
()
Demo: Implementing strong access controls
()
Injection attacks
()
Demo: SQL injection attack and mitigation
()
Configuration security
()
Secure by design
()
2. Secure Development Practices
Security in the software development lifecycle (SDLC)
()
Secure coding principles
()
Input validation and sanitization
()
Demo: Input validation and sanitization techniques
()
Error handling and logging
()
Demo: Secure error handling and logging
()
Cryptography fundamentals
()
Demo: Encryption and hashing in practice
()
3. Security Testing and Verification
Security testing: Finding and fixing vulnerabilities
()
Secrets management
()
Secure software supply chain management (SCA)
()
Static application security testing (SAST)
()
Demo: Using a SAST Tool
()
Dynamic application security testing (DAST)
()
Demo: Using a DAST Tool
()
Interactive application security testing (IAST)
()
Implementing security in the CI/CD pipeline
()
4. API Security
API security distinctions
()
OWASP API Security Top Ten
()
Broken object level authorization
()
Broken authentication
()
Demo: Implementing API authentication controls
()
Unrestricted resource consumption
()
Demo: Implementing resource consumption controls
()
5. Mobile App Security
OWASP Mobile Security Top Ten
()
Improper credential usage
()
Demo: Secure credential usage
()
Inadequate supply chain security
()
Demo: Validating supply chain security
()
Insecure authentication and authorization
()
6. Cloud-Native Applications
Cloud security considerations
()
Container security
()
Serverless security
()
Securing microservices
()
Security in the Internet of Things (IoT)
()
7. Securing AI Applications
Artificial intelligence and machine learning in security
()
OWASP Top Ten for Large Language Model Applications
()
Prompt injection attacks
()
Demo: Prompt injection attacks
()
Insecure output handling
()
Training data poisoning
()
8. Assessment Methodologies
Security regulations and compliance
()
Threat modeling
()
Demo: Building a threat model
()
Web security testing guide
()
Demo: Conducting a web security test
()
Application Security Verification Standard (ASVS)
()
Demo: Using the ASVS
()
Penetration testing
()
Demo: Conducting a penetration test
()
Conclusion
Ethical hacking and bug bounty programs
()
Application security certifications
()
Application security in different industries
()
Future trends in application security
()
Creating a career in application security
()
Ex_Files_Complete_Guide_to_Application_Security.zip
(2.2 MB)