Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Static Application Security Testing (SAST) (2019)

Static Application Security Testing (SAST) (2019)

3h 26mIntermediate2019-08-08

Authors

Jerod Brennen

Jerod Brennen

Security Architect, Advisor, Speaker, Teacher

Course details

Building security testing into the software development life cycle is the best way to protect your app and your end users. This course identifies tools and techniques that developers can use to minimize the cost and impact of security testing—while maximizing its impact and effectiveness. In this course, instructor Jerod Brennen focuses on offline testing activities: preparing test plans, policies, and other documentation and conducting offline source code reviews. He also explains how to conduct offline testing for the OWASP Top Ten vulnerabilities. Along the way, you can become familiar with best practices around security in the SDLC. The hands-on sections—with demos of popular tools such as Codacy and SonarQube—prepare you to apply the lessons in the real world.

Learning objectives
Security frameworks
OWASP Top Ten
Building Security In Maturity Model (BSIMM)
Planning your testing projects
Creating security policies
Source code reviews
Application threat modeling
Offline testing for OWASP Top Ten vulnerabilities

Skills covered

Application SecuritySecurity TestingEssential TrainingCybersecurity

Concepts

0. Introduction

  • 01 - The importance of offline testing
  • 02 - What you should know

1. Leading Practices

  • 03 - Security in the SDLC
  • 04 - Development methodologies
  • 05 - Programming languages
  • 06 - Security frameworks
  • 07 - Intro to the OWASP Top Ten
  • 08 - Other notable OWASP projects
  • 09 - Top 25 Software Errors
  • 10 - BSIMM
  • 11 - Building your test lab
  • 12 - Preparing your checklist

2. Security Documentation

  • 13 - Internal project plans
  • 14 - Communication planning
  • 15 - Change control policy
  • 16 - Security incident response policy
  • 17 - Logging and monitoring policy
  • 18 - Third-party agreements
  • 19 - OWASP ASVS

3. Source Code Security Reviews

  • 20 - Challenges of assessing source code
  • 21 - OWASP Code Review Project
  • 22 - Bytecode scanners
  • 23 - Binary code scanners
  • 24 - Code review models
  • 25 - Application threat modeling
  • 26 - Code review metrics
  • 27 - Demo - Codacy
  • 28 - Demo - SonarQube

4. Offline Testing for the OWASP Top Ten (2017)

  • 29 - The OWASP Top Ten
  • 30 - A1 - Injection
  • 31 - A2 - Broken authentication
  • 32 - A3 - Sensitive data exposure
  • 33 - A4 - XML external entities (XXE)
  • 34 - A5 - Broken access control
  • 35 - A6 - Security misconfiguration
  • 36 - A7 - Cross-site scripting (XSS)
  • 37 - A8 - Insecure deserialization
  • 38 - A9 - Using components with known vulnerabilities
  • 39 - A10 - Insufficient logging and monitoring

Conclusion

  • 40 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal