Programming Foundations: Secure Coding
2hBeginner2025-06-03
Authors

Frank P Moley III
Senior Principal Engineer at Catch&Release
Course details
This course is an introduction to secure development practices related to various aspects of software development. Security architect Frank Moley introduces you to risk analysis, including proactive risk identifications. Frank then looks at the most common types of vulnerabilities that plague applications today, including client/server issues, with a heavy focus on web-based and embedded and IoT focused development. The course then gets into a primer of cryptography, the role it plays in security, and its proper use by looking at the vulnerabilities around its misuse. Frank finishes the course by looking at strategies for each phase of the software development lifecycle to build a secure application development lifecycle while considering the modern development practices.
Skills covered
Software Development SecurityPersonaCybersecurity
Concepts
0. Introduction
- 01 - Introduction
1. Security and Risk Overview
- 02 - The goals of secure coding
- 03 - Understand the attacker
- 04 - Threat modeling
- 05 - Understand your risks
- 06 - Break what you build
- 07 - Document what you understand
- 08 - Introduction to vulnerabilities
2. Web-Based Client Server Issues
- 09 - Input validation
- 10 - Communication channel
- 11 - Session management
3. Thick Application and Client Server Issues
- 12 - Error handling
- 13 - Logging and output
- 14 - Internal data management
- 15 - Configuration
- 16 - Database
- 17 - File and I O
- 18 - Memory management
- 19 - Dependencies
4. Embedded Device and IoT Issues
- 20 - Physical security
- 21 - Side channel
- 22 - Memory
- 23 - Software versioning
- 24 - Third-party components
5. Security and Cryptography Misuse Issues
- 25 - Authentication and password
- 26 - Authorization and access control
- 27 - Cryptography
6. Security in the SDLC
- 28 - Requirements
- 29 - Design
- 30 - Development
- 31 - Testing
- 32 - Deployment
- 33 - Operations
- 34 - Containerization concerns
- 35 - Best practices
7. Conclusion
- 36 - Next steps