Course Outline
Module 1: Introduction to Security in the Software Development Lifecycle (Secure SDLC) • Secure SDLC principles • Relationship with ISO 27001 and PCI DSS (Req. 6) • Roles and responsibilities in security management • Security from design to production
Module 2: Software Security by Function and Languages • Specific risks in financial environments • Common vulnerabilities in Java/Spring Boot • Security risks in PL/SQL and databases • Secure software design • Layered separation • Dependency control • Least privilege principles • Secure coding techniques • Input validation • Safe error and exception handling • Proper use of encryption
Module 3: The 3 A's – Authentication, Authorization and Approval • Concepts and differences • Secure implementation in transactional environments • Use of mTLS • OAuth2, JWT, JWE and JWS • Pros and cons of each approach in financial ecosystems
Module 4: Cryptography and Key Management • Basic principles of applied cryptography • Encryption standards • AES (GCM vs CBC) • Secure key management • Rotation • Storage • Protection in rest and transit • Common errors and how to avoid them
Module 5: OWASP Top 10 and OWASP API Security Top 10 • Introduction to the extended OWASP approach • Injection: • SQL • LDAP • XPath • XSS and CSRF • Broken access control • Broken authentication • Specific risks in APIs: • BOLA • Excessive data exposure • SSRF • Examples applied to APIs and microservices
Module 6: Security Incident Handling • Basic incident response cycle • Detection • Containment • Recovery • Reporting • Use of logs and traceability • Monitoring in APIs and microservices • Lessons learned and continuous improvement
Module 7: PCI DSS and ISO 27001 Compliance from Development • Impact of secure development on certifications • Required evidence: • Security testing • Vulnerability analysis • Change control • Relationship between development, audits and compliance
Module 8: Security Testing Tools • Introduction to: • SAST • DAST • SCA • Use of tools: • OWASP ZAP • SonarQube • OWASP Dependency-Check • Integration of security in CI/CD pipelines • Best practices for production environments
Requirements
Requirements • Basic knowledge of software development • Previous experience in at least one of the following: Java, PL/SQL, APIs or transactional systems • Advanced knowledge in security is not required
Target Audience • Software developers • Software architects • Integration and API engineers • Development teams in financial environments • Technical staff involved in Secure SDLC and regulatory compliance
Testimonials (1)
The training helped me expand my knowledge and understanding of Burp Suite. I also realized that what I had learned through self-study was still quite limited. This training was very helpful to me as a QA because Burp Suite is a valuable tool for performing security testing and improving the overall quality of application testing. I will continue exploring this tool and learning more about its features and capabilities.