К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Advanced Practices in Application Security · LearnSpace
Назад в каталог
courseraIT и технологии

Advanced Practices in Application Security

Курс от STARWEAVER
Средний≈ 8.8 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

As cyber threats grow in sophistication, organizations can no longer treat application security as an afterthought. This course equips software developers, cybersecurity professionals, and DevSecOps teams to embed security throughout the software development lifecycle (SDLC). You'll master practical, up-to-date application security best practices aligned with industry frameworks from NIST, OWASP, CISA, and CSA. Learn to integrate secure coding, threat modeling, and supply chain security from the ground up. Explore secure development practices using NIST's SSDF, adopt Secure by Design principles endorsed by over 100 leading software firms, and implement controls from OWASP and CSA's Cloud Controls Matrix. Gain hands-on experience with application security testing tools for static analysis, container security, SBOMs, and threat modeling methodologies like STRIDE. Through a comprehensive fictional case study, you'll apply these skills in real-world scenarios, from legacy integration to cloud-native deployments, preparing you to lead security-first development in any organization. Stay ahead of regulatory demands and design secure software from day one.

Навыки, которые вы освоите

Application SecurityOpen Web Application Security Project (OWASP)Cloud SecurityContinuous MonitoringSecurity TestingContainerizationDependency AnalysisSecure CodingCloud-Native ComputingThreat ModelingHybrid Cloud ComputingSoftware DevelopmentCI/CDSecurity ControlsApplication DevelopmentMulti-CloudIT Security ArchitectureSupply ChainCloud StandardsApplication Design

Программа курса

6 модулей · 64 учебных материалов

01Course Introduction 3 материалов
Welcome to the Course: Course OverviewЧтениеBoardroom Briefing: Ship the Release or Stop the Line?DIALOGUEIntro Video to Course Видео
02Secure Development and Code Security 15 материалов

Lesson 1: Building Security from the Ground Up

Учитесь у экспертов

Derek Fisher

Cybersecurity Leader & Educator | Higher Education Professor and Director | Author & Speaker | Mentoring the Next Generation

Starweaver

Global Leaders in Professional & Technology Education

Advanced Practices in Application Security
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 8.8 ч

6 модулей

Язык: Английский

Часть программы вашего университета
Module IntroductionВидео
Secure by Design PrinciplesВидео
Secure Coding Practices Видео
Secure Configuration and DefaultsВидео

Lesson 2: OWASP Top 10 Prevention

Prevention of OWASP Top 10 ВидеоStopping Insecure Design and Misconfiguration FailuresВидеоDefending Against Supply Chain Attacks and Logging FailuresВидеоOWASP Top 10 Vulnerability Analysis and Prevention Strategy Обсуждение

Lesson 3: Application Security Testing and Protection

Code Testing for Vulnerabilities ВидеоTesting an Application for Run-Time Vulnerabilities ВидеоRun-Time Protection ВидеоImplementing Proactive Security Transformation in Development TeamsОбсуждениеFoundations Section of the OWASP Developer GuideЧтениеHands-On-Learning: Secure Coding Practices: Identifying and Fixing Vulnerable Code in GitHub CodespacesВзаимная проверкаSecure Development and Code Security Задание
03Threat Modeling Best Practices 14 материалов

Lesson 1: Threat Modeling

Intro Video to Module ВидеоThreats vs Risks ВидеоIntro to Threat Modelling ВидеоUtilizing STRIDE For Threat Modelling Видео

Lesson 2: Utilizing Threat Modeling Tools

Threat Modelling with OWASP Threat DragonВидеоUsing Attack Trees in Threat Modelling ВидеоCompleting a Rapid Threat Modeling Prototyping (RTMP) Видео

Lesson 3: Managing Findings from Threat Modeling

Risk Rating Using OWASP Risk RatingВидеоCVSS Scoring for Vulnerability ManagementВидеоTransforming Threats into Secure DesignsВидеоThreat Prioritization and Mitigation Strategy DevelopmentОбсуждениеNIST Threat Modeling Guidelines ЧтениеHands-On-Learning: Attack Path Modeling: Creating Attack Trees with Deciduous Взаимная проверка
04Supply Chain Security 15 материалов

Lesson 1: Understanding the Software Supply Chain

Intro Video to Module ВидеоSoftware Supply Chain Threat Landscape ВидеоSoftware Bill of Materials (SBOM) FundamentalsВидеоDependency Management and Open-Source Risk Assessment ВидеоOpen-Source Component Evaluation and Strategic Dependency ManagementОбсуждение

Lesson 2: Collecting Artifacts and Understanding Risk

SLSA Framework and Build Provenance ВидеоArtifact Integrity and Code Signing ВидеоVendor Risk Assessment and Third-Party Security Видео

Lesson 3: Managing and Monitoring the Supply Chain

Continuous Supply Chain MonitoringВидеоImplementing Continuous Supply Chain Monitoring StrategyОбсуждениеCompliance and Regulatory Requirements ВидеоSupply Chain Incident Response and Recovery ВидеоSecuring the Software Supply Chain ЧтениеHands-On-Learning: Software Supply Chain Security: SBOM Generation and Vulnerability Analysis with Syft and Grype Взаимная проверка
05Cloud Security and Container Security 15 материалов

Lesson 1: Understanding Cloud and Container Fundamentals

Intro Video to Module ВидеоCloud-Native Security Fundamental ВидеоContainer and Serverless Security ВидеоCloud Security Automation and Infrastructure as Code (IaC) Security Видео

Lesson 2: Understanding Container Security Practices

Kubernetes Security Architecture and RBAC ВидеоContainer and Registry Security ВидеоRuntime Protection and Behavioral Monitoring ВидеоContainer Runtime Security Monitoring and Threat DetectionОбсуждение

Lesson 3: Understanding Cloud Security Defenses

Network Security and Micro-Segmentation ВидеоSecrets Management and Data Protection ВидеоCompliance and Governance in Cloud-Native Environments ВидеоCCM v4.0 Implementation GuidelinesЧтениеCloud Migration Security Strategy and MonitoringОбсуждениеHands-On-Learning: Cloud-Native Security: Container Vulnerability Scanning and Security Reporting with Trivy Взаимная проверка
06Course Conclusion 2 материалов
Course Wrap-up Video ВидеоProject: Comprehensive Application Security Assessment: From Code to Container Взаимная проверка
Threat Modeling Best Practices Задание
Supply Chain Security Задание
Cloud Security and Container Security Задание