К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Designing Secure Applications Using the OWASP Top 10 · LearnSpace
Назад в каталог
courseraIT и технологии

Designing Secure Applications Using the OWASP Top 10

Курс от Packt
Средний≈ 18.8 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Modern applications operate in increasingly complex environments where cloud-native architectures, APIs, microservices, software supply chains, and distributed identities introduce new security challenges. In this course, you will learn how to design secure applications by applying the principles behind the OWASP Top 10, the world's most recognized framework for application security risks. Rather than focusing solely on vulnerability remediation, you will develop a security-first architectural mindset that helps prevent weaknesses before they emerge. You will begin by exploring how the application threat landscape has evolved, understanding attacker economics, breach lifecycles, and the methodology OWASP uses to identify and rank risks. From there, you will examine the foundations of secure architecture and discover how design decisions directly influence security outcomes across modern systems and platforms. As the course progresses, you will perform a deep analysis of each OWASP Top 10 category, including Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, Vulnerable Components, Authentication Failures, Software Integrity Risks, Logging and Monitoring Failures, and SSRF. Through architecture-focused discussions, real-world breach case studies, secure-by-design patterns, and hands-on labs, you will learn practical strategies for preventing and mitigating these risks in enterprise environments. This course is designed for software developers, software architects, DevSecOps engineers, cybersecurity professionals, cloud engineers, technical leaders, and IT practitioners who want to strengthen application security expertise. A basic understanding of software development, web applications, networking, and cloud concepts is recommended. The course is suitable for learners at an intermediate level seeking to bridge security theory and secure system design. By the end of the course, you will be able to evaluate application architectures through the lens of the OWASP Top 10, identify and analyze modern security risks, design secure-by-default systems, implement effective mitigation strategies, assess software supply chain and identity-related threats, operationalize application security programs, and integrate security principles into enterprise technology decisions.

Навыки, которые вы освоите

Application SecurityOpen Web Application Security Project (OWASP)Secure CodingCloud SecurityHardeningInfrastructure SecurityCryptographyApplication DesignIT Security ArchitectureCryptographic ProtocolsData AccessRisk ManagementSecurity Architecture ReviewDevSecOpsAuthenticationsSecurity ControlsSupply ChainThreat ModelingVulnerability AssessmentsRisk Analysis

Программа курса

17 модулей · 120 учебных материалов

01The Course Intro1 материалов

The Course Intro

Introduction: Welcome, Orientation & the OWASP CommunityВидео
02Module 1 — The Evolution of Modern Application Risk4 материалов

Module 1 — The Evolution of Modern Application Risk

The Shifting Risk Landscape (2010 → 2025)ВидеоUnderstanding Attacker EconomicsВидеоThe Breach LifecycleВидео

Учитесь у экспертов

Packt - Course Instructors

Преподаватель курса

Designing Secure Applications Using the OWASP Top 10
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 18.8 ч

17 модулей

Язык: Английский

Часть программы вашего университета
Module 1 — The Evolution of Modern Application Risk - AssessmentЗадание
03Module 2 — How OWASP Builds the Top Ten5 материалов

Module 2 — How OWASP Builds the Top Ten

Data Sources and WeightingВидео2025 Methodology ImprovementsВидеоWhy Certain Categories Moved Up or DownВидеоLimitations of the OWASP Ranking ModelВидеоModule 2 — How OWASP Builds the Top Ten - AssessmentЗадание
04Module 3 — Security Architecture Fundamentals for the OWASP Era4 материалов

Module 3 — Security Architecture Fundamentals for the OWASP Era

Macro System Patterns: How Architecture Shapes SecurityВидеоCore Pillars of Modern Security DesignВидеоHow Architecture Influences OWASP RisksВидеоModule 3 — Security Architecture Fundamentals for the OWASP Era - AssessmentЗадание
05Module 4 — A01 Broken Access Control9 материалов

Module 4 — A01 Broken Access Control

The 12 Types of Access Control FailuresВидеоHow Access Control Breaks in Modern SystemsВидеоArchitectural Anti-PatternsВидеоBusiness Impact ModelВидеоHow Access Control Breaks in Modern Systems – Part 2ВидеоArchitectural Anti-Patterns – How Teams Accidentally Break Access ControlВидеоDeep Case Study NarrativesВидеоSecure-by-Design PatternsВидеоModule 4 — A01 Broken Access Control - AssessmentЗадание
06Module 5 — A02 Cryptographic Failures6 материалов

Module 5 — A02 Cryptographic Failures

Crypto LifecycleВидеоSubtle Failure ModesВидеоCloud-Native Crypto FailuresВидеоCase StudiesВидеоSecure PatternsВидеоModule 5 — A02 Cryptographic FailuresЗадание
07Module 6 — A03 Injection6 материалов

Module 6 — A03 Injection

The 8 Injection Classes (Beyond SQL)ВидеоInjection in Serverless & MicroservicesВидеоAPI-Specific Injection PatternsВидеоCase StudiesВидеоSecure PatternsВидеоModule 6 — A03 Injection - AssessmentЗадание
08Module 7 — A04 Insecure Design7 материалов

Module 7 — A04 Insecure Design

Architecture DebtВидеоAbuse Case ModelingВидеоBusiness Logic FlawsВидеоCognitive Biases in DesignВидеоDeep Case StudiesВидеоSecure PatternsВидеоModule 7 — A04 Insecure Design - AssessmentЗадание
09Module 8 — A05 Security Misconfiguration6 материалов

Module 8 — A05 Security Misconfiguration

Misconfiguration in Multi-CloudВидеоContainer-Level MisconfigurationВидеоFeature Toggles as Configuration RiskВидеоInfrastructure DriftВидеоBusiness ImpactВидеоModule 8 — A05 Security Misconfiguration - AssessmentЗадание
10Module 9 — A06 Vulnerable and Outdated Components13 материалов

Module 9 — A06 Vulnerable and Outdated Components

Supply Chain Risk ModelВидеоThe 7 Modes of Component ExposureВидеоSBOM AnalysisВидеоPredictive Vulnerability ManagementВидеоCase Studies (Log4Shell & Dependency Confusion)ВидеоIntegrity Assurance & Artifact ProvenanceВидеоTrust Boundary Collapse in Modern Supply ChainsВидеоMalicious Maintainers & Governance RiskВидеоTransitive Dependency CollapseВидеоAI Supply Chain RisksВидеоSaaS & Third-Party Service Dependency RisksВидеоOperationalizing Supply Chain SecurityВидеоModule 9 — A06 Vulnerable and Outdated Components - AssessmentЗадание
11Module 10 — A07 Identification & Authentication Failures12 материалов

Module 10 — A07 Identification & Authentication Failures

Authentication Architecture in Modern SystemsВидеоThe 12 Failure Modes of AuthenticationВидеоThe New Identity Attack SurfaceВидеоPasswordless Authentication PitfallsВидеоAPI Authentication & Service-to-Service IdentityВидеоCookie, Token & Session Handling FailuresВидеоAdvanced Attacker TechniquesВидеоAuthentication in Mobile & Desktop AppsВидеоCloud & Multi-Tenant Identity FailuresВидеоCase StudiesВидеоSecure-by-Design PatternsВидеоModule 10 — A07 Identification & Authentication Failures - AssessmentЗадание
12Module 11 — A08 Software & Data Integrity Failures12 материалов

Module 11 — A08 Software & Data Integrity Failures

Understanding Software Integrity in Distributed SystemsВидеоWhere Integrity Breaks in Real SystemsВидеоSupply Chain Integrity vs. Component VulnerabilityВидеоIntegrity Attacks in CI/CD PipelinesВидеоConfiguration Integrity FailuresВидеоData Integrity Failures in Distributed AppsВидеоThird-Party Service Integrity RisksВидеоReal-World Case StudiesВидеоSecure-by-Design Patterns for IntegrityВидеоRuntime Integrity Monitoring & Detection PatternsВидеоOrganizational Controls for IntegrityВидеоModule 11 — A08 Software & Data Integrity Failures - AssessmentЗадание
13Module 12 — A09 Security Logging & Monitoring Failures7 материалов

Module 12 — A09 Security Logging & Monitoring Failures

Why Logging & Monitoring Fail in Modern SystemsВидеоArchitectural Logging Gaps in Cloud & MicroservicesВидеоLog Integrity & Anti-TamperingВидеоDetection Engineering EssentialsВидеоCase Studies: Breaches Made Worse by Missing LogsВидеоSecure Logging & Monitoring PatternsВидеоModule 12 — A09 Security Logging & Monitoring Failures - AssessmentЗадание
14Module 13 — A10 SSRF6 материалов

Module 13 — A10 SSRF

What SSRF Really Is in Modern SystemsВидеоWhere SSRF Hides in Cloud & MicroservicesВидеоHow Attackers Exploit SSRFВидеоHigh-Impact SSRF Case StudiesВидеоSecure-by-Design Patterns Against SSRFВидеоModule 13 — A10 SSRF - AssessmentЗадание
15Module 14 — The Enterprise & Leadership Integration8 материалов

Module 14 — The Enterprise & Leadership Integration

Making OWASP Operational: Turning Risks Into Enterprise ControlsВидеоMapping OWASP to Major Security StandardsВидеоDesigning a Modern AppSec Program (2025+)ВидеоDeveloper Security ChampionsВидеоExecutive Communication & Risk TranslationВидеоBuilding a Sustainable Security RoadmapВидеоCapstone ReflectionВидеоModule 14 — The Enterprise & Leadership Integration - AssessmentЗадание
16All Labs for OWASP Top 1011 материалов

All Labs for OWASP Top 10

A1 Command Injection – OWASP Top 10ВидеоA2 Broken Authentication – OWASP Top 10ВидеоA3 Sensitive Information Disclosure – OWASP Top 10ВидеоA4 XML External Entity Injection (XXE)ВидеоA5 Broken Access Control – OWASP Top 10ВидеоA6 Security Misconfiguration – OWASP Top 10ВидеоA7 Cross-Site Scripting (XSS)ВидеоA8 Insecure Deserialized ObjectsВидеоA9 Using Components With Known VulnerabilitiesВидеоA10 Unvalidated Redirects and ForwardsВидеоAll Labs for OWASP Top 10 - AssessmentЗадание
17Course Conclusion3 материалов

Course Conclusion

Course ConclusionВидеоFull Course Practice AssessmentЗаданиеFull Course AssessmentЗадание