К содержимому
learnspaceYOUR NEXT CHAPTER
ПРОСТРАНСТВО ОБУЧЕНИЯ
ГлавнаяКаталог курсовМоё обучениеCoursera

Знания без границ

Учитесь у лучших университетов и компаний мира.

Открыть Coursera
Интеграция
Пространство университета
Моё пространствоСтраница курса
↵
ЯЛичный кабинетСтудент
© 2026 LearnSpaceКаждый день — возможность узнать больше.Помощь
Fundamentals of Secure Software · LearnSpace
Назад в каталог
courseraIT и технологии

Fundamentals of Secure Software

Курс от Packt
Средний≈ 18.4 чАнглийский
О курсеНавыкиПрограммаПреподаватели

О курсе

Updated in May 2025. This course now features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. In today's digital world, software security is more critical than ever. This course provides a comprehensive understanding of secure software development, equipping you with the knowledge to identify vulnerabilities, implement security best practices, and mitigate risks. You'll explore essential security principles, the Software Development Life Cycle (SDLC), and key frameworks like OWASP, NIST, and CSA. Throughout the course, you’ll dive deep into secure coding practices, application security goals, and risk management strategies. You’ll gain hands-on experience with tools like WebGoat, Threat Dragon, and Microsoft Threat Model Tool. The course covers major security threats, including injection attacks, cryptographic failures, and insecure design, with demonstrations on how to mitigate these risks effectively. You'll also explore advanced topics such as DevSecOps, secure CI/CD pipelines, and supply chain security. The curriculum includes critical cloud security concepts, API protection, and vulnerability management techniques. Hands-on demos and real-world case studies ensure a practical, application-driven learning experience. This course is ideal for software developers, security engineers, and IT professionals looking to enhance their understanding of secure software development. A basic knowledge of programming and web application concepts is recommended, but no prior cybersecurity experience is required. Whether you're new to security or looking to deepen your expertise, this course will provide valuable insights into building resilient software.

Навыки, которые вы освоите

Application SecurityOpen Web Application Security Project (OWASP)Software Development Life CycleVulnerability ManagementCloud SecurityThreat ModelingPenetration TestingThreat ManagementSecurity TestingDevOpsCloud PlatformsEncryptionVulnerability ScanningSecure CodingCI/CDDevSecOpsCryptographySoftware DevelopmentConfiguration ManagementVulnerability Assessments

Программа курса

13 модулей · 124 учебных материалов

01Introduction to the Course6 материалов

Introduction to the Course

Introduction to Application SecurityВидеоFull Course ResourcesЧтениеApplication Security Terms and DefinitionsВидеоApplication Security GoalsВидео

Учитесь у экспертов

Packt - Course Instructors

Преподаватель курса

Fundamentals of Secure Software
В каталоге вашей программы

Инвестируйте в себя

Новые знания — в удобное для вас время.

Начать на Coursera

Обучение откроется на Coursera
в новой вкладке

Обучение на Coursera

≈ 18.4 ч

13 модулей

Язык: Английский

Субтитры: Казахский

Часть программы вашего университета
OWASP WebGoat DemoВидео
Introduction to the Course - AssessmentЗадание
02Understanding Secure SDLC9 материалов

Introduction to OWASP Top 10 and More Items

Application Security IntroductionВидеоTop 10sВидеоApplication Security Terms and DefinitionsВидеоApplication Security GoalsВидеоIntroduction to NISTВидеоIntroduction to CSAВидеоAPI SecurityВидеоUnderstanding Threat Modeling in Software SecurityDIALOGUEUnderstanding Secure SDLC - AssessmentЗадание
03 Defense in Depth8 материалов

Dive into the OWASP Top 10

Defense in DepthВидеоRoles and Terms in CybersecurityВидеоAPI SecurityВидеоContent Security Policy (CSP)ВидеоServer-Side Request Forgery - SSRFВидеоVulnerability ManagementВидеоUnderstanding 'Defense in Depth' Cybersecurity StrategyDIALOGUE Defense in Depth - AssessmentЗадание
04 Dive into the OWASP Top 1016 материалов

Defenses and Tools

Broken Access ControlВидеоBroken Access Control - DemoВидеоCryptographic FailuresВидеоInjectionВидеоInjection DemoВидеоInsecure DesignВидеоSecurity MisconfigurationВидеоVulnerable and Outdated ComponentsВидеоIdentification and Authentication FailuresВидеоIdentification Failures DemoВидеоSoftware and Data Integrity FailuresВидеоSecurity Logging and Monitoring FailuresВидеоCross-Site Scripting (XSS)ВидеоXSS DemoВидеоUnderstanding Broken Access ControlDIALOGUE Dive into the OWASP Top 10 - AssessmentЗадание
05Supply Chain Security8 материалов

Session Management

Introduction to Supply Chain SecurityВидеоSupply Chain DefensesВидеоSoftware Composition Analysis (SCA)ВидеоIntroducing SLSAВидеоSoftware Bill of Materials (SBOM)ВидеоDependency-Track and CycloneDXВидеоEnsuring Software Supply Chain SecurityDIALOGUESupply Chain Security - AssessmentЗадание
06Cloud and Container Security13 материалов

Risk Rating and Threat Modeling

Introduction to CloudВидеоCloud Security ConceptsВидеоAWS Security PillarВидеоAWS Identity and Access ManagementВидеоAWS Detection ControlsВидеоAWS InfrastructureВидеоAWS Data ProtectionВидеоAWS Incident ResponseВидеоAWS Application SecurityВидеоContainer SecurityВидеоAzure and GCPВидеоUnderstanding Cloud Computing and Shared ResponsibilityDIALOGUECloud and Container Security- AssessmentЗадание
07Session Management9 материалов

Encryption and Hashing

Introduction to Session ManagementВидеоWeb SessionsВидеоJSON Web Token (JWT)ВидеоJWT ExampleВидеоJSON Web Encryption (JWE)ВидеоOAuthВидеоOpenID & OpenID ConnectВидеоExploring Session ManagementDIALOGUESession Management - AssessmentЗадание
08Risk Rating and Basic Threat Modeling11 материалов

Frameworks and Process

Risk Rating IntroductionВидеоRisk Rating DemoВидеоSecurity ControlsВидеоIntroduction to Threat ModelingВидеоType of Threat ModelingВидеоIntroduction to Manual Threat ModelingВидеоPrepping for Microsoft Threat Model ToolВидеоMicrosoft Threat Model Tool DemoВидеоOWASP Threat Dragon DemoВидеоUsing Risk Rating MethodologiesDIALOGUERisk Rating and Basic Threat Modeling - AssessmentЗадание
09More Advanced Threat Modeling11 материалов

Security Scanning and Testing

Additional Methods of Threat ModelingВидеоUsing DREADВидеоUsing MITRE ATT&CKВидеоOther Advanced Threat Modeling TechniquesВидеоAttack TreesВидеоAttack Tree DemoВидеоContinuous Threat ModelingВидео Threagile DemoВидеоThreat Modeling the CloudВидеоExploring Threat ModelingDIALOGUEMore Advanced Threat Modeling - AssessmentЗадание
10Encryption and Hashing8 материалов

Conclusion

Encryption OverviewВидеоEncryption Use CasesВидео Hashing OverviewВидеоHashing DemoВидеоPublic Key Infrastructure (PKI)ВидеоPassword ManagementВидеоPassword DemoВидеоUnderstanding Symmetric and Asymmetric EncryptionDIALOGUE
11DevSecOps and Secure CICD10 материалов
DevOpsВидео DevSecOpsВидеоDevSecOps DesignВидеоDevSecOps CodeВидеоDevSecOps AnalysisВидеоDevSecOps BuildВидеоDevSecOps OperationsВидеоSecure CICDВидеоSecure CICD DemoВидеоUntitledDIALOGUE
12Security Scanning and Testing12 материалов
SAST (Static Application Security Testing)ВидеоCodeQL DemoВидеоDAST (Dynamic Application Security Testing)ВидеоNew VideoВидеоIAST (Interactive Application Security Testing)ВидеоASPM (Application Security Posture Management)ВидеоASPM DemoВидеоRASP (Runtime Application Self-Protection)ВидеоWAF (Web Application Firewall)Видео Penetration TestingВидеоFuzz TestingВидеоExploring Static Analysis and False PositivesDIALOGUE
13Conclusion3 материалов
ConclusionВидеоFull Course Practice AssessmentЗаданиеFull course assessmentЗадание