Skip to content

Secure Development and Application Security

Developers, testers and technical leads who build or review web applications and APIs. You should be able to read code in at least one web language.

Track
Cybersecurity
Level
Intermediate
Duration
6 days, or 12 half-day sessions
Formats
Instructor-led cohort · In-house for your team · Online, live

What you will be able to do

  • Recognise the vulnerabilities in the OWASP Top 10 and the OWASP API Security Top 10 in real code.
  • Fix common flaws such as injection, broken access control and insecure authentication.
  • Model the threats to a new feature before it is built, and agree what controls it needs.
  • Handle secrets, sessions, tokens and personal data safely in web applications and APIs.
  • Add security checks to the delivery pipeline, from dependency scanning to automated scans.
  • Review code and test applications for security problems, and report them so they get fixed.

Security is cheaper when it is built in

A vulnerability found in design costs a conversation. The same vulnerability found after launch can cost customer data, money and trust, especially in banking, payments and any system that holds personal data.

This course teaches developers and testers to find and fix security problems while the code is still being written.

How it is taught

You work on a deliberately vulnerable sample application with a web front end and a REST API, modelled on the kind of systems built across the region: customer portals, payment callbacks and back-office tools. You attack it in a lab, fix what you find, and add checks to its pipeline so the same flaws do not come back.

Examples are in common web languages, and the techniques apply to any stack. If you are new to security, start with Cybersecurity Fundamentals.

Syllabus

  1. Module 1

    Why applications get breached

    • How attackers approach a web application or API
    • The OWASP Top 10, with examples from real incidents
    • Security as part of the delivery life cycle
  2. Module 2

    Threat modelling

    • Data flow diagrams and trust boundaries
    • Identifying threats with STRIDE
    • Turning threats into requirements and tests
  3. Module 3

    Injection and input handling

    • SQL, command and template injection
    • Cross-site scripting and output encoding
    • Validating input and handling file uploads safely
  4. Module 4

    Authentication, sessions and access control

    • Password storage, multi-factor authentication and account recovery
    • Sessions, JSON Web Tokens and OAuth 2.0 in practice
    • Broken access control and how to test for it
  5. Module 5

    API security

    • The OWASP API Security Top 10
    • Rate limiting, input schemas and API gateways
    • Securing payment callbacks and webhooks
  6. Module 6

    Secrets, data and dependencies

    • Keeping keys and passwords out of code
    • Encryption in transit and at rest
    • Personal data and the Kenya Data Protection Act 2019 for developers
    • Vulnerable dependencies and the software supply chain
  7. Module 7

    Security testing in the pipeline

    • Static analysis and dependency scanning
    • Dynamic scanning with OWASP ZAP
    • Security code review checklists
  8. Module 8

    Handling vulnerabilities

    • Rating severity and prioritising fixes
    • Writing findings developers can act on
    • Logging and monitoring for application attacks

Assessment and certificate

Assessment
A practical assessment: you find and fix vulnerabilities in a sample application and its API, write a short threat model for a new feature, and report your findings to an assessor.
Certificate
Deefrent Academy certificate, awarded on passing the course assessment.
Dates and fees
Ask for dates and fees. Tell us the course and the format you prefer, and we reply with the next dates and the fee.

Training a whole team?

This course can run privately for your organisation, at your premises or online, with examples drawn from your own systems.

Ready to join the next cohort?

Tell us how you would like to attend. We reply with the next dates, the fee and what you need before you start.