Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Quick Guide to AppSec and the OWASP Top 10 2025
Rating: 4.3 out of 5(138 ratings)
2,112 students

Quick Guide to AppSec and the OWASP Top 10 2025

Quick guide to the OWASP Top Ten and Application Security
Created byDerek Fisher
Last updated 3/2026
English

What you'll learn

  • Awareness of what Application Security is and how it's used
  • Some historical context on Application Security
  • Basic terms used in AppSec
  • What a Secure SDLC and DevSecOps pipeline look like
  • Quick view of OWASP and the OWASP Top Ten Web App vulnerabilities

Course content

4 sections18 lectures2h 13m total length
  • Introduction7:52

    Welcome to "Quick Guide to AppSec and the OWASP Top Ten"! Join Derek Fisher, a seasoned product security leader, speaker, university instructor, and author of "The Application Security Program Handbook" as he takes you on a journey through the essentials of application security. We cover the foundational concepts like asset types, threats, and the pillars of cybersecurity: confidentiality, integrity, availability, authentication, and authorization (CIAAA). From real-world examples to best practices, this video dives into securing assets and understanding the critical components of application security. Follow along and learn more about protecting your digital assets. Ready to level up your AppSec knowledge? Let’s get started!

  • AppSec and the Secure SDLC9:54

    In this in-depth look at application security, we break down essential concepts and strategies to secure your applications from development to deployment. W cover the key elements of authentication, authorization, and session management, as well as data protection at rest, in use, and in motion. Learn about the importance of secure code reviews, threat modeling, risk assessments, and the integration of security in DevSecOps and CI/CD pipelines. Explore frameworks like OWASP and NIST and understand the power of defense in depth to protect your applications. Finally, discover how continuous feedback loops and testing at each development stage contribute to safer, more resilient applications.

Requirements

  • Some programming experience
  • Some familiarity with development practices
  • Some familiarity with cybersecurity

Description

Every company uses software to function. Whether they are a Fortune 500 technology company or a sole proprietor landscaping company, software is integral to businesses large and small. Software provides a means to track employees, customers, inventory, and scheduling. Data moves from a myriad of systems, networks, and software providing insights to businesses looking to stay competitive. Some of that software used is built within the organization or it is purchased and integrated. What this means is that every organization, regardless of size and industry, has a software need. It enables organizations to move quickly and stay ahead of their competition.

This is where organizations need your help to secure their applications!

In this quick guide to application security and the OWASP Top Ten we will cover what is in the Top Ten. We’ll cover what makes them vulnerabilities and how to protect your application from attacks using these vulnerabilities. Well talk about cryptographic failures, insecure configuration, how to maintain software integrity, what injection attacks are and more!You’ll learn about the terms and security goals that are used in an organization. You’ll learn about some of the basic ways that application security can be brought into the development lifecycle both from a traditional pipeline and from a DevSecOps perspective. I hope you enjoy this brief but key course on AppSec.

Who this course is for:

  • Software Developers
  • Software Architects
  • Quality Assurance Testers