
Discover secure software implementation across an eight-course series, guiding developers, architects, and IT professionals to address SDLC issues, vulnerabilities, security controls, and secure build pipelines.
Meet a 25-plus year IT veteran and government security expert, now CFO of tech Commanders, author, and US Navy veteran, guiding you into software development with storage networking.
Learn the fundamentals of software development lifecycle and IT security best practices, with no prerequisites, and practice what you learn to succeed in completing the series.
Learn how secure software implementation fits into the deployment phase of the SDLC, with testing, onboarding, installation, and a feedback loop guiding rolling out new software.
Identify and mitigate common software vulnerabilities, including injection flaws, broken authentication, and broken cryptography. Protect keys, passwords, and tokens while addressing session management, authorization, misconfigurations, and vulnerable components.
Explore security controls for input validation, decoding and canonicalization, hashing, encryption, tokenization, and centralized exception handling to prevent injections and tampering.
Enforce input validation with allow and deny lists, decoding once and canonicalizing inputs before validation, and strengthen security with hashing, encryption, tokenization, and centralized exception handling, logging, and sandboxing.
Learn to select and classify build system security controls using cost-benefit analysis, frameworks and audits, covering technical, operational, administrative, and management controls.
Secure build pipelines by protecting repositories, enforcing governance, and automating vulnerability scanning across ci/cd stages, with private networks, access controls, and configuration management.
Review key points on encryption, input validation approaches (exact match, allow list, deny list), injection vulnerabilities like SQL injection, misconfigurations, and security controls such as password salting.
Course review questions cover injection vulnerabilities like cross-site scripting and unsafe deserialization, clarify that backdoor is not a security misconfiguration, and discuss server-side request forgery and security control families.
Explore the resources and programs, including tech commanders, gcp gurus, a GitHub repository, and cloud interview ace. Reach out for assistance to become a cloud engineer or developer.
Course Overview
In this course series we cover what secure software design means and why software can meet all quality requirements and still be insecure.
Please note that this course provides introductory concepts for beginners and is NOT a programming course or has any hands-on.
This course, specifically Secure Software Implementation, is designed to provide learners with a foundational start in software design that focuses on software security, SDLC, and IT Security Fundamentals.
The course covers essential aspects of Secure Software Implementation, Common Software Vulnerabilities, and Security Controls.
The course continues on to cover Implementing Security Controls and Securing Build Systems to name a few lessons.
The course provides some review questions and a summary review.
Lastly, the 8-course series cov.ers approximately 65% or more of the exam objectives for the CSSLP exam upon completion of all eight courses.
There are many benefits of designing security early with your software build,s which we cover in this course.
This is a series of courses for learning about "Secure Software Development Fundamentals."
Course 1 - Secure Software Concepts
Course 2 - Secure Software Requirements
Course 3 - Secure Software Design
Course 4 - Defining Security Implementations
Course 5 - Secure Software Testing
Course 6 - Secure Software Acceptance
Course 7 - Software Deployment, Operations and Maintenance
Course 8 - Supply Chain and Software Acquisition
Who should take this course (Target Audience)?
You are a developer or software engineer and want to understand
You want to learn IT security fundamentals focused on software development
What are the Couse Pre Requirements?
There are no course pre-requirement
What You'll Learn
What are the critical aspects of secure development?
What is the CIA Triad, AAA, and other security fundamentals
Identify the correct software build requirements needed for a secure software program
Determine how to specify the proper software architecture to meet your software security requirements
Understand what the commonly accepted best practices are for software acceptance
Determine the proper software acquisition and supply chain requirements for your software programs
Learn the proper software testing procedure for developing a secure software program.
Requirements
No Requirements
Course Contents
Course Overview, Instructor Intro, Course Prereqs
Main Modules: Secure Software Implementation, Common Software Vulnerabilities, Security Controls, Implementing Security Controls. Securing Build Systems
Review Questions
Course Closeout