Principles of Secure Development in Practice and Methods for Ensuring Information Security (PBV)

Cybersecurity, ICT Security

Designed for junior and experienced developers, this course strengthens application security and reduces the chance of successful cyberattacks. You will learn to detect and fix common threats like XSS, CSRF and SQL Injection, perform risk analysis and run practical exercises to test defenses.

The course covers modern auth standards, correct use of OAuth2 and OpenID Connect and how to assess their risks. You will use automated detection with OWASP tools, learn practical handling of certificates and study the effects of quantum computing on cryptography and automation.

THIS TRAINING COURSE WILL HELP YOU:

  • Identify potential security threats to your application
  • Understand consequences of a successful compromise
  • Find weaknesses in your source code and assess related risks
  • Prevent vulnerabilities in code and reduce associated risks
  • Use tools to detect vulnerabilities in source code

WHO SHOULD ATTEND?

  • Junior developers building publicly accessible applications
  • Senior developers responsible for secure coding
  • Developers of web and API services exposed to the internet

COURSE LOCATION AND AVAILABLE DATES

Contact us

Public courses are usually delivered in Czech, but this course is also available in English. We can arrange private training for your team online, at your premises or in our classrooms, and tailor the content to your needs.

For groups of around 4 or more participants, private training can already be comparable in price to booking individual places on a public course. Send us your requirements and we’ll recommend the best format and provide an exact quote.

Request training in English

Course content:

Hide details
  • Introduction to application security
    1. Introduction to core application security concepts and risk mitigation methodologies
    2. Overview of possible attack vectors
    3. OWASP categorization and vulnerability analysis as part of security assessments
  • Authentication and authorization of users to applications
    1. Overview of current protocols (OAuth2, OpenID Connect, …) and security analysis
    2. Attacks on authentication protocols and analysis of associated risks
  • Workshop and practical exercises focused on risk analysis and security methodologies
    1. Demonstration of XSS, CSRF and SQL Injection attacks
    2. Practical execution of attacks
    3. Evaluation of attacks and prevention measures
  • Working with certificates
    1. Role of certificates in software development
    2. Explanation of certificate principles
    3. Practical demonstration of securing systems using certificates
  • Automated vulnerability detection using OWASP
    1. Demonstration of tools for vulnerability detection
    2. Processing and interpreting output from code analysis
  • Near future of security
    1. Increasing need to secure all devices
    2. Automation of infrastructure management
    3. Consequences of quantum computers for communication security
Prerequisites:
Basic programming experience and access to a development environment.
Schedule:
2 days (9:00-17:00)
Price per person:
552.00 € ( 667.92 € incl. 21% VAT)

Training and learning environment