logo-img
CASE Java - Certified Application Security Engineer

CASE Java - Certified Application Security Engineer

3 days Self study Engels
Klassikaal Classroom

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

Software and application security have lagged behind in many organizations while 75% of all cyberattacks are aimed at web applications. The number of attacks on them is growing annually, while there is often little attention to security in preliminary training and requirements. A low price, often achieved through partial duplication, is considered more important, and security - if it is even considered - only comes into play just before delivery. Because the costs of making changes at this stage are many times higher than earlier in the process, risks are accepted or only minimized.

According to the 'State of Software Security Report 2017' from CA Veracode, nearly 90% of Java applications contain one or more vulnerable components, making them an ideal entry point for malicious hackers. There is therefore a high demand for Java developers with security knowledge, both in developing a new program and in upgrading an existing application.

The Certified Application Security Engineer (CASE) training covers both theoretical and hands-on various security skills and knowledge required in the different phases of a typical software development life cycle (SDLC). Because a secure application is more than just secure coding, CASE goes beyond just providing secure coding guidelines. This includes topics such as drafting security requirements (SAMM, BSIMM, OpenSAMM), threat modeling (Stride model), secure application design, and dealing with security issues in post-development phases. The training includes a comprehensive number of labs that correspond to current reality. 

CASE has been developed with the help of international application and software developers and aligns with the NICE 2.0 Framework (Securely Provision Category). 

For .NET developers, TSTC also offers a .NET variant of this training: CASE .NET

 

Certification

Following the training, you can take the 'Certified Application Security Engineer' exam, allowing you to obtain the corresponding internationally recognized title.

Training Requirements

  • Java ontwikkelaars met minimaal 2 jaar ervaring, professionals die zich willen ontwikkelen in de richting van application security engineer, application security analyst of application security tester. Professionals die betrokken zijn bij het ontwikkelen, testen, beheren of beveiligen van Java applicaties.

Training Content

Understanding Application Security, Threats, and Attacks

Security Requirements Gathering

Secure Application Design and Architecture

Secure Coding Practices for Input Validation

Secure Coding Practices for Authentication and Authorization

Secure Coding Practices for Cryptography

Secure Coding Practices for Session Management

Secure Coding Practices for Error Handling

Static and Dynamic Application Security Testing (SAST & DAST)

Secure Deployment and Maintenance

Description

Software and application security have lagged behind in many organizations while 75% of all cyberattacks are aimed at web applications. The number of attacks on them is growing annually, while there is often little attention to security in preliminary training and requirements. A low price, often achieved through partial duplication, is considered more important, and security - if it is even considered - only comes into play just before delivery. Because the costs of making changes at this stage are many times higher than earlier in the process, risks are accepted or only minimized.

According to the 'State of Software Security Report 2017' from CA Veracode, nearly 90% of Java applications contain one or more vulnerable components, making them an ideal entry point for malicious hackers. There is therefore a high demand for Java developers with security knowledge, both in developing a new program and in upgrading an existing application.

The Certified Application Security Engineer (CASE) training covers both theoretical and hands-on various security skills and knowledge required in the different phases of a typical software development life cycle (SDLC). Because a secure application is more than just secure coding, CASE goes beyond just providing secure coding guidelines. This includes topics such as drafting security requirements (SAMM, BSIMM, OpenSAMM), threat modeling (Stride model), secure application design, and dealing with security issues in post-development phases. The training includes a comprehensive number of labs that correspond to current reality. 

CASE has been developed with the help of international application and software developers and aligns with the NICE 2.0 Framework (Securely Provision Category). 

For .NET developers, TSTC also offers a .NET variant of this training: CASE .NET

 

Certification

Following the training, you can take the 'Certified Application Security Engineer' exam, allowing you to obtain the corresponding internationally recognized title.

Training Requirements

  • Java ontwikkelaars met minimaal 2 jaar ervaring, professionals die zich willen ontwikkelen in de richting van application security engineer, application security analyst of application security tester. Professionals die betrokken zijn bij het ontwikkelen, testen, beheren of beveiligen van Java applicaties.

Training Content

Understanding Application Security, Threats, and Attacks

Security Requirements Gathering

Secure Application Design and Architecture

Secure Coding Practices for Input Validation

Secure Coding Practices for Authentication and Authorization

Secure Coding Practices for Cryptography

Secure Coding Practices for Session Management

Secure Coding Practices for Error Handling

Static and Dynamic Application Security Testing (SAST & DAST)

Secure Deployment and Maintenance

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The CASE Java - Certified Application Security Engineer?

  • In-depth knowledge of a secure Software Development Lifecycle (SDLC) and secure SDLC models.
  • Define and enforce best practices for application security.
  • Stimulating the development of a holistic application security program
  • Apply and execute application security scanning technologies such as AppScan, Fortify, WebInspect, static application security testing (SAST), dynamic application security testing (DAST), single sign-on, and encryption.
  • Knowledge of the OWASP Top 10, threat modeling, static application security testing (SAST), and dynamic application security testing.
  • Perform manual and automated code reviews (=overall inspection of the source code for vulnerabilities) on an application.
  • Assess the severity of errors and publish comprehensive reports detailing the associated risks and mitigations.
  • Create a software source code review process that is part of the development cycles (SDLC, Agile, CI / CD)
  • Documenting the security requirements of an application in development
  • Perform application security testing on web applications to assess them for vulnerabilities.
  • Working in teams to improve the security posture

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Klassikaal Classroom
Date: Elk moment te starten

Price:

Do you prefer to follow the training in person or Live Online? This is possible! With in-person participation, you attend classes at our location in Veenendaal in a small group. You can ask questions, actively participate in discussions, and share experiences with fellow participants. Our experienced trainers provide clear explanations, Dutch local context, and practical examples that relate to your work situation.

Live Online training, unlike eLearning, also offers the opportunity for interaction, but online. You save travel time while still benefiting from contact with a trainer, live explanations, and remote guidance.

1

Applicant Information

2

Billing Information

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino