EdX

Application Security for Developers (edX)

Offered by IBM,
Application Security for Developers (edX)

Learn to identify security vulnerabilities in applications and implement secure code practices to prevent events like data breaches and leaks. Become familiar with DevSecOps practices, and SAST for identifying security flaws.

Class Deals by MOOC List - Click here and see EdX's Active Discounts, Deals, and Promo Codes.

Vulnerabilities can occur at any stage of software development, making it critical for developers to write secure code and maintain a secured development environment and the platform it runs on. In this course, you will learn to identify security vulnerabilities in applications and implement secure code practices to prevent events like data breaches and leaks which can significantly impact an organization’s reputation and financial condition. This course provides a comprehensive overview of security best practices that developers should follow when developing applications. You’ll gain extensive knowledge on various practices, concepts, and processes for maintaining a secure environment, including DevSecOps practices that automate security integration across the software development lifecycle (SDLC), Static Application Security Testing (SAST) for identifying security flaws, Dynamic Analysis, and Dynamic Testing, and creating a Secure Development Environment, an ongoing process for securing a network, computing resources, and storage devices both on-premise and in the cloud. This course familiarizes you with the top Open Web Application Security Project (OWASP) application security risks such as broken access controls and SQL injections and teaches you how to prevent and mitigate these threats. This course includes multiple hands-on labs to develop and demonstrate your skills and knowledge for maintaining a secure development environment.
This course is part of the DevOps and Software Engineering Professional Certificate Professional Certificate.

What you'll learn

  • Demonstrate your knowledge of security testing procedures and describe how coding practices and other mitigation strategies help reduce risk.
  • Apply security concepts to various stages of the Software Development Lifecycle (SDLC).
  • Explain security by design, and develop applications using security by design principles.
  • Perform defensive coding that follow Open Web Application Security Project (OWASP) principles.

Syllabus

Module 1: Introduction to Security for Application Development
Security By Design
What is DevSecOps
Vulnerability Scanning and Threat Modeling
Threat Monitoring
Activity: Security Concepts and Terminology

Module 2: Security Testing and Mitigation Strategies
Intro to Security Testing and Mitigation Strategies
Static Analysis
Dynamic Analysis
Hands-on Lab: Using Static and Dynamic Analysis
Code Review
Vulnerability Analysis
Evaluating Vulnerability Analysis
Runtime Protection
Software Component Analysis
Hands-on Lab: Evaluate Software Component Analysis
Continuous Security Analysis

Module 3: OWASP
Intro to OWASP
OWASP Top 1-3
OWASP Top 4-6
OWASP Top 7-10
SQL Injections
Hands-on Lab: Understanding SQL Injections
Software and Data Integrity Failures: Cross Site Scripting
Hands-on Lab: Software and Data Integrity Failures: Cross Site Scripting
Storing Secrets Securely
Lab: Storing Secrets Securely
App ID

Module 4: Security Best Practices
Code Practices
Hands-on Lab: Code Practices
Dependencies
Hands-on Lab: Dependencies
Secure Development Environment
Hands-on Lab: Secure Development Environment

Module 5: Final Exam

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Side-Channel Security: Developing a Side-Channel Mindset (edX) EdX
Graz University of Technology,TUGrazX

Side-Channel Security: Developing a Side-Channel Mindset (edX)

Side channels are everywhere. They are incredibly powerful and have disrupted the world in the last years, especially with attacks like Meltdown and Spectre that impacted most computers on the planet. You also have seen side channels and used them already yourself. In this course, you will learn and practice the side-channel mindset and how to spot side channels in the real-world and how to use them in non-technical and semi-technical settings.

Self Paced
Self-Paced
Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX) EdX
Graz University of Technology,TUGrazX

Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX)

Fault attacks (sometimes also called active side-channel attacks ) are a very powerful means that goes beyond just leaking secrets from an application or device, to actively manipulating it. We will look at fault attacks that can be triggered from software, namely Rowhammer and Plundervolt. We will also learn that some transient-execution attacks have some similarities to fault attacks. You will implement some of these attacks yourself and learn how they are mitigated.

Self Paced
Self-Paced
Unlocking Information Security I: From Cryptography to Buffer Overflows (edX) EdX
Tel Aviv University,IsraelX,TAUx

Unlocking Information Security I: From Cryptography to Buffer Overflows (edX)

Learn how systems are hacked and defended. Information Security is everywhere: as the world becomes more and more digitized, so it becomes more and more hackable. Cyber attacks, data breaches, and even cyber warfare are all very real - so it is infinitely important to understand how hackers think and act, and how you can fight back.

Self Paced
Self-Paced
Beginners Guide to Cybersecurity (edX) EdX
IBM

Beginners Guide to Cybersecurity (edX)

This course is designed for beginners to build critical skills to address common security threats, and adopt best practices for reducing risks. A tech talent shortage continues as organizations adopt higher security standards to address the ongoing risk of threats and breaches. This course builds key skills to address common security threats and risks and provides best practices to guard against them.

Self Paced
Self-Paced
Introduction to Software Side Channels and Mitigations (edX) EdX
Graz University of Technology,TUGrazX

Introduction to Software Side Channels and Mitigations (edX)

Side channels exist in the real world, but they also exist in computers and can be exploited directly from software. This is a substantial computer security problem today, that we need to learn about to be able to stop attacks. In this course, you will learn and practice basic software-based side channels and understand the thought process to utilize a side channel. You will then learn how to mitigate or avoid side channels in software.

Self Paced
5-12 Weeks
Cybersecurity Fundamentals (edX) EdX
Rochester Institute of Technology,RITx

Cybersecurity Fundamentals (edX)

Learn cybersecurity fundamentals, including how to detect threats, protect systems and networks, and anticipate potential cyber attacks. In this introduction to the field of computing security, you will be given an extensive overview of the various branches of computing security. You will learn cybersecurity concepts, issues, and tools that are critical in solving problems in the computing security domain.

Aug 17th 2026
5-12 Weeks
Cloud Computing Security (edX) EdX
University System of Maryland - USM,USMx,University of Maryland Global Campus - UMGC,UMGC

Cloud Computing Security (edX)

Learn how to identify security issues in the cloud and industry-standard techniques and procedures to prevent and mitigate risks. How do you protect the critical data that is increasingly being stored in the cloud? Learn how to build a security strategy that keeps data safe and mitigates risk.

Mar 21st 2024
5-12 Weeks
DevOps Basics for Everyone (edX) EdX
IBM

DevOps Basics for Everyone (edX)

This course is intended to help launch your career as a DevOps Professional. In this course you will learn to think, work, organize and measure DevOps - skills that you can use to build better products. The DevOps Basics for Everyone course explores DevOps as a cultural movement. By thinking from a DevOps perspective, you will be able to build better products for your customer. This course provides views of DevOps from both a business perspective and as a DevOps engineer.

Self Paced
Self-Paced