
In this course, Secure Ideas will walk attendees through the various items in the latest OWASP Top 10 and corresponding controls.
Course Length: 12 Hours
Includes a Certificate of Completion
Next scheduled date:
Notify me when available
Description
In this course, Secure Ideas will walk attendees through the various items in the latest OWASP Top 10 and corresponding controls.
Since 2003, OWASP has released the Top 10 Most Critical Web Application Security Risks list. It has been the basis of much development and consternation, but do you really understand what each of these issues and their corresponding controls mean? As a developer, do you know how to prevent these issues? As a security professional, do you truly know what they are and how to evaluate their effectiveness?
Students will leverage modern applications to explore how the vulnerabilities work and how to find them in their own applications. Check out our other Secure Ideas courses here.
Syllabus
Introduction
-
- What is the Top 10?
-
- Update Process
-
- Past Versions
-
- Why It Matters
-
- What is the Top 10?
OWASP Top 10
-
- A01:2021 – Broken Access Control
-
- A02:2021 – Cryptographic Failures
-
- A03:2021 – Injection
-
- A04:2021 – Insecure Design
-
- A05:2021 – Security Misconfiguration
-
- A06:2021 – Vulnerable and Outdated Components
-
- A07:2021 – Identification and Authentication Failures
-
- A08:2021 – Software and Data Integrity Failures
-
- A09:2021 – Security Logging and Monitoring Failures
-
- A10:2021 – Server-Side Request Forgery (SSRF)
-
- Summary of Proactive Controls
FAQ
Any developers and or security professionals with responsibilities related to application security, including both offensive and defensive roles
About the Instructor
Kevin Tackett
"Professionally Evil"Bio
Kevin Tackett is CEO of Secure Ideas, a consulting company dedicated to security testing and training. Kevin passionately advocates for cybersecurity through his work with Secure Ideas, as a global board member for OWASP and as a faculty member at IANS. During his over 30 years in the industry, Kevin acted as an instructor and author for the SANS institute.
Register for Upcoming
Practical OWASP TOP 10
On-Demand Kevin Tackett
Attention: This is not a phish!
Antisyphon Training accounts have moved to learning.antisyphontraining.com. Training purchases will now be directed to that site. You can trust us.
Related products
-
Bill McCauleyLive4 Hrs
Foundational Application Security Training
View Course -
Alissa TorresLiveOD16 Hrs
Advanced Endpoint Investigations
View Course -
Bryan StrandLiveOD4 Hrs
Blue Team Foundations with Atomic Controls
View Course -
Carrie RobertsLiveOD16 Hrs
PowerShell for InfoSec: What You Need to Know
View Course

