"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to Web Application Security
- Web security fundamentals
- Modern web architecture
- Application attack surface
- Common security threats
- Security principles
- Application security lifecycle
Module 2: Introduction to OWASP
- OWASP overview
- OWASP resources
- OWASP Top 10
- Application security guidance
- OWASP projects
- Security community resources
Module 3: Web Application Architecture
- Client-server architecture
- HTTP and HTTPS
- Requests and responses
- Cookies and sessions
- Web APIs
- Application components
Module 4: OWASP Top 10 Overview
- Major application risks
- Vulnerability categories
- Risk identification
- Security impact
- Risk prioritization
- Mitigation strategies
Module 5: Broken Access Control
- Access control fundamentals
- Authorization weaknesses
- Privilege boundaries
- Insecure direct object references
- Access validation
- Mitigation practices
Module 6: Cryptographic Failures
- Data protection
- Encryption fundamentals
- Data in transit
- Data at rest
- Key management
- Secure cryptographic practices
Module 7: Injection Vulnerabilities
- Injection concepts
- SQL injection
- Command injection
- Input handling
- Parameterized queries
- Prevention techniques
Module 8: Insecure Design
- Secure design principles
- Threat modeling
- Security requirements
- Trust boundaries
- Abuse cases
- Design reviews
Module 9: Security Misconfiguration
- Default configurations
- Unnecessary services
- Security headers
- Error handling
- Configuration management
- System hardening
Module 10: Vulnerable & Outdated Components
- Third-party components
- Dependency management
- Component inventory
- Vulnerability tracking
- Patch management
- Software supply chain awareness
Module 11: Authentication Failures
- Authentication fundamentals
- Password security
- Multi-Factor Authentication
- Session management
- Credential protection
- Authentication best practices
Module 12: Software & Data Integrity
- Software integrity
- Update mechanisms
- CI/CD security
- Dependency integrity
- Trusted sources
- Supply chain protection
Module 13: Security Logging & Monitoring
- Application logging
- Security events
- Monitoring
- Alerting
- Suspicious activity
- Incident visibility
Module 14: Server-Side Request Forgery
- SSRF concepts
- Request validation
- Trust boundaries
- Network restrictions
- Input validation
- Mitigation strategies
Module 15: Cross-Site Scripting
- XSS fundamentals
- Stored XSS
- Reflected XSS
- DOM-based XSS
- Output encoding
- Content Security Policy
Module 16: Cross-Site Request Forgery
- CSRF concepts
- Request authenticity
- Anti-CSRF tokens
- Cookie security
- SameSite controls
- Prevention practices
Module 17: API Security Fundamentals
- API architecture
- REST security
- API authentication
- Authorization
- Input validation
- Rate limiting
Module 18: Secure Coding Practices
- Input validation
- Output encoding
- Error handling
- Secure authentication
- Session protection
- Defensive programming
Module 19: Web Security Testing
- Testing methodology
- Application mapping
- Request analysis
- Vulnerability identification
- Finding validation
- Security documentation
Module 20: Application Vulnerability Management
- Vulnerability discovery
- Risk classification
- Prioritization
- Remediation planning
- Retesting
- Continuous improvement
Module 21: DevSecOps & Application Security
- Secure SDLC
- CI/CD security
- Static analysis
- Dynamic analysis
- Dependency scanning
- Security automation
Module 22: Practical Web Security Assessment
- Application assessment planning
- OWASP-based review
- Vulnerability analysis
- Risk evaluation
- Remediation recommendations
- Security improvement planning
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device
Course Overview
The OWASP Web Application Security program equips professionals with practical skills to assess and strengthen modern web applications. Learners explore OWASP Top 10 risks, secure authentication, access control, injection vulnerabilities, cryptographic failures, security misconfigurations, API security, secure coding, vulnerability assessment, and application security testing through practical scenarios.