Secure SDLC & Application Security Governance
Move security upstream and make it a governed part of how you ship software.
Tuition
$449
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
4.8 hours
Estimated time
What you will be able to do
- You will be able to explain the secure SDLC and identify concrete shift-left opportunities across each phase.
- You will be able to run a structured threat model using a method like STRIDE and a data flow diagram.
- You will be able to map common weaknesses to the OWASP Top 10 and recommend secure design controls.
- You will be able to place SAST, DAST, and SCA correctly in a CI/CD pipeline and tune them to reduce noise.
- You will be able to design release gates and express security policy as code rather than as manual checklists.
- You will be able to triage, prioritize, and track application vulnerabilities using severity and risk context.
- You will be able to define governance metrics and SLAs that show whether the AppSec program is actually working.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The Secure SDLC and Shift-Left
Understand what a secure software development lifecycle is and why moving security earlier reduces cost and risk. This module frames the lifecycle phases and the shift-left mindset that the rest of the course builds on.
2 lessons · 5 quiz questions
- 02
Threat Modeling and Secure Design
Learn to anticipate how a system can be attacked and to design defenses before code is written. This module covers structured threat modeling with STRIDE and the secure design controls behind the OWASP Top 10.
2 lessons · 5 quiz questions · assignment
- 03
Security Tooling in the CI/CD Pipeline
Learn what SAST, DAST, and SCA actually do, their strengths and blind spots, and where each belongs in a CI/CD pipeline. This module focuses on integrating tooling so it produces trusted, actionable signal.
2 lessons · 5 quiz questions
- 04
Governance, Gates, and Application Risk
Turn scattered security activities into a governed program with explicit gates, policy as code, and disciplined vulnerability management. This module connects AppSec to risk decisions and measurable outcomes.
2 lessons · 5 quiz questions · assignment