Skip to main content
Course

Secure SDLC & Application Security Governance

Move security upstream and make it a governed part of how you ship software.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

4.8 hours

Estimated time

What you will be able to do

  • You will be able to explain the secure SDLC and identify concrete shift-left opportunities across each phase.
  • You will be able to run a structured threat model using a method like STRIDE and a data flow diagram.
  • You will be able to map common weaknesses to the OWASP Top 10 and recommend secure design controls.
  • You will be able to place SAST, DAST, and SCA correctly in a CI/CD pipeline and tune them to reduce noise.
  • You will be able to design release gates and express security policy as code rather than as manual checklists.
  • You will be able to triage, prioritize, and track application vulnerabilities using severity and risk context.
  • You will be able to define governance metrics and SLAs that show whether the AppSec program is actually working.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    The Secure SDLC and Shift-Left

    Understand what a secure software development lifecycle is and why moving security earlier reduces cost and risk. This module frames the lifecycle phases and the shift-left mindset that the rest of the course builds on.

    2 lessons · 5 quiz questions

  2. 02

    Threat Modeling and Secure Design

    Learn to anticipate how a system can be attacked and to design defenses before code is written. This module covers structured threat modeling with STRIDE and the secure design controls behind the OWASP Top 10.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Security Tooling in the CI/CD Pipeline

    Learn what SAST, DAST, and SCA actually do, their strengths and blind spots, and where each belongs in a CI/CD pipeline. This module focuses on integrating tooling so it produces trusted, actionable signal.

    2 lessons · 5 quiz questions

  4. 04

    Governance, Gates, and Application Risk

    Turn scattered security activities into a governed program with explicit gates, policy as code, and disciplined vulnerability management. This module connects AppSec to risk decisions and measurable outcomes.

    2 lessons · 5 quiz questions · assignment