Secure Coding Fundamentals Training
Secure Coding Fundamentals is a hands-on, two-day foundational course that teaches developers to write defensible code. Students learn secure-coding concepts and terminology, how exploits work, and how to detect, attack and defend against the most dangerous software errors — from injection and cross-site scripting to broken authentication, XML External Entities and broken access control — mapped to the CWE/SANS Top 25.
Learning Objectives
- Understand the concepts and terminology behind defensive, secure coding, including the phases and goals of a typical exploit
- Perform bug hunting and vulnerability testing safely and appropriately, and use organizational defect-reporting mechanisms
- Recognize common software exploits and the value of a multi-layered defense-in-depth approach
- Identify examples from the CWE Top 25 Most Dangerous Software Errors and their security consequences
- Identify untrusted data sources and the consequences of mishandling them (denial of service, XSS, injection)
- Detect, attack and defend authentication, authorization, XSS, injection, XXE, file-upload and access-control weaknesses
- Use code scanners, dynamic scanners and web application firewalls (WAFs) effectively, and implement robust testing strategies
- Harden web and application servers and identify resources for ongoing threat intelligence
Prerequisites
Programming experience in at least one common programming language.
Course Outline
- Module 1: Bug Hunting Foundation
- Why hunt bugs, the language of cybersecurity, the changing threat landscape, an AppSec dissection of SolarWinds, the human perimeter, and interpreting the Verizon Data Breach Investigations Report. Labs & demos: a case study in failure.
- Module 2: Moving Forward from Hunting Bugs
- Removing bugs using the CWE/SANS Top 25, the Web Application Security Consortium (WASC), CERT Secure Coding Standards, the Microsoft Security Response Center, and software-specific threat intelligence.
- Module 3: Foundation for Securing Web Applications
- Principles of information security, security as a lifecycle issue, minimizing attack surface, layered defense, compartmentalization, considering all application states, and never trusting untrusted data.
- Module 4: Bug Stomping 101
- Unvalidated data and buffer overflows; injection and SQL injection; broken authentication and session management; sensitive data exposure; XML External Entities (XXE); and broken access control — with hands-on defense labs.
- Module 5: Bug Stomping 102
- Cross-Site Scripting (persistent, reflective and DOM-based); deserialization and vulnerable components; insufficient logging and monitoring; and spoofing and Cross-Site Request Forgery (CSRF) — with hands-on defense labs.
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Programming & Development training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Secure Coding Fundamentals Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
Secure Coding Fundamentals is a hands-on, two-day foundational course that teaches developers to write defensible code. Students learn secure-coding concepts and terminology, how exploits work, and how to detect, attack and defend against the most dangerous software errors — from injection and cross-site scripting to broken authentication, XML External Entities and broken access control — mapped to the CWE/SANS Top 25. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.
Course Objectives
Once I've completed the course, I'll be able to:
- Understand the concepts and terminology behind defensive, secure coding, including the phases and goals of a typical exploit
- Perform bug hunting and vulnerability testing safely and appropriately, and use organizational defect-reporting mechanisms
- Recognize common software exploits and the value of a multi-layered defense-in-depth approach
- Identify examples from the CWE Top 25 Most Dangerous Software Errors and their security consequences
- Identify untrusted data sources and the consequences of mishandling them (denial of service, XSS, injection)
- Detect, attack and defend authentication, authorization, XSS, injection, XXE, file-upload and access-control weaknesses
- Use code scanners, dynamic scanners and web application firewalls (WAFs) effectively, and implement robust testing strategies
- Harden web and application servers and identify resources for ongoing threat intelligence
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in programming & development. Additional course information is available at https://appliedtechnologyacademy.com/secure-coding-fundamentals/.
Thank you for your consideration,
[Your Name]
Related Programming & Development courses
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.