Web applications are public-facing by definition, which makes them the most exposed thing most organizations own. Learn, as developers and overseers together, how they get broken and what a strong security policy requires in response.
Overview
Syllabus
Module 1
- Foundations of Web Application Security and the Federal Policy Landscape
- What a web application is and why it is a common attack surface
- The CIA triad applied to federal systems
- Threat actors from nation-state to insider
- Shared responsibility across developers, system owners, ISSOs and users
- FISMA, the Risk Management Framework and the authorization process, Executive Order 14028 and its amendments, and Cybersecurity Framework 2.0
- How to tell when a policy has been superseded
Module 2
- Common Web Application Vulnerabilities
- How the OWASP Top 10 is developed and why federal secure-coding guidance references it
- The 2025 edition categories including broken access control, cryptographic failures, injection, insecure design and misconfiguration, software supply chain failures, authentication failures, mishandling of exceptional conditions, and logging and monitoring failures
- Why each is consequential for federal systems
Module 3
- Secure Development Practices and the Secure SDLC
- The phases of a secure development lifecycle
- Input validation, output encoding, least privilege, secure defaults and failing securely
- Security requirements and threat modeling before code is written
- Static and dynamic testing at a conceptual level
- Open-source and software supply chain risk
- How secure development supports the path to an authorization to operate