Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Designing Secure Applications Using the OWASP Top 10

Packt via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course features Coursera Coach! A smarter way to learn with interactive, real-time conversations that help you test your knowledge, challenge assumptions, and deepen your understanding as you progress through the course. Modern applications operate in increasingly complex environments where cloud-native architectures, APIs, microservices, software supply chains, and distributed identities introduce new security challenges. In this course, you will learn how to design secure applications by applying the principles behind the OWASP Top 10, the world's most recognized framework for application security risks. Rather than focusing solely on vulnerability remediation, you will develop a security-first architectural mindset that helps prevent weaknesses before they emerge. You will begin by exploring how the application threat landscape has evolved, understanding attacker economics, breach lifecycles, and the methodology OWASP uses to identify and rank risks. From there, you will examine the foundations of secure architecture and discover how design decisions directly influence security outcomes across modern systems and platforms. As the course progresses, you will perform a deep analysis of each OWASP Top 10 category, including Broken Access Control, Cryptographic Failures, Injection, Insecure Design, Security Misconfiguration, Vulnerable Components, Authentication Failures, Software Integrity Risks, Logging and Monitoring Failures, and SSRF. Through architecture-focused discussions, real-world breach case studies, secure-by-design patterns, and hands-on labs, you will learn practical strategies for preventing and mitigating these risks in enterprise environments. This course is designed for software developers, software architects, DevSecOps engineers, cybersecurity professionals, cloud engineers, technical leaders, and IT practitioners who want to strengthen application security expertise. A basic understanding of software development, web applications, networking, and cloud concepts is recommended. The course is suitable for learners at an intermediate level seeking to bridge security theory and secure system design. By the end of the course, you will be able to evaluate application architectures through the lens of the OWASP Top 10, identify and analyze modern security risks, design secure-by-default systems, implement effective mitigation strategies, assess software supply chain and identity-related threats, operationalize application security programs, and integrate security principles into enterprise technology decisions.

Syllabus

  • The Course Intro
    • In this module, we will introduce the course structure and establish the foundational context for OWASP within application security. We will also orient learners to the goals, scope, and expectations of the program. Finally, we will set the stage for understanding modern security challenges in application development.
  • Module 1 — The Evolution of Modern Application Risk
    • In this module, we will examine how application security risks have transformed over time. We will explore attacker incentives and how economics shape exploitation strategies. We will also break down how breaches unfold across their full lifecycle.
  • Module 2 — How OWASP Builds the Top Ten
    • In this module, we will explore how the OWASP Top 10 is constructed and validated. We will examine the data-driven methodology behind risk prioritization. We will also discuss how to responsibly interpret ranking-based security models.
  • Module 3 — Security Architecture Fundamentals for the OWASP Era
    • In this module, we will explore how architecture directly shapes application security outcomes. We will break down the foundational principles of secure system design. We will also connect architectural decisions to OWASP risk categories.
  • Module 4 — A01 Broken Access Control
    • In this module, we will examine how access control mechanisms fail across real-world systems. We will analyze architectural and design-level causes of authorization weaknesses. We will also explore patterns for building robust and secure access control systems.
  • Module 5 — A02 Cryptographic Failures
    • In this module, we will explore how cryptographic systems fail in modern applications. We will break down lifecycle stages where encryption is commonly misused or weakened. We will also review secure patterns for protecting sensitive data effectively.
  • Module 6 — A03 Injection
    • In this module, we will examine how injection vulnerabilities manifest across modern architectures. We will explore how APIs and distributed systems expand the injection attack surface. We will also study defensive coding and design strategies to eliminate injection risks.
  • Module 7 — A04 Insecure Design
    • In this module, we will explore how insecure design emerges at the architectural level. We will examine how cognitive biases and business logic flaws introduce vulnerabilities. We will also focus on designing systems that prevent security issues before implementation.
  • Module 8 — A05 Security Misconfiguration
    • In this module, we will examine how configuration errors lead to security vulnerabilities. We will explore risks across cloud, containers, and infrastructure environments. We will also focus on preventing misconfiguration through disciplined security practices.
  • Module 9 — A06 Vulnerable and Outdated Components
    • In this module, we will explore risks introduced by third-party and open-source components. We will examine how supply chain complexity increases exposure to vulnerabilities. We will also focus on practical approaches to managing and mitigating dependency risks.
  • Module 10 — A07 Identification & Authentication Failures
    • In this module, we will examine how authentication systems are designed and where they fail. We will explore identity as a modern attack surface across cloud and applications. We will also study secure-by-design approaches to identity and access management.
  • Module 11 — A08 Software & Data Integrity Failures
    • In this module, we will explore how integrity failures compromise software systems. We will examine CI/CD, configuration, and third-party risks affecting trust. We will also focus on building systems that ensure end-to-end integrity.
  • Module 12 — A09 Security Logging & Monitoring Failures
    • In this module, we will examine why logging and monitoring systems fail in practice. We will explore how visibility gaps increase breach impact and detection time. We will also focus on building resilient and tamper-resistant observability systems.
  • Module 13 — A10 SSRF
    • In this module, we will explore how SSRF attacks target internal systems through external interfaces. We will analyze how modern architectures unintentionally expose SSRF attack paths. We will also focus on secure design patterns that prevent SSRF exploitation.
  • Module 14 — The Enterprise & Leadership Integration
    • In this module, we will connect OWASP concepts to enterprise security strategy and governance. We will explore how to operationalize security across organizations. We will also focus on building long-term, sustainable security programs.
  • All Labs for OWASP Top 10
    • In this module, we will provide hands-on experience with OWASP Top 10 vulnerabilities. We will explore exploitation techniques across multiple real-world scenarios. We will also reinforce secure coding and remediation practices through practical labs.
  • Course Conclusion
    • In this module, we will consolidate the core lessons from the entire course. We will reflect on how OWASP principles apply across modern systems. We will also outline next steps for advancing secure application design skills.

Taught by

Packt - Course Instructors

Reviews

Start your review of Designing Secure Applications Using the OWASP Top 10

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.