Building Web Application Security Strategies Against Common Vulnerabilities

Move web application security from general awareness to a repeatable, reviewable practice.

📍 Istanbul🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Security and delivery speed are traded against each other in web application security whether or not anyone says so. The documentation for this aspect of technology and systems delivery is accurate only until the next release. The programme uses small-group work so that each participant's treatment of the practice within technology and systems delivery is examined, not just described. The result is the confidence to make and defend decisions about web application security under scrutiny. Post-incident reviews keep identifying weaknesses in this part of technology and systems delivery that were visible long before the incident. Most organisations already have a policy on the wider technology and systems delivery agenda; far fewer can show it working. It treats web application security as an operating discipline and equips participants to run it as one. It is written for people who have to make this aspect of technology and systems delivery work with the resources they already have. Work concludes with a self-assessment of the technology and systems delivery discipline that participants can repeat annually.

Expected Learning Outcomes

01

Control technical debt in web application security deliberately rather than by neglect.

02

Define the availability, performance and recovery targets for web application security.

03

Establish monitoring and alerting on web application security that reflects user experience.

04

Apply access control and least privilege throughout web application security.

05

Estimate what web application security costs to run properly, and what is lost when it is not.

06

Compare the organisation's handling of web application security with recognised practice, and close the material gaps.

07

Design a training and briefing approach that sustains competence in web application security.

Who Should Attend

01

IT managers and service owners responsible for web application security.

02

Business partners who must understand web application security well enough to challenge it.

03

Information security specialists protecting web application security.

04

Compliance and governance staff whose remit includes web application security.

05

Network and communications engineers supporting web application security.

06

IT governance and audit staff reviewing web application security.

Course Modules

01

Web application security: capacity, performance and load

2 sessions · 8 points

Session 1Designing web application security around how it will fail

  • Inventory third-party dependencies inside web application security and their update status.
  • Confirm the support model and escalation path for web application security.
  • Set the review interval for web application security and who attends.
  • Check that web application security still works when volumes rise unexpectedly.

Session 2Proving the backup of web application security by restoring it

  • State the availability and recovery objectives for web application security as numbers.
  • Confirm every release of web application security can be rolled back within a defined time.
  • Set delivery and reliability indicators for web application security the team trusts.
  • Confirm data retention and deletion rules applied within web application security.
02

Web application security: backup, recovery and continuity

2 sessions · 8 points

Session 1Building lasting competence in web application security

  • Set out the decisions in web application security that require sign-off and by whom.
  • Name a single owner for each element of web application security.
  • Document the runbook for web application security to the level a new engineer could use.
  • Test the procedure for web application security against a realistic scenario.

Session 2Keeping web application security alive after the initial push

  • Establish who is informed, consulted and accountable in web application security.
  • Distinguish symptoms from causes when web application security underperforms.
  • Plan the sequence in which improvements to web application security will be introduced.
  • Review whether web application security is aligned with the objectives of the technical platform.
03

Web application security: build, pipeline and release discipline

2 sessions · 8 points

Session 1Dependencies and supply chain risk in web application security

  • Apply change control to web application security including emergency changes.
  • Record the rationale for each significant choice made about web application security.
  • Reduce the variation in how web application security is carried out between teams.
  • Review logging on web application security for coverage and retention.

Session 2The change to web application security that caused the last outage

  • Close out actions on web application security rather than leaving them open indefinitely.
  • Verify six months later that changes to web application security have held.
  • Record the technical debt in web application security and schedule repayment.
  • Check that records of web application security answer the questions likely to be asked.
04

Web application security: requirements, targets and service levels

2 sessions · 8 points

Session 1The hard cases in web application security and how to reason about them

  • Define incident severity levels for web application security and the response each triggers.
  • Restore a backup of web application security in a test environment and time it.
  • Identify the single points of failure in web application security.
  • Identify where judgement in web application security is legitimate and where it is not.

Session 2Making releases of web application security routine instead of risky

  • Configure alerting on web application security that reflects what users experience.
  • Compare the cost of web application security with the cost of its absence.
  • Measure current load on web application security and project it forward twelve months.
  • Test the failover for web application security rather than assuming it works.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.