2,200 €−330 €1,870 €
What this module delivers.
How the training runs
- Method
- Work through attack classes, weigh countermeasures against each other
- Basis
- Official iSAQB WEBSEC curriculum 2020.1-rev10
- Outcome
- 30 credit points: 10 methodical, 20 technical, no course exam
Dates & booking
Choose a date that fits
2 dates
Sessions with this symbol offer up to 25% group discount. Click “Details & Registration” to learn more.
3,047 €−305 €2,742 €
No dates match this selection.
Dates are still available. Reset the filters to see them.
Fit
Who this module is designed for
Typical roles
- You design or review web applications that are reachable from the internet.
- You decide on authentication, authorisation and how credentials are handled.
- You answer the security questions that come out of audits, acceptance reviews and customer assessments.
Prerequisites
No prerequisites
You can start right away. Helpful: basic knowledge of network communication, basic knowledge of HTML, CSS and JavaScript, hands-on experience building web applications.
Consider instead WEB Builds up HTTP, architecture styles and scaling across 1140 minutes; WEBSEC, by contrast, already assumes basic knowledge of web technologies and web development.
Curriculum
CPSA® WEBSEC Course in Detail
Curriculum 2020.1-rev10 splits WEBSEC into six parts across 1080 teaching minutes. The first three apply to any system: analysis, the secure development process, cryptography. The last three belong to web applications, their attackers and the infrastructure around them, with 675 of the minutes.
01Analysis
This part settles what is worth protecting and how much protection is proportionate.
- Threat modeling and attack trees as the analysis tools
- Security goals such as confidentiality, integrity, authenticity, availability and liability
- Trading security off against usability, cost and business purpose
- Guidelines and rating: ISO 27000, OWASP, PCI-DSS, GDPR, CVSS
02Secure design and development process
Here security moves out of the review and into the development process itself.
- Validating every input and escaping every output as the ground rule
- Security gates, the two-man rule and trust no one
- Secure coding patterns: secure factory, secure state machine, secure logger
- OWASP SAMM, MS SDL and BSIMM as frameworks; SAST, DAST, IAST and SCA as analysis methods
03Cryptography
This part turns cryptography into a selection decision rather than a build project.
- Hashing procedures, salting and rainbow-table attacks
- Symmetric and asymmetric procedures, entropy and perfect forward secrecy
- Trust concepts: PKI, CA models and the web of trust
- X.509 certificates, digital signatures and the use of existing libraries
04Web: Technical foundation
One of the two longest parts: who gets in, and how the system recognises them.
- Authentication types from HTTP auth through multi-factor to single sign-on
- Authorisation with OAuth, OpenID Connect, SAML and JWT
- Stateless against stateful concepts and what each of them costs
- TLS as a security-related protocol, and the limits of security through obscurity
05Web: Known attacks and attack vectors
A quarter of the curriculum is the attacks themselves, each taken by how it works.
- Attack vectors sorted by application, operating system, network, design and process layer
- Injection, DoS and DDoS including botnets, man-in-the-middle
- Fuzzing as a black box test, in-memory attacks and backdoors
- Social engineering, credential stuffing, and sources such as the OWASP Top Ten and SANS25
06Web: Security and infrastructure
To close, everything that surrounds the application.
- Firewalls, packet filtering and the architectural consequences of a DMZ
- Web application firewalls plus intrusion detection and prevention
- Logging, monitoring and fixed feedback processes out of operations
- Using TLS even inside closed networks
Outcome
What you will be able to do afterwards
- 01
You identify assets worth protecting, model threats with attack trees and compare CVSS and the OWASP Rating as classification systems.
- 02
You justify the trade-off between security, usability and cost, and derive acceptance criteria from it.
- 03
You anchor input validation, output escaping and security gates in the development process.
- 04
You separate SAST, DAST, IAST and SCA from each other and pick the method that fits.
- 05
You select hashing and encryption procedures with reasons, and distinguish PKI, the web of trust and X.509 certificates.
- 06
You design authentication and authorisation using multi-factor, OAuth, OpenID Connect, SAML or JWT.
- 07
You analyse injection, DoS and man-in-the-middle attacks, and derive design decisions that make them harder.
- 08
You plan firewalls, a DMZ, a WAF and intrusion detection as part of the architecture rather than as an afterthought.
Credit points toward CPSA-A
- Methodical competence
- 10
- Technical competence
- 20
- Communicative competence
- 0
30 of 70 points toward CPSA-A admission
Certificate of participation
The tecnovy certificate of participation records your attendance of the WEBSEC training, not a passed examination.
Open the Certificate Showroom tecnovy →≥80%attendance
Why tecnovy
What you get on top with us
01
iSAQB® Accredited Provider
We are an officially accredited Training Provider of the International Software Architecture Qualification Board.
02
Certificate Showroom
Get your certificate of participation and, if you have one, add your exam certificate from E-Learning. Fully automated, beautifully designed. Just for you, only at tecnovy.
03
No Slideshow, Hands-On!
Promised: no PowerPoint marathon. We work in groups, tie theory to practice, and you get real project examples from our experienced trainers plus the exchange with like-minded people.
04
Attend Twice, Pay Once
You are welcome to attend the training online again within a year as a refresher.
05
Learn from Experts
We always guarantee you the use of didactically and methodically first-class qualified trainers who draw their knowledge from training experience as well as professional practical and project experience.
06
Flexible Date Change
If you are not able to attend the course, you can rebook your training free of charge up to one week before the start of the training.
FAQs
Frequently asked questions
01Do I need CPSA-F to attend the tecnovy WEBSEC training?
02Is there a WEBSEC examination?
03How many credit points does WEBSEC carry?
04How does the CPSA-A certification work?
05How long is the WEBSEC training?
06What is the difference between WEBSEC and WEB?
07Does WEBSEC work through the OWASP Top Ten?
08Does WEBSEC cover embedded systems or physical security?
09Do I get the flipcharts from the WEBSEC training?
What does your training at tecnovy look like?
