|
Securing Web Applications, Services and Servers:
|
||||||||||||||||||||||||||||||||||||||||||||||||||
What is this course about?Organisations today increasingly rely on the Internet and networked systems to conduct business. At the same time, cyber crime and security violations pose an ever-growing threat to business-critical functions and data. If Web applications are not enabled with the appropriate security countermeasures, third parties are able to eavesdrop and compromise the integrity of information passed to and from your Web applications. For organisations that share proprietary data across the Internet, intranets or other public networks, this is of particular concern.
This course systematically exposes potential security threats, provides proven solutions and shows you the steps you can take today to help ensure the integrity and privacy of your Web applications. Special attention is paid to the Open Web Application Security Project (OWASP) Top Ten security issues.
Who will benefit from this course?This course is valuable for anyone who wants to protect their Web applications from attack.
Specifically, this course is geared for those directly involved in the development, maintenance or auditing of Web applications, including Web application developers, software QA personnel, Web application security testers and auditors, and security administrators, as well as those involved in the cybersecurity measures and implementation.What background do I need?Basic knowledge of Web application operation and Web server administration are assumed. You should have knowledge at the level of
Course 470, Developing a Web Site: Hands-On. For example, you should have an understanding of Web browser/server operation, session management and basic HTML. In addition, experience with server-side Web application development and security knowledge is helpful.What Web servers are covered in this course?This course provides a choice between the two most commonly deployed Web servers: Microsoft Internet Information Services on Windows or Apache on Windows.What Web programming languages are covered in this course?This course covers most Web application security issues in a language-independent format. The information provided is applicable to most environments used today. During the hands-on exercises, you choose between using ASP.NET with C# or Java EE. Will I learn how to enable HTTPS in this course?Yes, this course covers configuring a Web server to use HTTPS. This includes obtaining a digital certificate from a certification authority, as well as self-signing. Participants are given a choice of using IIS or Apache for the hands-on exercise.Does this course cover the OWASP Top Ten?Yes, this course goes into detail on the Open Web Application Security Project (OWASP) Guide and the Top Ten security issues. These include: SQL injection flaws, cross-site scripting (XSS), session ID hijacking, Cross Site Request Forgery (CSRF), information leakage, improper error handling, insecure cryptographic storage and failure to restrict URL access.I've heard a lot about cybersecurity lately. Does this course cover cybersecurity?Yes, this course provides hands-on experience discovering and protecting the most common Web-based cybersecurity risks.Will I learn how to secure Web services in this course?Yes. Topics covered include protecting XML message content with WS-Security and ensuring integrity with XML schemas.Does this course cover securing Web servers?Yes. While this course does not cover detailed configuration of a Web server, several Web server security topics are covered. These topics include enabling HTTPS on a Web server, configuring file permissions, detecting file-system changes, and restricting Web server acceptance of HTTP methods.How much time is spent on each topic?
|
Course Dates
| Attend highlighted events in person or live, online via Learning Tree AnyWareTM. |
UK Dates | |
| 1-4 May | London enrol |
| 21-24 Aug | London enrol |
| 4-7 Dec | London enrol |
US East Coast Dates | |
| 2-5 Apr | New York enrol* |
| 8-11 May | Washington, DC enrol* |
*New York and Washington DC Courses – Available online with a run time of 2pm to 9pm BST.
For AnyWare enrolments, please register at least 10 days prior to the start of the course.
More Dates and locations.
Fees
| £ 1,925 | Standard Fee |
| Fee with a Savings Plan | |
| £ 1,225 | 2-Course Passport |
| £ 1,085 | 3-Course Passport |
| £ 1,000 | 4-Course Passport |
| £ 1,600 | Voucher 10-Pack |
On-Site &
Custom Training
Bring this or any Learning Tree course to your location or have it customised for your organisation.