#CODESEC: Secure practices in a team - SSDLC in practice

Security isn’t a step at the end of the development process; it’s a proactive and continuous commitment that needs to be integrated from the very beginning. 

This course dives deep into the Secure Software Development Lifecycle (SSDLC), equipping your team with the knowledge and skills to implement security best practices at every phase of development. 

Learn how to shift your team’s mindset to prioritize security and transform your software projects into secure, resilient, and trustworthy solutions.

Why you should attend

If you’re involved in software development and want to elevate your understanding of security from a holistic and practical perspective, this course is essential. 

You’ll learn why a modular and structured approach to software security is crucial, and you’ll discover how integrating security measures early can prevent costly and dangerous vulnerabilities down the line. 

By gaining insight into both technical practices and programmatic strategies, you’ll be better prepared to meet your company’s security challenges comprehensively.

What you will learn

This course will cover a wide range of topics to build a strong understanding of how to implement SSDLC effectively:

  1. Traditional Approaches to Security:
    • Understand why the traditional “test at the end” approach fails to protect against modern threats.
    • Learn the limitations of reactive security measures and the importance of a proactive mindset.
  2. Theoretical Foundation: Introduction to SSDLC:
    • Get an in-depth overview of the Secure Software Development Lifecycle and its core principles.
    • Learn how SSDLC integrates security into every stage of software development, from planning to maintenance.
  3. Security Maturity Models:
    • Explore different maturity models that organizations use to measure and improve their security practices.
    • Understand how to assess your organization’s security maturity and plan for growth.
  4. Practical SSDLC – Phases Deep Dive:
    • Delve into each phase of the SSDLC with practical examples and case studies.
    • Learn about secure requirements gathering, threat modeling during design, secure coding practices, and how to conduct security testing.
    • Discover techniques for continuous monitoring and the importance of ongoing security maintenance and updates.
  5. Review and Hands-On Exercises:
    • Participate in review sessions that reinforce key concepts.
    • Engage in practical exercises that challenge you to apply SSDLC practices to real-world scenarios, enhancing your ability to think critically about security throughout the development process.

Who is it for

This course is designed for individuals responsible for building or enhancing a security program. It’s also valuable for technical roles looking to better understand their contribution to the overall security framework.

Ideal participants include Project Managers, Scrum/Kanban Masters, Product Owners, Technical Team Leads, Developers, QAs, DevOps, and SecOps/DevSecOps team members.

As an introductory course, it is best suited for those in junior to mid-level positions. While prior knowledge of security concepts is helpful, it is not a requirement.

Other information & prerequisites

Laptops are optional; no additional preinstalled software will be needed.

  • Language: ROMANIAN or ENGLISH
  • Duration: 5 hours
  • Minimum students: 8
  • Date: November 26th
  • Venue: To be announced
  • Price:
    • Before October 28th: 120 EURO + vat
    • After October 28th: 150 EURO + vat

About the trainer

ALIN CIOCOIU

Freelance Security Engineer

Alin is a Security Engineer and freelance pentester with a strong focus on implementing secure practices within development teams. He is experienced in applying SSDLC (Secure Software Development Lifecycle) in practice, helping organizations enhance their security posture through thorough testing and secure development methodologies.

FAQs

Q: What happens if there aren’t enough participants?
A: If we do not meet the minimum number of participants, you can either transfer to another workshop and pay or receive a refund for any difference in price, or opt for a full refund. You will be notified in advance and given options to choose what works best for you.

Q: Are food and accommodation included in the price?
A:
The food and accommodation are not included in the price. However, we can recommend nearby accommodation options for your convenience.

Q: Can I get a refund if I can’t attend after registering?
A:
Yes, full refunds are available up to 20 days before the workshop start date. However, if you cancel after that, we can offer only 50% of the price.

Q: How and when will I receive the details about the location and prerequisites?
A:
You will receive an email with all the necessary details, including the workshop location, prerequisites, and schedule, at least one week before the event. If you have any immediate questions, feel free to reach out to us directly.