Secure Web Application / PCI DSS Compliancy Training Course

Course description

If your web applications or systems have any involvement with processing or storing credit card data in any form, then the Payment Card Industry Data Security Standards will almost certainly affect you. This still applies if the services or code merely lives on a shared resource which also stores or processes credit card data.

Security breaches and failures can lead to harsh penalties from member organisations (such as Visa and Mastercard), and the nature of the penalty depends on various factors such as the extent of non compliance with PCI data security standards found during a forensic investigation, and number of affected accounts / records breached.

Our course aims to address a significant requirement of the PCI DSS which is to ensure that relevant training is given to any software developers involved in developing & maintaining such financial applications and services.

The PCI DSS draws heavily on the current OWASP Top Ten Web Application Security Risks. These largely affect cross-platform technologies, and as such our course can be suitable for anyone involved in web development; our hands-on exercises and code demonstrations are delivered with examples in ASP.NET (with VB.NET or C#) or Java, but we can tailor the course for on-site delivery and focus on your development language / platform of choice (PHP, HTML5, Python et al).

What you will learn

* Payment Card Industry Data Security Standards for Software Development
* Secure Development Lifecycle
* OWASP Top 10 Threats with code examples
* Crypto techniques
* Fuzz testing

Who should attend

Web Developers, Testers, Software Architects, Development Managers, Technical QA Managers

Prerequisites

Experience of data-driven web development in a language such as Java, C#, VB.NET, PHP. Knowledge of JavaScript would also be useful.

Web Application Security / PCI DSS Training Course Syllabus

Introduction to Security

What is Application Security and why does it matter?

Payment Card Industry Data Security Standards – PCI-DSS

  • Who / what is the PCI made up of?
  • What PCI DSSmeans to Software Developers
  • Ensuring compliance through design and coding Best Practises

SDL in depth

  • Analysing security and privacy risk
  • Attack surface analysis
  • Threat Modeling
  • Identifying the right tools
  • Enforcing banned functions
  • Static analysis
  • Dynamic / Fuzz Testing
  • Response Plan
  • Final Security Review

Hands-on with the OWASP Top 10 Web Application Security Risks

  • A1: Injection
  • A2: Cross-Site Scripting (XSS)
  • A3: Broken Authentication and Session Management
  • A4: Insecure Direct Object References
  • A5: Cross-Site Request Forgery (CSRF)
  • A6: Security Misconfiguration
  • A7: Insecure Cryptographic Storage
  • A8: Failure to Restrict URL Access
  • A9: Insufficient Transport Layer Protection
  • A10: Unvalidated Redirects and Forwards

Beyond OWASP

  • Data Protection Mechanisms (crypto and more)
  • Fuzz testing and other tools
  • Click jacking
  • Response Splitting
  • CWE/SANS Top 25 Most Dangerous Software Errors
  • Exploiting authentication
  • Language issues
  • Data devaluation
  • Tokenisation solutions
  • Auditing & Logging Solutions

Summary

  • Applying what you’ve learnt in the real world.
  • Understanding the business impact of insecure software (beyond just PCI compliance)



Related courses

banking1
Developing Banking Software with Java & Spring Training Course

aspnet1
Intro to ASP.NET 4.0 Training Course

java1
Java SE Programming Training Course UK

Register

Register to “security1”


11 Jun 2012
10 Sep 2012
12 Nov 2012
21 Jan 2013
On-Site Options











Close
On-site

On-site / Customised Secure Web Application / PCI DSS Compliancy Training

Our Secure Web Application / PCI DSS Compliancy course is available for customised / on-site delivery. If you are looking for a bespoke, tailored Secure Web Application / PCI DSS Compliancy training course based on your project requirements or existing experience level, please feel free to give us a call on 0203 3137 3920, we’d be glad to help.
Okay, so we don't do pizza.

Save as PDF
Send via email

Share course data




Close

Code

security1

Experience Level

intermediate

Days

3

Scheduled Dates

11 Jun 2012
10 Sep 2012
12 Nov 2012
21 Jan 2013

Price per person

£1595 +VAT

Scheduled Address

Framework Training
Westbourne House
14-16
Westbourne Grove
London
W2 5RH

More about our London Training Centre

In categories: Banking Software Development, Java Training Courses, Microsoft Training Courses, Software Security Training Courses, Web Development Training Courses
Tags and keywords: , , , , , , , , , , , , , , , ,