Course Code: owaspwstg
Duration: 21 hours
Prerequisites:
- A general understanding of web development lifecycle
- Experience in web application development, security, and testing
Audience
- Developers
- Engineers
- Architects
Overview:
The Web Security Testing Guide (WSTG) is a community-led, open-source testing resource that provides a comprehensive framework in performing security testing for web applications and services. The Open Web Application Security Project (OWASP) Foundation and its online community continuously develop the WSTG.
This instructor-led, live training (online or onsite) is aimed at developers, engineers, and architects who wish to apply the WSTG testing framework, principles, and techniques to secure their web applications and services.
By the end of this training, participants will be able to:
- Use the WSTG to implement testing processes and techniques in the web development lifecycle.
- Explore different testing techniques to customize the WSTG framework based on business needs.
- Perform various security testing methods to protect web applications from risks and attacks.
- Create an assessment report to document security testing findings and results.
Format of the Course
- Interactive lecture and discussion.
- Lots of exercises and practice.
- Hands-on implementation in a live-lab environment.
Course Customization Options
- To request a customized training for this course, please contact us to arrange.
Course Outline:
Introduction
Overview of Web Security Testing Guide
- The OWASP Testing Project
- Tailoring and prioritizing for organizations
- Testing principles and techniques
- Security testing objectives and requirements
Exploring Various Testing Techniques
- Manual inspections and reviews
- Threat modeling
- Source code review
- Penetration testing
- Security test integration and data analysis
Understanding the OWASP Testing Framework
- Activities from development to deployment
- Maintenance and operations
- Lifecycle end-to-end testing framework and workflow
- Penetration testing methodologies
Performing Web Application Security Testing
- Information gathering
- Configuration and deployment management testing
- Identity management testing
- Authentication and authorization testing
- Session management testing
- Input validation testing
- Testing for error handling
- Testing for weak cryptography
- Business logic testing
- Client-side testing
- API testing
Reporting the Testing Assessment and Results
- Introduction section
- Executive summary
- Findings section
- Appendices
Getting Involved in the Web Security Testing Guide
- Referencing and linking WSTG scenarios
- Code of conduct
- Contribution guide
- Feature requests and feedback
Summary and Conclusion
United Arab Emirates - OWASP Web Security Testing Guide
Qatar - OWASP Web Security Testing Guide
Egypt - OWASP Web Security Testing Guide
Saudi Arabia - OWASP Web Security Testing Guide
South Africa - OWASP Web Security Testing Guide
Brasil - Guia de Testes de Segurança Web OWASP
Canada - OWASP Web Security Testing Guide
香港 - OWASP Web Security Testing Guide
澳門 - OWASP Web Security Testing Guide
USA - OWASP Web Security Testing Guide
Österreich - OWASP Web Security Testing Guide
Schweiz - OWASP Web Security Testing Guide
Deutschland - OWASP Web Security Testing Guide
Czech Republic - OWASP Web Security Testing Guide
Denmark - OWASP Web Security Testing Guide
Estonia - OWASP Web Security Testing Guide
Finland - OWASP Web Security Testing Guide
Greece - OWASP Οδηγός Ασφάλειας Πορταλίων Διαδικτύου
Magyarország - OWASP Web Security Testing Guide
Ireland - OWASP Web Security Testing Guide
Luxembourg - OWASP Web Security Testing Guide
Latvia - OWASP Web Security Testing Guide
España - Guía de Pruebas de Seguridad Web OWASP
Italia - OWASP Web Security Testing Guide
Lithuania - OWASP Web Security Testing Guide
Nederland - OWASP Web Security Testing Guide
Norway - OWASP Web Sikkerhetstestingsguide
Portugal - Guia de Testes de Segurança Web OWASP
România - OWASP Ghidul de Testare a Securității Web
Sverige - OWASP Web Security Testing Guide
Türkiye - OWASP Web Güvenlik Test Rehberi
Malta - OWASP Web Security Testing Guide
Belgique - Guide de Test de Sécurité Web OWASP
France - Guide de Test de Sécurité Web OWASP
日本 - OWASP Web Security Testing Guide
Australia - OWASP Web Security Testing Guide
Malaysia - OWASP Web Security Testing Guide
New Zealand - OWASP Web Security Testing Guide
Philippines - OWASP Web Security Testing Guide
Singapore - OWASP Web Security Testing Guide
Thailand - OWASP Web Security Testing Guide
Vietnam - Hướng dẫn Kiểm thử An toàn Mạng OWASP
India - OWASP Web Security Testing Guide
Argentina - Guía de Pruebas de Seguridad Web OWASP
Chile - Guía de Pruebas de Seguridad Web OWASP
Costa Rica - Guía de Pruebas de Seguridad Web OWASP
Ecuador - Guía de Pruebas de Seguridad Web OWASP
Guatemala - Guía de Pruebas de Seguridad Web OWASP
Colombia - Guía de Pruebas de Seguridad Web OWASP
México - Guía de Pruebas de Seguridad Web OWASP
Panama - Guía de Pruebas de Seguridad Web OWASP
Peru - Guía de Pruebas de Seguridad Web OWASP
Uruguay - Guía de Pruebas de Seguridad Web OWASP
Venezuela - Guía de Pruebas de Seguridad Web OWASP
Polska - OWASP Web Security Testing Guide
United Kingdom - OWASP Web Security Testing Guide
South Korea - OWASP 웹 보안 테스트 가이드
Pakistan - OWASP Web Security Testing Guide
Sri Lanka - OWASP Web Security Testing Guide
Bulgaria - OWASP Руководство за Тестване на Уеб Безопасност
Bolivia - Guía de Pruebas de Seguridad Web OWASP
Indonesia - OWASP Web Security Testing Guide
Kazakhstan - OWASP Web Security Testing Guide
Moldova - OWASP Ghidul de Testare a Securității Web
Morocco - OWASP Web Security Testing Guide
Tunisia - OWASP Web Security Testing Guide
Kuwait - OWASP Web Security Testing Guide
Oman - OWASP Web Security Testing Guide
Slovakia - OWASP Web Security Testing Guide
Kenya - OWASP Web Security Testing Guide
Nigeria - OWASP Web Security Testing Guide
Botswana - OWASP Web Security Testing Guide
Slovenia - OWASP Web Security Testing Guide
Croatia - OWASP Web Security Testing Guide
Serbia - OWASP Web Security Testing Guide
Bhutan - OWASP Web Security Testing Guide
Nepal - OWASP Web Security Testing Guide